| CVE-2024-50475 | WordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerability | Scott Gamon | Signup Page | Critical | 9.8 | 2024-10-29 08:39:21 | Deep Dive |
| CVE-2024-50449 | WordPress PDF Generator Addon for Elementor Page Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) vulnerability | RedefiningTheWeb | PDF Generator Addon for Elementor Page Builder | Medium | 6.5 | 2024-10-28 17:54:50 | Deep Dive |
| CVE-2020-36839 | WP Lead Plus X <= 0.99 - Cross-Site Request Forgery | bc2018 | WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus X | High | 8.3 | 2024-10-16 06:43:45 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-6757 | Elementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function | elemntor | Elementor Website Builder – more than just a page builder | Medium | 4.3 | 2024-10-15 02:03:52 | Deep Dive |
| CVE-2024-8760 | Stackable – Page Builder Gutenberg Blocks <= 3.13.6 - Unauthenticated CSS Injection | bfintal | Stackable – Page Builder Gutenberg Blocks | Medium | 5.3 | 2024-10-12 08:41:04 | Deep Dive |
| CVE-2024-9656 | Mynx Page Builder <= 0.27.8 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | azexo | Mynx Page Builder | Medium | 6.4 | 2024-10-12 05:39:42 | Deep Dive |
| CVE-2024-8913 | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_template | posimyththemes | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | Medium | 4.3 | 2024-10-11 08:30:46 | Deep Dive |
| CVE-2024-9234 | GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload | ataurr | GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor | Critical | 9.8 | 2024-10-11 06:50:20 | Deep Dive |
| CVE-2024-47298 | WordPress Bold Page Builder plugin <= 5.1.1 - Cross Site Scripting (XSS) vulnerability | boldthemes | Bold Page Builder | Medium | 6.5 | 2024-10-06 11:44:39 | Deep Dive |
| CVE-2024-47299 | WordPress Website Builder by SeedProd <= 6.17.4 - Cross Site Scripting (XSS) vulnerability | SeedProd | Coming Soon Page, Under Construction & Maintenance Mode by SeedProd | Medium | 5.9 | 2024-10-06 11:42:29 | Deep Dive |
| CVE-2024-47375 | WordPress XLTab – Accordions and Tabs for Elementor Page Builder plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | webangon | XLTab – Accordions and Tabs for Elementor Page Builder | Medium | 6.5 | 2024-10-05 15:14:56 | Deep Dive |
| CVE-2024-47382 | WordPress Page-list plugin <= 5.6 - Cross Site Scripting (XSS) vulnerability | webvitaly | Page-list | Medium | 6.5 | 2024-10-05 14:56:17 | Deep Dive |
| CVE-2024-47391 | WordPress Bold Page Builder plugin < 5.1.1 - Cross Site Scripting (XSS) vulnerability | boldthemes | Bold Page Builder | Medium | 6.5 | 2024-10-05 14:44:09 | Deep Dive |
| CVE-2024-9204 | Smart Custom 404 Error Page <= 11.4.7 - Reflected Cross-Site Scripting | nerdpressteam | Smart Custom 404 Error Page | Medium | 6.1 | 2024-10-04 02:04:55 | Deep Dive |
| CVE-2024-9218 | Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.3.14 - Reflected Cross-Site Scripting | wpblockart | Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid | Medium | 6.1 | 2024-10-02 08:31:51 | Deep Dive |
| CVE-2024-9274 | Elastik Page Builder <= 0.27.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | azexo | Elastik Page Builder | Medium | 6.4 | 2024-10-01 07:30:10 | Deep Dive |
| CVE-2024-9049 | Beaver Builder – WordPress Page Builder <= 2.8.3.6 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Group Module | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | Medium | 6.4 | 2024-09-27 06:53:58 | Deep Dive |
| CVE-2024-43977 | WordPress The Plus Addons for Elementor plugin <= 5.6.2 - Cross Site Scripting (XSS) vulnerability | POSIMYTH | The Plus Addons for Elementor Page Builder Lite | Medium | 5.9 | 2024-09-17 22:38:59 | Deep Dive |
| CVE-2024-5416 | Elementor Website Builder – More than Just a Page Builder <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets | elemntor | Elementor Website Builder – more than just a page builder | Medium | 5.4 | 2024-09-11 11:32:03 | Deep Dive |