| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-24718 | WordPress WP Sessions Time Monitoring Full Automatic Plugin <= 1.1.1 - Reflected Cross Site Scripting (XSS) vulnerability | activity-log.com | WP Sessions Time Monitoring Full Automatic | High | 7.1 | 2025-01-31 08:24:42 | Deep Dive |
| CVE-2023-41866 | WordPress Automatic YouTube Gallery plugin <= 2.3.3 - Broken Access Control vulnerability | Plugins360 Labs | Automatic YouTube Gallery | Medium | 4.3 | 2024-12-13 14:24:22 | Deep Dive |
| CVE-2024-11009 | Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) <= 1.2.1 - Authenticated (Administrator+) SQL Injection via post_id Parameter | pagup | Automatic Internal Links for SEO by Pagup | Medium | 4.9 | 2024-11-27 11:33:23 | Deep Dive |
| CVE-2024-50493 | WordPress Automatic Translation plugin <= 1.0.4 - Arbitrary File Upload vulnerability | masterhomepage | Automatic Translation | Critical | 10.0 | 2024-10-29 07:55:08 | Deep Dive |
| CVE-2024-49681 | WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.0.9 - SQL Injection vulnerability | activity-log.com | WP Sessions Time Monitoring Full Automatic | Critical | 9.3 | 2024-10-24 12:09:17 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-9586 | Linkz.ai <= 1.1.8 - Missing Authorization to Unauthenticated Plugin Settings Update | vittor1o | Linkz.ai – Automatic link previews on hover | Medium | 6.5 | 2024-10-11 05:33:13 | Deep Dive |
| CVE-2024-9587 | Linkz.ai <= 1.1.8 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update via AJAX | vittor1o | Linkz.ai – Automatic link previews on hover | Medium | 5.4 | 2024-10-11 05:33:12 | Deep Dive |
| CVE-2024-9119 | SVG Complete <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | automatic-rock | SVG Complete | Medium | 6.4 | 2024-10-01 07:30:07 | Deep Dive |
| CVE-2024-5969 | AIomatic - Automatic AI Content Writer <= 2.0.5 - Unauthenticated Arbitrary Email Sending | CodeRevolution | Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit | Medium | 5.8 | 2024-07-27 07:33:47 | Deep Dive |
| CVE-2024-5600 | Happy SCSS Compiler - Compile SCSS to CSS automatically <= 1.3.10 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting | happymonkeyagency | SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue | Medium | 5.4 | 2024-07-09 08:33:05 | Deep Dive |
| CVE-2024-0632 | Automatic Translator with Google Translate <= 1.5.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via Custom Font | juangirini | Automatic Translator with Google Translate | Medium | 4.4 | 2024-05-22 07:37:23 | Deep Dive |
| CVE-2024-4849 | WordPress Automatic <= 3.94.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via autoplay Parameter | ValvePress | WordPress Automatic Plugin | Medium | 6.4 | 2024-05-18 05:40:02 | Deep Dive |
| CVE-2024-27955 | WordPress Automatic plugin <= 3.92.0 - CSRF to Privilege Escalation vulnerability | WP Automatic | Automatic | High | 8.3 | 2024-05-17 08:50:52 | Deep Dive |
| CVE-2024-27954 | WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability | WP Automatic | Automatic | Critical | 9.3 | 2024-05-17 08:50:37 | Deep Dive |
| CVE-2024-32693 | WordPress Automatic plugin < 3.93.0 - Multiple Cross Site Request Forgery (CSRF) vulnerability | ValvePress | Automatic | High | 7.6 | 2024-04-22 07:58:25 | Deep Dive |
| CVE-2024-27956 | WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability | ValvePress | Automatic | Critical | 9.9 | 2024-03-21 17:01:14 | Deep Dive |
| CVE-2023-5203 | WP Sessions Time Monitoring Full Automatic < 1.0.9 - Unauthenticated SQL injection | Unknown | WP Sessions Time Monitoring Full Automatic | - | - | 2023-12-26 18:33:08 | Deep Dive |
| CVE-2023-49180 | WordPress Automatic Youtube Video Posts Plugin Plugin <= 5.2.2 is vulnerable to Cross Site Scripting (XSS) | Ternstyle LLC | Automatic Youtube Video Posts Plugin | Medium | 5.9 | 2023-12-15 14:47:33 | Deep Dive |
| CVE-2023-3041 | Autochat <= 1.1.7- Unauthenticated Stored XSS | Unknown | Autochat Automatic Conversation | 中危 | - | 2023-07-17 13:29:50 | Deep Dive |