| CVE-2024-4390 | Depicter <= 3.0.2 - Authenticated (Contributor+) Arbitrary Nonce Generation | averta | Depicter — Popup & Slider Builder | Medium | 6.5 | 2024-06-20 03:37:23 | Deep Dive |
| CVE-2024-4305 | PostX < 4.1.0 - Contributor+ Stored XSS | Unknown | Post Grid Gutenberg Blocks and WordPress Blog Plugin | - | - | 2024-06-17 06:00:01 | Deep Dive |
| CVE-2023-52233 | WordPress POST SMTP Mailer plugin <= 2.8.6 - Broken Access Control on API vulnerability | Post SMTP | Post SMTP Mailer/Email Log | High | 8.6 | 2024-06-11 16:05:39 | Deep Dive |
| CVE-2023-51498 | WordPress WooCommerce Canada Post Shipping plugin <= 2.8.3 - Broken Access Control vulnerability | Woo | WooCommerce Canada Post Shipping | Medium | 5.3 | 2024-06-11 14:37:58 | Deep Dive |
| CVE-2024-35665 | WordPress Insert Post Ads plugin <= 1.3.2 - Broken Access Control vulnerability | namithjawahar | Insert Post Ads | Medium | 5.3 | 2024-06-11 14:10:58 | Deep Dive |
| CVE-2024-3549 | Blog2Social: Social Media Auto Post & Scheduler <= 7.4.1 - Authenticated (Subscriber+) SQL Injection | pr-gateway | Blog2Social: Social Media Auto Post & Scheduler | Critical | 9.9 | 2024-06-11 06:44:16 | Deep Dive |
| CVE-2024-32713 | WordPress AI Post Generator | AutoWriter plugin <= 3.3 - Broken Access Control vulnerability | AutoWriter | AI Post Generator | AutoWriter | Medium | 5.4 | 2024-06-09 17:08:30 | Deep Dive |
| CVE-2024-35739 | WordPress The Post Grid plugin <= 7.7.1 - Cross Site Scripting (XSS) vulnerability | RadiusTheme | The Post Grid | Medium | 6.5 | 2024-06-08 12:42:20 | Deep Dive |
| CVE-2024-5149 | BuddyForms <= 2.8.9 - Email Verification Bypass due to Insufficient Randomness | themekraft | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | Medium | 6.5 | 2024-06-05 04:32:25 | Deep Dive |
| CVE-2023-51667 | WordPress Rate my Post – WP Rating System plugin <= 3.4.2 - Broken Access Control vulnerability | FeedbackWP | Rate my Post – WP Rating System | Medium | 5.3 | 2024-06-04 12:29:23 | Deep Dive |
| CVE-2024-34789 | WordPress Post Grid Elementor Addon plugin <= 2.0.16 - Cross Site Scripting (XSS) vulnerability | WP Hait | Post Grid Elementor Addon | Medium | 6.5 | 2024-06-03 10:58:28 | Deep Dive |
| CVE-2024-34793 | WordPress WP Next Post Navi plugin <= 1.8.3 - Cross Site Scripting (XSS) vulnerability | Kharim Tomlinson | WP Next Post Navi | Medium | 5.9 | 2024-06-03 10:52:02 | Deep Dive |
| CVE-2024-3564 | Content Blocks (Custom Post Widget) <= 3.3.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode | vanderwijk | Content Blocks (Custom Post Widget) | High | 8.8 | 2024-06-01 03:31:17 | Deep Dive |
| CVE-2024-3565 | Content Blocks (Custom Post Widget) <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via content_block Shortcode | vanderwijk | Content Blocks (Custom Post Widget) | Medium | 6.4 | 2024-06-01 03:31:17 | Deep Dive |
| CVE-2023-7073 | Auto Featured Image (Auto Post Thumbnail) <= 4.1.7 - Authenticated (Author+) Server-Side Request Forgery | themeisle | Auto Featured Image (Auto Post Thumbnail) | Medium | 6.4 | 2024-05-31 14:31:47 | Deep Dive |
| CVE-2024-5326 | Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update | wpxpo | Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX | High | 8.8 | 2024-05-30 10:59:29 | Deep Dive |
| CVE-2024-5207 | POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection | saadiqbal | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | High | 7.2 | 2024-05-30 05:33:15 | Deep Dive |
| CVE-2024-5223 | Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.1 - Authenticated (Author+) Stored Cross-Site Scripting | wpxpo | Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX | Medium | 6.4 | 2024-05-30 03:34:28 | Deep Dive |
| CVE-2024-1376 | Event post <= 5.9.4 - Missing Authorization | bastho | Event post | Medium | 4.3 | 2024-05-24 06:42:17 | Deep Dive |
| CVE-2024-4043 | WP Ultimate Post Grid <= 3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-text Shortcode | brechtvds | WP Ultimate Post Grid | Medium | 6.4 | 2024-05-23 06:46:02 | Deep Dive |