| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-40011 | WordPress Cost Calculator Builder plugin <= 3.1.42 - Broken Access Control vulnerability | Stylemix | Cost Calculator Builder | Medium | 5.4 | 2024-12-13 14:24:05 | Deep Dive |
| CVE-2024-47344 | WordPress uListing plugin <= 2.1.5 - Sensitive Data Exposure vulnerability | Stylemix | uListing | Medium | 5.3 | 2024-10-07 05:34:22 | Deep Dive |
| CVE-2024-6012 | Cost Calculator Builder <= 3.2.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Creation | stylemix | Cost Calculator Builder | Medium | 4.3 | 2024-07-02 09:32:10 | Deep Dive |
| CVE-2024-6011 | Cost Calculator Builder <= 3.2.12 - Authenticated (Administrator+) Stored Cross-Site Scripting | stylemix | Cost Calculator Builder | Medium | 4.4 | 2024-07-02 09:32:10 | Deep Dive |
| CVE-2024-5545 | Motors – Car Dealer, Classifieds & Listing <= 1.4.9 - Missing Authorization | stylemix | Motors – Car Dealership & Classified Listings Plugin | Medium | 5.3 | 2024-07-02 07:37:05 | Deep Dive |
| CVE-2024-5468 | WordPress Header Builder Plugin – Pearl <= 1.3.7 - Missing Authorization to Unauthenticated Arbitrary Site Options Deletion | stylemix | Pearl – Header Builder | Medium | 6.5 | 2024-06-12 08:33:20 | Deep Dive |
| CVE-2024-4000 | WordPress Header Builder Plugin – Pearl <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | stylemix | Pearl – Header Builder | Medium | 6.4 | 2024-05-02 16:52:35 | Deep Dive |
| CVE-2024-3942 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Medium | 6.3 | 2024-05-02 16:52:11 | Deep Dive |
| CVE-2024-3275 | eRoom – Zoom Meetings & Webinar <= 1.4.18 - Missing Authorization to Information Exposure | digitalmeactivecampaign | eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams | Medium | 4.3 | 2024-05-02 16:52:09 | Deep Dive |
| CVE-2024-3136 | MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Critical | 9.8 | 2024-04-09 18:59:08 | Deep Dive |
| CVE-2024-1904 | MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Medium | 4.3 | 2024-04-09 18:58:37 | Deep Dive |
| CVE-2024-2411 | MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Critical | 9.8 | 2024-03-29 08:31:30 | Deep Dive |
| CVE-2024-2409 | MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Critical | 9.8 | 2024-03-29 08:31:30 | Deep Dive |
| CVE-2024-2106 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Medium | 5.3 | 2024-03-13 15:26:40 | Deep Dive |
| CVE-2024-1512 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Critical | 9.8 | 2024-02-17 07:36:57 | Deep Dive |
| CVE-2023-2834 | BookIt <= 2.3.7 - Authentication Bypass | stellarwp | Bookit — Booking & Appointment Calendar | Critical | 9.8 | 2023-06-30 01:56:18 | Deep Dive |
| CVE-2021-4381 | uListing <= 1.6.6 - Unauthenticated Options Changes via wp_route | stylemix | Directory Listings WordPress plugin – uListing | Critical | 9.8 | 2023-06-07 01:51:55 | Deep Dive |
| CVE-2021-4370 | uListing <= 1.6.6 - Missing Authorization | stylemix | Directory Listings WordPress plugin – uListing | Critical | 9.8 | 2023-06-07 01:51:43 | Deep Dive |
| CVE-2021-4357 | uListing <= 1.6.6 - Unauthenticated Arbitrary Post/Page Deletion | stylemix | Directory Listings WordPress plugin – uListing | Critical | 9.1 | 2023-06-07 01:51:26 | Deep Dive |
| CVE-2021-4345 | uListing <= 1.6.6 - Unauthenticated Arbitrary Roles and Capabilities Creation/Deletion | stylemix | Directory Listings WordPress plugin – uListing | Medium | 6.5 | 2023-06-07 01:51:18 | Deep Dive |