| CVE-2024-8323 | Pricing Tables WordPress Plugin – Easy Pricing Tables <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via fontFamily Attribute | fatcatapps | Pricing Table WordPress Plugin – Easy Pricing Tables | Medium | 6.4 | 2024-11-06 11:32:03 | Deep Dive |
| CVE-2024-10715 | MapPress Maps for WordPress <= 2.94.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Block | chrisvrichardson | MapPress Maps for WordPress | Medium | 6.4 | 2024-11-06 11:00:29 | Deep Dive |
| CVE-2024-8615 | WP JobSearch <= 2.6.7 - Unauthenticated Arbitrary File Upload | eyecix | JobSearch WP Job Board | Critical | 10.0 | 2024-11-06 08:29:58 | Deep Dive |
| CVE-2024-8614 | WP JobSearch <= 2.6.7 - Authenticated (Subscriber+) Arbitrary File Upload | eyecix | JobSearch WP Job Board | Critical | 9.9 | 2024-11-06 08:29:57 | Deep Dive |
| CVE-2024-10020 | Heateor Social Login WordPress <= 1.1.35 - Authentication Bypass via Disqus OAuth provider | heateor | Heateor Social Login WordPress | High | 8.1 | 2024-11-06 06:43:31 | Deep Dive |
| CVE-2024-10647 | WS Form LITE – Drag & Drop Contact Form Builder for WordPress <= 1.9.244 - Reflected Cross-Site Scripting via URL | westguard | WS Form LITE – Drag & Drop Contact Form Builder | Medium | 6.1 | 2024-11-06 02:01:57 | Deep Dive |
| CVE-2024-10028 | Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.2.13 - Sensitive Invormation Disclosure via procstat Log | everestthemes | Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin | High | 7.5 | 2024-11-05 23:28:42 | Deep Dive |
| CVE-2024-10263 | Tickera – WordPress Event Ticketing <= 3.5.4.4 - Unauthenticated Arbitrary Shortcode Execution | tickera | Tickera – Sell Tickets & Manage Events | High | 7.3 | 2024-11-05 12:45:22 | Deep Dive |
| CVE-2024-51682 | WordPress HT Builder – WordPress Theme Builder for Elementor plugin <= 1.3.0 - Stored Cross Site Scripting (XSS) vulnerability | HasThemes | HT Builder – WordPress Theme Builder for Elementor | Medium | 6.5 | 2024-11-04 14:12:40 | Deep Dive |
| CVE-2024-8739 | ReCaptcha Integration for WordPress <= 1.2.5 - Reflected Cross-Site Scripting | wedevs | ReCaptcha Integration for WordPress | Medium | 6.1 | 2024-11-02 02:03:08 | Deep Dive |
| CVE-2024-37218 | WordPress Page Builder Sandwich <= 5.1.0 - Broken Access Control vulnerability | WordPress Page Builder Sandwich Team | Page Builder Sandwich – Front-End Page Builder | Medium | 4.3 | 2024-11-01 14:18:32 | Deep Dive |
| CVE-2024-37226 | WordPress Kanban Boards for WordPress plugin <= 2.5.21 - Broken Access Control vulnerability | Kanban for WordPress | Kanban Boards for WordPress | Medium | 5.3 | 2024-11-01 14:18:31 | Deep Dive |
| CVE-2024-37444 | WordPress Defender plugin <= 4.7.1 - Broken Access Control vulnerability | WPMU DEV - Your All-in-One WordPress Platform | Defender Security | Medium | 5.3 | 2024-11-01 14:18:21 | Deep Dive |
| CVE-2024-38690 | WordPress iPanorama 360 plugin <= 1.8.3 - Broken Access Control vulnerability | Avirtum | iPanorama 360 WordPress Virtual Tour Builder | Medium | 5.3 | 2024-11-01 14:18:09 | Deep Dive |
| CVE-2024-38792 | WordPress ConveyThis Translate plugin <= 234 - Non-arbitrary Options Update vulnerability | ConveyThis Translate Team | Language Translate Widget for WordPress – ConveyThis | Medium | 5.3 | 2024-11-01 14:17:56 | Deep Dive |
| CVE-2024-39639 | WordPress File Upload plugin <= 4.24.7 - Broken Access Control + CSRF vulnerability | Nickolas Bossinas | WordPress File Upload | Medium | 4.3 | 2024-11-01 14:17:54 | Deep Dive |
| CVE-2024-43118 | WordPress Hummingbird plugin <= 3.9.1 - Broken Access Control vulnerability | WPMU DEV - Your All-in-One WordPress Platform | Hummingbird | Medium | 4.3 | 2024-11-01 14:17:50 | Deep Dive |
| CVE-2024-43235 | WordPress Meta Box plugin <= 5.9.10 - Broken Access Control vulnerability | MetaBox.io | Meta Box – WordPress Custom Fields Framework | High | 7.1 | 2024-11-01 14:17:37 | Deep Dive |
| CVE-2024-43268 | WordPress Backup and Restore WordPress plugin <= 1.50 - Broken Access Control vulnerability | WPBackItUp | Backup and Restore WordPress | Medium | 5.4 | 2024-11-01 14:17:34 | Deep Dive |
| CVE-2024-43270 | WordPress Backup and Restore WordPress plugin <= 1.50 - Unauthenticated Broken Access Control vulnerability | WPBackItUp | Backup and Restore WordPress | Medium | 5.3 | 2024-11-01 14:17:34 | Deep Dive |