| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-0350 | Divi Carousel Lite <= 2.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Carousel and Logo Carousel Widgets | badhonrocks | Divi Carousel Free (Divi5 Support) | Medium | 6.4 | 2025-01-25 09:22:46 | Deep Dive |
| CVE-2025-24746 | WordPress Popup Maker plugin <= 1.20.2 - Cross Site Scripting (XSS) vulnerability | Daniel Iser | Popup Maker | Medium | 6.5 | 2025-01-24 17:25:23 | Deep Dive |
| CVE-2024-56277 | WordPress Poll Maker Plugin < 5.5.5 - HTML Injection vulnerability | Ays Pro | Poll Maker | 中危 | - | 2025-01-21 13:40:34 | Deep Dive |
| CVE-2025-23827 | WordPress Strx Magic Floating Sidebar Maker plugin <= 1.4.1 - CSRF to Stored XSS vulnerability | straps | Strx Magic Floating Sidebar Maker | High | 7.1 | 2025-01-16 20:07:12 | Deep Dive |
| CVE-2024-56295 | WordPress Poll Maker plugin <= 5.5.6 - Broken Access Control vulnerability | Ays Pro | Poll Maker | Medium | 6.5 | 2025-01-15 15:23:40 | Deep Dive |
| CVE-2024-10562 | Form Maker by 10Web < 1.15.31 - Admin+ Stored XSS | Unknown | Form Maker by 10Web | 中危 | - | 2025-01-07 06:00:03 | Deep Dive |
| CVE-2024-11934 | Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce <= 2.1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | formaloo | Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce | Medium | 6.4 | 2025-01-07 03:21:55 | Deep Dive |
| CVE-2023-45766 | WordPress Poll Maker plugin <= 4.7.1 - Broken Access Control vulnerability | Ays Pro | Poll Maker | 中危 | - | 2025-01-02 11:59:55 | Deep Dive |
| CVE-2024-12411 | WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More <= 2.5.4 - Reflected Cross-Site Scripting | onetarek | WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More | Medium | 6.1 | 2024-12-14 04:23:44 | Deep Dive |
| CVE-2024-11865 | Tabs Maker <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | html5maps | Tabs Maker | Medium | 6.4 | 2024-12-14 04:23:39 | Deep Dive |
| CVE-2023-22697 | WordPress Survey Maker plugin <= 3.2.0 - Broken Access Control vulnerability | Ays Pro | Survey Maker | Medium | 5.3 | 2024-12-13 14:22:13 | Deep Dive |
| CVE-2022-45819 | WordPress Popup Maker plugin <= 1.17.1 - Broken Access Control vulnerability | Daniel Iser | Popup Maker | Low | 3.5 | 2024-12-13 14:22:03 | Deep Dive |
| CVE-2024-10583 | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder <= 1.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | danieliser | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder | Medium | 5.4 | 2024-12-12 06:46:34 | Deep Dive |
| CVE-2023-50904 | WordPress Poll Maker plugin <= 4.8.0 - Broken Access Control vulnerability | Ays Pro | Poll Maker | 中危 | - | 2024-12-09 11:29:52 | Deep Dive |
| CVE-2024-12115 | Poll Maker <= 5.5.4 - Cross-Site Request Forgery to Poll Duplication | ays-pro | Poll Maker – Versus Polls, Anonymous Polls, Image Polls | Medium | 4.3 | 2024-12-07 01:45:53 | Deep Dive |
| CVE-2024-11323 | AI Quiz | Quiz Maker <= 1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update | kekotron | AI Quiz | Quiz Maker | High | 8.8 | 2024-12-06 08:24:52 | Deep Dive |
| CVE-2024-5020 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-12-04 08:22:47 | Deep Dive |
| CVE-2024-52421 | WordPress WP Popup Window Maker plugin <= 2.0 - CSRF to Stored XSS vulnerability | wp-buy | WP Popup Window Maker | High | 7.1 | 2024-11-19 16:32:18 | Deep Dive |
| CVE-2024-10265 | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via add_query_arg Parameter | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | Medium | 6.1 | 2024-11-10 12:30:34 | Deep Dive |
| CVE-2024-9874 | WordPress Poll Maker Plugin <= 5.4.6 - Authenticated (Administrator+) Time-Based SQL Injection | ays-pro | Poll Maker – Versus Polls, Anonymous Polls, Image Polls | Medium | 4.9 | 2024-11-09 06:41:30 | Deep Dive |