| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-43935 | WordPress WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin <= 1.6.7 - Cross Site Scripting (XSS) vulnerability | WP Delicious | Delicious Recipes – WordPress Recipe Plugin | Medium | 6.5 | 2024-08-29 18:08:32 | Deep Dive |
| CVE-2024-43965 | WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerability | Smackcoders | SendGrid for WordPress | High | 8.2 | 2024-08-29 15:23:13 | Deep Dive |
| CVE-2024-7895 | Beaver Builder (Lite Version) <= 2.8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | Medium | 6.4 | 2024-08-29 10:59:42 | Deep Dive |
| CVE-2024-43117 | WordPress Hummingbird plugin <= 3.9.1 - Cross Site Request Forgery (CSRF) vulnerability | WPMU DEV - Your All-in-One WordPress Platform | Hummingbird | Medium | 4.3 | 2024-08-26 20:50:26 | Deep Dive |
| CVE-2024-43269 | WordPress Backup and Restore WordPress plugin <= 1.50 - Cross Site Request Forgery (CSRF) vulnerability | WPBackItUp | Backup and Restore WordPress | Medium | 4.3 | 2024-08-26 20:48:11 | Deep Dive |
| CVE-2024-43257 | WordPress Leopard plugin <= 2.0.36 - Subscriber+ Sensitive Data Exposure vulnerability | Nouthemes | Leopard - WordPress offload media | Medium | 6.5 | 2024-08-26 20:15:38 | Deep Dive |
| CVE-2024-6499 | WordPress Button Plugin MaxButtons <= 9.7.8 - Full Path Disclosure | maxfoundry | MaxButtons – Create buttons | Medium | 5.3 | 2024-08-24 03:29:24 | Deep Dive |
| CVE-2024-7848 | User Private Files <= 2.1.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private File Access | deepakkite | File Sharing & Download Manager – User Private Files | Medium | 4.3 | 2024-08-22 10:58:41 | Deep Dive |
| CVE-2024-7384 | AcyMailing <= 9.7.2 - Authenticated (Subscriber+) Arbitrary File Upload via acym_extractArchive Function | acyba | AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress | High | 7.5 | 2024-08-22 02:02:02 | Deep Dive |
| CVE-2024-6847 | SmartSearch WP <= 2.4.4 - Unauthenticated SQLi | Unknown | Chatbot with ChatGPT WordPress | - | - | 2024-08-20 06:00:03 | Deep Dive |
| CVE-2024-43256 | WordPress Leopard plugin <= 2.0.36 - Subscriber+ Plugin Settings Change vulnerability | nouthemes | Leopard - WordPress offload media | High | 7.1 | 2024-08-19 17:25:21 | Deep Dive |
| CVE-2024-6843 | SmartSearch WP <= 2.4.4 - Unauthenticated Stored XSS | Unknown | Chatbot with ChatGPT WordPress | - | - | 2024-08-19 06:00:06 | Deep Dive |
| CVE-2024-43335 | WordPress Responsive Blocks – WordPress Gutenberg Blocks plugin <= 1.8.8 - Cross Site Scripting (XSS) vulnerability | CyberChimps | Responsive Blocks – WordPress Gutenberg Blocks | Medium | 6.5 | 2024-08-18 13:39:57 | Deep Dive |
| CVE-2023-5505 | BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal | wp_media | BackWPup – WordPress Backup & Restore Plugin | Medium | 6.8 | 2024-08-17 08:37:24 | Deep Dive |
| CVE-2023-4025 | Radio Player <= 2.0.73 - Missing Authorization to Player Update | princeahmed | Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player | Medium | 5.3 | 2024-08-17 07:34:24 | Deep Dive |
| CVE-2023-4024 | Radio Player <= 2.0.73 - Missing Authorization to Player Deletion | princeahmed | Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player | Medium | 5.3 | 2024-08-17 07:34:21 | Deep Dive |
| CVE-2023-4027 | Radio Player <= 2.0.73 - Missing Authorization to Settings Update | princeahmed | Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player | Medium | 5.3 | 2024-08-17 07:34:20 | Deep Dive |
| CVE-2024-7301 | WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload | nickboss | Iptanus File Upload | High | 7.2 | 2024-08-16 04:29:27 | Deep Dive |
| CVE-2024-43125 | WordPress WP Table Builder plugin <= 1.4.15 - Cross Site Scripting (XSS) vulnerability | WP Table Builder | WP Table Builder – WordPress Table Plugin | Medium | 6.5 | 2024-08-12 22:36:10 | Deep Dive |
| CVE-2024-43224 | WordPress YaMaps for WordPress Plugin plugin <= 0.6.27 - Cross Site Scripting (XSS) vulnerability | Yuri Baranov | YaMaps for WordPress | Medium | 6.5 | 2024-08-12 21:19:35 | Deep Dive |