| CVE-2024-5973 | MasterStudy LMS < 3.3.24 - Privilege Escalation to Instructor | Unknown | MasterStudy LMS WordPress Plugin | - | - | 2024-07-22 06:00:06 | Deep Dive |
| CVE-2024-5004 | CM Popup Plugin for WordPress < 1.6.6 - Contributor+ Stored XSS | Unknown | CM Popup Plugin for WordPress | - | - | 2024-07-22 06:00:02 | Deep Dive |
| CVE-2024-37519 | WordPress Premium Blocks – Gutenberg Blocks for WordPress plugin <= 2.1.27 - Cross Site Scripting (XSS) vulnerability | Leap13 | Premium Blocks – Gutenberg Blocks for WordPress | Medium | 6.5 | 2024-07-21 07:12:58 | Deep Dive |
| CVE-2024-37556 | WordPress WordPress Notification Bar plugin <= 1.3.10 - Cross Site Scripting (XSS) vulnerability | SeedProd | WordPress Notification Bar | Medium | 5.9 | 2024-07-21 06:53:17 | Deep Dive |
| CVE-2024-37918 | WordPress ConeBlog plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerability | WPCone | ConeBlog – WordPress Blog Widgets | Medium | 6.5 | 2024-07-20 09:01:49 | Deep Dive |
| CVE-2024-37946 | WordPress ReCaptcha Integration for WordPress plugin <= 1.2.7 - Cross Site Scripting (XSS) vulnerability | weDevs | ReCaptcha Integration for WordPress | Medium | 5.9 | 2024-07-20 08:49:47 | Deep Dive |
| CVE-2024-37959 | WordPress Power BI Embedded for WordPress plugin <= 1.1.7 - Cross Site Scripting (XSS) vulnerability | Atlas Public Policy | Power BI Embedded for WordPress | Medium | 5.9 | 2024-07-20 08:10:01 | Deep Dive |
| CVE-2024-5703 | Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.26 - Missing Authorization | icegram | Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress | Medium | 4.3 | 2024-07-17 07:32:19 | Deep Dive |
| CVE-2024-6669 | AI ChatBot for WordPress – WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | Medium | 5.5 | 2024-07-17 06:45:11 | Deep Dive |
| CVE-2024-5852 | WordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory Traversal | nickboss | Iptanus File Upload | Medium | 4.3 | 2024-07-16 08:32:30 | Deep Dive |
| CVE-2024-6559 | XCloner <= 4.7.3 - Unauthenticated Full Path Disclosure | watchful | Backup, Restore and Migrate your sites with XCloner | Medium | 5.3 | 2024-07-16 06:43:31 | Deep Dive |
| CVE-2024-5630 | Insert or Embed Articulate Content into WordPress < 4.3000000024 - Author+ Arbitrary File Upload | Unknown | Insert or Embed Articulate Content into WordPress | 中危 | - | 2024-07-15 06:00:02 | Deep Dive |
| CVE-2024-5028 | CM WordPress Search And Replace Plugin < 1.3.9 - Plugin Reset via CSRF | Unknown | CM WordPress Search And Replace Plugin | - | - | 2024-07-13 06:00:07 | Deep Dive |
| CVE-2024-3919 | OpenPGP Form Encryption for WordPress < 1.5.1 - Contributor+ Stored XSS | Unknown | OpenPGP Form Encryption for WordPress | - | - | 2024-07-13 06:00:05 | Deep Dive |
| CVE-2024-3026 | WordPress Button Plugin MaxButtons < 9.7.8 - Editor+ Stored XSS | Unknown | WordPress Button Plugin MaxButtons | - | - | 2024-07-13 06:00:04 | Deep Dive |
| CVE-2024-38704 | WordPress Team Manager plugin <= 2.1.12 - Local File Inclusion vulnerability | DynamicWebLab | WordPress Team Manager | Medium | 6.5 | 2024-07-12 14:07:20 | Deep Dive |
| CVE-2024-37941 | WordPress Internal Link Juicer: SEO Auto Linker for WordPress plugin <= 2.24.3 - Cross Site Request Forgery (CSRF) vulnerability | Internal Link Juicer | Internal Link Juicer: SEO Auto Linker for WordPress | Medium | 4.3 | 2024-07-12 13:42:38 | Deep Dive |
| CVE-2024-6625 | WP Total Branding <= 1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via title Parameter | m_uysl | WP Total Branding – Complete branding solution for WordPress | Medium | 5.5 | 2024-07-12 07:35:10 | Deep Dive |
| CVE-2024-6555 | WP Popups – WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path Disclosure | timersys | WP Popups – WordPress Popup builder | Medium | 5.3 | 2024-07-12 05:32:38 | Deep Dive |
| CVE-2024-6554 | Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure | wpmudev | Branda – White Label & Branding, Free Login Page Customizer | Medium | 5.3 | 2024-07-11 03:33:19 | Deep Dive |