| CVE-2024-3239 | PostX < 4.0.2 - Contributor+ Stored XSS | Unknown | Post Grid Gutenberg Blocks and WordPress Blog Plugin | 中危 | - | 2024-05-13 06:00:01 | Deep Dive |
| CVE-2024-4560 | Kognetiks Chatbot for WordPress <= 1.9.9 - Unauthenticated Arbitrary File Upload via chatbot_chatgpt_upload_file_to_assistant Function | kognetiks | Kognetiks Chatbot for WordPress | Critical | 9.8 | 2024-05-11 05:38:42 | Deep Dive |
| CVE-2024-4630 | Starter Templates — Elementor, WordPress & Beaver Builder Templates <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | brainstormforce | Starter Templates – AI-Powered Templates for Elementor & Gutenberg | Medium | 6.4 | 2024-05-11 04:30:18 | Deep Dive |
| CVE-2024-4430 | Beaver Builder <= 2.8.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via photo widget crop attribute | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | Medium | 6.4 | 2024-05-10 21:32:43 | Deep Dive |
| CVE-2024-4417 | Falang multilanguage for WordPress <= 1.3.49 - Authenticated (Administrator+) Stored Cross-Site Scripting | sbouey | Falang multilanguage for WordPress | Medium | 4.4 | 2024-05-10 21:32:42 | Deep Dive |
| CVE-2024-4277 | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 6.4 | 2024-05-10 09:32:09 | Deep Dive |
| CVE-2024-4444 | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 5.3 | 2024-05-10 08:32:35 | Deep Dive |
| CVE-2024-4434 | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Critical | 9.8 | 2024-05-10 08:32:33 | Deep Dive |
| CVE-2024-4398 | HTML5 Audio Player- Best WordPress Audio Player Plugin <= 2.2.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets | bplugins | HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player | Medium | 6.4 | 2024-05-10 07:33:39 | Deep Dive |
| CVE-2024-4397 | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | High | 8.8 | 2024-05-09 20:03:42 | Deep Dive |
| CVE-2024-1467 | Starter Templates — Elementor, WordPress & Beaver Builder Templates <= 4.1.6 - Authenticated (Contributor+) Server-Side Request Forgery | brainstormforce | Starter Templates – AI-Powered Templates for Elementor & Gutenberg | Medium | 4.3 | 2024-05-09 20:03:40 | Deep Dive |
| CVE-2024-4082 | Joli FAQ SEO – WordPress FAQ Plugin <= 1.3.2 - Cross-Site Request Forgery | wpjoli | Joli FAQ SEO – WordPress FAQ Plugin | Medium | 4.3 | 2024-05-09 20:03:38 | Deep Dive |
| CVE-2024-3923 | Beaver Builder – WordPress Page Builder <= 2.8.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | Medium | 6.4 | 2024-05-09 20:03:36 | Deep Dive |
| CVE-2024-4312 | Soccer Engine – Soccer Plugin for WordPress <= 1.12 - Cross-Site Request Forgery | daext | Soccer Engine – Soccer Plugin for WordPress | Medium | 4.3 | 2024-05-09 20:03:28 | Deep Dive |
| CVE-2024-34418 | WordPress WPCS ( WordPress Custom Search ) plugin <= 1.1 - Cross Site Scripting (XSS) vulnerability | Tech9logy Creators | WPCS ( WordPress Custom Search ) | Medium | 5.9 | 2024-05-09 11:32:12 | Deep Dive |
| CVE-2024-34420 | WordPress Comments Evolved for WordPress plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerability | talspotim | Comments Evolved for WordPress | Medium | 5.9 | 2024-05-09 11:29:45 | Deep Dive |
| CVE-2024-34423 | WordPress Forty Four – 404 Plugin for WordPress plugin <= 1.4 - Cross Site Scripting (XSS) vulnerability | phpbits | Forty Four – 404 Plugin for WordPress | Medium | 5.9 | 2024-05-09 11:22:49 | Deep Dive |
| CVE-2022-40218 | WordPress TH Advance Product Search plugin <= 1.1.4 - Unauthenticated Plugin Settings Change vulnerability | ThemeHunk | Advance WordPress Search Plugin | Medium | 6.5 | 2024-05-08 11:57:45 | Deep Dive |
| CVE-2024-34561 | WordPress Real3D Flipbook PDF Viewer Lite plugin <= 3.71 - Cross Site Scripting (XSS) vulnerability | Creative interactive media | 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin | Medium | 5.9 | 2024-05-08 11:09:42 | Deep Dive |
| CVE-2024-34573 | WordPress Pootle Pagebuilder plugin <= 5.7.1 - Cross Site Scripting (XSS) vulnerability | Pootlepress | Pootle Pagebuilder – WordPress Page builder | Medium | 6.5 | 2024-05-08 09:00:31 | Deep Dive |