Lucene search

K

Wpdeveloper Security Vulnerabilities

cve
cve

CVE-2024-31306

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Stored XSS.This issue affects Essential Blocks for Gutenberg: from n/a through 4.5.3.

6.5CVSS

9.2AI Score

0.0004EPSS

2024-04-07 06:15 PM
24
cve
cve

CVE-2024-32717

Missing Authorization vulnerability in WPDeveloper SchedulePress.This issue affects SchedulePress: from n/a through 5.0.8.

6.5CVSS

6.8AI Score

0.0004EPSS

2024-05-14 03:37 PM
38
cve
cve

CVE-2024-34764

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 5.9.15.

6.5CVSS

7AI Score

0.0004EPSS

2024-06-03 12:15 PM
32
cve
cve

CVE-2024-3733

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_...

5.3CVSS

6.7AI Score

0.0004EPSS

2024-04-25 09:15 AM
34
cve
cve

CVE-2024-39649

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 5.9.26.

6.5CVSS

6.5AI Score

0.0004EPSS

2024-08-01 10:15 PM
32
cve
cve

CVE-2024-43129

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through 3.5.8.

8.8CVSS

6.5AI Score

0.0005EPSS

2024-08-13 11:15 AM
24
cve
cve

CVE-2024-43227

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper BetterDocs allows Stored XSS.This issue affects BetterDocs: from n/a through 3.5.8.

6.5CVSS

6.4AI Score

0.0004EPSS

2024-08-12 09:15 PM
22
cve
cve

CVE-2024-43328

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through 4.0.9.

8.3CVSS

8.3AI Score

0.0004EPSS

2024-08-19 08:15 PM
25
cve
cve

CVE-2024-43936

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through 4.0.8.

6.5CVSS

6.5AI Score

0.0004EPSS

2024-08-29 06:15 PM
27
cve
cve

CVE-2024-5058

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Typing Text allows Stored XSS.This issue affects Typing Text: from n/a through 1.2.5.

6.5CVSS

6.5AI Score

0.0004EPSS

2024-06-21 12:15 PM
27
cve
cve

CVE-2024-5188

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_manual_calendar_events' function in all versions up to, and including, 5.9.22 due to insufficient input sanitization and...

6.4CVSS

6.1AI Score

0.001EPSS

2024-06-06 11:15 AM
31
cve
cve

CVE-2024-5571

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's EmbedPress PDF widget in all versions up to, and in...

6.4CVSS

6AI Score

0.001EPSS

2024-06-05 09:15 AM
27
cve
cve

CVE-2024-5595

The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

5.4CVSS

5.6AI Score

0.0004EPSS

2024-08-02 06:15 AM
5
cve
cve

CVE-2024-6557

The SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.1.3. This is due the plugin utilizing the wpdeveloper library and le...

5.3CVSS

5.1AI Score

0.001EPSS

2024-07-16 05:15 AM
25
cve
cve

CVE-2024-8440

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output esca...

6.4CVSS

5.7AI Score

0.001EPSS

2024-09-11 07:15 AM
24
cve
cve

CVE-2024-8742

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization ...

6.4CVSS

5.7AI Score

0.001EPSS

2024-09-13 07:15 AM
26
Total number of security vulnerabilities66