A vulnerability classified as problematic was found in Widget4Call Plugin up to 1.0.7 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-13099. The attack can be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Email Newsletter Plugin up to 1.1 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-13098. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in Responsive iframe Plugin up to 1.2.0 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component Block Option Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-12768. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in WP Finance Plugin up to 1.3.6 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-13096. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Dell PowerProtect DD up to 7.10.1.40/7.13.1.10/8.1.0.10. It has been classified as problematic. This affects an unknown part. The manipulation leads to path traversal: '\..\filename'.
This vulnerability is uniquely identified as CVE-2024-51534. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Dell PowerProtect DD up to 7.10.1.40/7.13.1.10/8.1.0.10 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to insufficient granularity of access control.
This vulnerability is handled as CVE-2024-53295. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in WP Finance Plugin up to 1.3.6 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-13097. The attack can be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in aThemes Addons for Elementor Plugin up to 1.0.12 on WordPress. Affected is an unknown function of the component Image Accordion Widget. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-13547. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in dsky Site Search 360 Plugin up to 2.1.6 on WordPress. This issue affects the function ss360-resultblock of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-11780. The attack may be initiated remotely. There is no exploit available.
U.S. and Dutch law enforcement agencies have announced that they have dismantled 39 domains and their associated servers as part of efforts to disrupt a network of online marketplaces originating from Pakistan.
The action, which took place on January 29, 2025, has been codenamed Operation Heart Blocker.
The vast array of sites in question peddled phishing toolkits and fraud-enabling tools and
A vulnerability classified as problematic was found in posimyththemes Plus Addons for Elementor Plugin up to 6.1.8 on WordPress. This vulnerability affects unknown code of the component Table Widget. The manipulation of the argument searchable_label leads to cross site scripting.
This vulnerability was named CVE-2024-11829. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Dell PowerProtect DD up to 7.10.1.40/7.13.1.10. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2024-53296. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in dcooperman MagicForm Plugin up to 1.6.2 on WordPress. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2025-0939. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in wpjobportal WP Job Portal Plugin up to 2.2.6 on WordPress. It has been classified as problematic. Affected is the function deleteCompanyLogo. The manipulation leads to authorization bypass.
This vulnerability is traded as CVE-2024-13428. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in wpjobportal WP Job Portal Plugin up to 2.2.6 on WordPress and classified as problematic. This issue affects the function getresumefiledownloadbyid/getallresumefiles. The manipulation leads to authorization bypass.
The identification of this vulnerability is CVE-2024-13372. The attack may be initiated remotely. There is no exploit available.
A vulnerability has been found in wpjobportal WP Job Portal Plugin up to 2.2.6 on WordPress and classified as problematic. This vulnerability affects the function sendEmailToJobSeeker. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-13371. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in brechtvds Custom Related Posts Plugin up to 1.7.3 on WordPress. This affects an unknown part. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-12825. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in artbees Jupiter X Core Plugin up to 4.8.7 on WordPress. Affected by this issue is some unknown functionality of the component Inline SVG Handler. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2025-0365. The attack may be launched remotely. There is no exploit available.