CVE-2024-2310 exposes the perilous side of WP Google Review Slider. This vulnerability, discovered during plugin testing, transforms innocuous user interactions into a gateway for malicious actors, potentially compromising website security. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).
CVE-2024-3188 – Shortcodes Ultimate – Stored XSS to Admin Account Creation (Contributor+) – POC
Plugin Security Certification: “Metricool” – Version 1.22: Use metrics and analytics with Enhanced Security

Are you looking to harness the power of analytics and metrics for your WordPress website while ensuring top-notch security? Look no further than Metricool, the plugin that seamlessly integrates your WordPress site with Metricool’s comprehensive analytics platform.
With Metricool, you gain valuable insights into your website’s performance and audience engagement. From tracking page views to analyzing social media metrics, Metricool empowers you to make data-driven decisions to optimize your online presence.
CVE-2024-2972 – Floating Chat Widget (Chaty) – Stored XSS to JS backdoor creation – POC

The discovery of CVE-2024-2972 sheds light on the vulnerability within Floating Chat Widget (Chaty), unraveling the potential for Stored XSS exploitation. This flaw raises concerns over website security and the potential for malicious backdoor creation. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).
CVE-2024-3261 – Strong Testimonials – Stored XSS to Admin Account Creation (Contributor+) – POC
CVE-2024-2118 – Social Media Share Buttons – Stored XSS to JS backdoor creation – POC

A critical vulnerability, CVE-2024-2118, threatens WordPress sites using Social Media Share Buttons. This flaw enables malicious actors to execute Stored XSS attacks, opening the door to account takeovers and backdoor creation. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).
Plugin Security Certification: “WP External Links” – Version 2.61: Use links with Enhanced Security

WP External Links, the comprehensive link management plugin, has undergone rigorous security testing and has successfully obtained the Plugin Security Certification (PSC) from CleanTalk. With enhanced security measures, this plugin allows users to manage both internal and external links on their WordPress websites with confidence.
CVE-2024-2309 – WP Staging – Stored XSS to JS backdoor creation – POC

A critical vulnerability, CVE-2024-2309, has been discovered in the WP Staging WordPress plugin, exposing websites to Stored Cross-Site Scripting (XSS) attacks. This flaw allows attackers to execute malicious scripts, potentially leading to the creation of JavaScript backdoors and compromising website integrity. Immediate action is advised to mitigate the risk. This vulnerability allows malicious actors to execute Stored XSS attacks, potentially leading to the creation of JavaScript backdoors, compromising website integrity. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).
CVE-2024-3703 – Carousel Slider – Editor+ Stored XSS – POC

In the digital landscape, vulnerabilities in software can lead to significant security risks. One such vulnerability, CVE-2024-3703, has been discovered in the Carousel Slider plugin for WordPress. This particular vulnerability, categorized as a Stored XSS (Cross-Site Scripting), can enable malicious actors to execute arbitrary code on behalf of contributors, potentially leading to account takeover and other malicious activities. This article delves into the discovery, exploitation, potential risks, and recommendations associated with this vulnerability. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back)