Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Custom Block Builder | 0 ~ 3.8.3 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Custom Block Builder WordPress plugin < 3.8.3 contains a reflected cross-site scripting caused by lack of sanitization and escaping of a parameter before output, letting attackers execute malicious scripts in high privilege users' browsers, exploit requires victim to load malicious page. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-12878.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-10152 | Simple Certain Time to Show Content < 1.3.1 - Reflected XSS | |
| CVE-2024-10483 | SimplePress Forum < 6.10.11 - Reflected XSS | |
| CVE-2024-10563 | WooCommerce Cart Count Shortcode < 1.1.0 - Contributor+ XSS | |
| CVE-2024-12737 | WP BASE Booking of Appointments, Services and Events < 5.0.0 - Reflected XSS | |
| CVE-2024-13571 | Post Timeline < 2.3.10 - Reflected XSS | |
| CVE-2024-13113 | Countdown Timer for Elementor < 1.3.7 - Contributor+ Stored XSS | |
| CVE-2024-13624 | WPMovieLibrary <= 2.1.4.8 - Reflected XSS | |
| CVE-2024-13628 | WP Pricing Table <= 1.1 - Reflected XSS | |
| CVE-2024-13632 | WP Extra Fields <= 1.0.1 - Reflected XSS | |
| CVE-2024-13631 | OM Stripe <= 02.00.00 - Reflected XSS | |
| CVE-2024-13630 | News List <= 1.0 - Reflected XSS | |
| CVE-2024-13629 | Pushbiz <= 1.0 - Reflected XSS | |
| CVE-2024-13634 | Post Sync <= 1.1 - Reflected XSS | |
| CVE-2024-13633 | Simple Catalogue <= 1.0.2 - Reflected XSS | |
| CVE-2024-13669 | CalendApp <= 1.1 - Reflected XSS | |
| CVE-2024-13678 | R3W Instafeed <= 1.0 - Reflected XSS |
No comments yet