CVE-2024-30461 – Tumult Hype Animations <= 1.9.11 - Cross-Site Request Forgery to Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2024-30461
The Tumult Hype Animations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.11. This is due to missing or incorrect nonce validation on the hypeanimations_updatecontainer() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2024-30460 may be a duplicate of this issue. • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-2890 – WordPress Tumult Hype Animations plugin <= 1.9.12 - Arbitrary File Upload vulnerability
https://notcve.org/view.php?id=CVE-2024-2890
Unrestricted Upload of File with Dangerous Type vulnerability in Tumult Inc. Tumult Hype Animations.This issue affects Tumult Hype Animations: from n/a through 1.9.12. Carga sin restricciones de archivos con vulnerabilidad de tipo peligroso en Tumult Inc. Tumult Hype Animations. Este problema afecta a Tumult Hype Animations: desde n/a hasta 1.9.12. • https://patchstack.com/database/vulnerability/tumult-hype-animations/wordpress-tumult-hype-animations-plugin-1-9-12-arbitrary-file-upload-vulnerability?_s_id=cve • CWE-434: Unrestricted Upload of File with Dangerous Type •