Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 181-200 of 837 records
Threat Entry Updated 2024-11-21

CVE-2024-5811 - Before 1 Plugin

The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2024-5811

MEDIUM CVSS 5.4 2024-07-12
Threat Entry Updated 2024-11-21

CVE-2024-4753 - Before 1 Plugin

The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2024-4753

MEDIUM CVSS 4.8 2024-07-12
Threat Entry Updated 2024-11-21

CVE-2024-3112 - Before 1 Plugin

The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

PLUGIN Before 1

CVE-2024-3112

MEDIUM CVSS 4.8 2024-07-12
Threat Entry Updated 2024-11-21

CVE-2024-1845 - Before 1 Plugin

The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

PLUGIN Before 1

CVE-2024-1845

HIGH CVSS 8.8 2024-07-11
Threat Entry Updated 2024-11-21

CVE-2024-6026 - Before 1 Plugin

The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access to the Sliders (by default Administrator, however this can be changed via the Slider by 10Web WordPress plugin before 1.2.56's options) and the ability to add images (Editor+) to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2024-6026

MEDIUM CVSS 5.4 2024-07-11
Threat Entry Updated 2025-05-21

CVE-2024-3410 - Before 1 Plugin

The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2024-3410

MEDIUM CVSS 4.3 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-4627 - Before 1 Plugin

The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager feature of the Rank Math SEO WordPress plugin before 1.0.219) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-4627

MEDIUM CVSS 5.4 2024-07-02
Threat Entry Updated 2025-05-01

CVE-2024-6130 - Before 1 Plugin

The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2024-6130

MEDIUM CVSS 4.8 2024-07-01
Threat Entry Updated 2024-11-21

CVE-2024-3111 - Before 1 Plugin

The Interactive Content WordPress plugin before 1.15.8 does not validate uploads which could allow a Contributors and above to update malicious SVG files, leading to Stored Cross-Site Scripting issues

PLUGIN Before 1

CVE-2024-3111

MEDIUM CVSS 5.4 2024-06-27
Threat Entry Updated 2025-05-13

CVE-2024-3236 - Before 1 Plugin

The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2024-3236

MEDIUM CVSS 5.4 2024-06-17
Threat Entry Updated 2025-03-25

CVE-2024-3552 - Before 1 Plugin

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.

PLUGIN Before 1

CVE-2024-3552

CRITICAL CVSS 9.8 2024-06-13
Threat Entry Updated 2025-05-05

CVE-2024-2749 - Before 1 Plugin

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example) despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 configurations.

PLUGIN Before 1

CVE-2024-2749

MEDIUM CVSS 5.9 2024-05-14
Threat Entry Updated 2025-05-05

CVE-2024-2441 - Before 1 Plugin

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.

PLUGIN Before 1

CVE-2024-2441

HIGH CVSS 8.1 2024-05-14
Threat Entry Updated 2025-05-08

CVE-2024-3692 - Before 1 Plugin

The Gutenverse WordPress plugin before 1.9.1 does not validate the htmlTag option in various of its block before outputting it back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2024-3692

MEDIUM CVSS 6.1 2024-05-03
Threat Entry Updated 2025-05-08

CVE-2024-3481 - Before 1 Plugin

The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks

PLUGIN Before 1

CVE-2024-3481

MEDIUM CVSS 5.2 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-2908 - Before 1 Plugin

The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-2908

MEDIUM CVSS 4.3 2024-04-26
Threat Entry Updated 2024-11-21

CVE-2024-2404 - Before 1 Plugin

The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow low privilege users such as Subscribers to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2024-2404

MEDIUM CVSS 5.4 2024-04-24
Threat Entry Updated 2025-05-08

CVE-2024-2402 - Before 1 Plugin

The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2024-2402

MEDIUM CVSS 5.4 2024-04-24
Threat Entry Updated 2025-04-07

CVE-2024-2322 - Before 1 Plugin

The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admins delete arbitrary email templates as well as delete and unsubscribe users from abandoned orders via CSRF attacks.

PLUGIN Before 1

CVE-2024-2322

MEDIUM CVSS 6.8 2024-04-03
Threat Entry Updated 2025-05-07

CVE-2024-2278 - Before 1 Plugin

Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2024-2278

MEDIUM CVSS 6.1 2024-04-01
Scroll to top