Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 121-140 of 837 records
Threat Entry Updated 2025-05-15

CVE-2024-13113 - Before 1 Plugin

The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when outputting them on the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2024-13113

MEDIUM CVSS 5.9 2025-02-26
Threat Entry Updated 2025-05-20

CVE-2024-10563 - Before 1 Plugin

The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2024-10563

MEDIUM CVSS 5.4 2025-02-26
Threat Entry Updated 2025-05-15

CVE-2024-10152 - Before 1 Plugin

The Simple Certain Time to Show Content WordPress plugin before 1.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 1

CVE-2024-10152

HIGH CVSS 7.1 2025-02-26
Threat Entry Updated 2025-05-07

CVE-2024-13605 - Before 1 Plugin

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-13605

MEDIUM CVSS 4.8 2025-02-24
Threat Entry Updated 2025-05-14

CVE-2024-13306 - Before 1 Plugin

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-13306

MEDIUM CVSS 4.3 2025-02-15
Threat Entry Updated 2025-05-14

CVE-2024-13208 - Before 1 Plugin

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-13208

MEDIUM CVSS 4.3 2025-02-15
Threat Entry Updated 2025-05-14

CVE-2024-7052 - Before 1 Plugin

The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2024-7052

MEDIUM CVSS 4.8 2025-02-14
Threat Entry Updated 2025-05-13

CVE-2024-13116 - Before 1 Plugin

The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-13116

LOW CVSS 3.8 2025-01-27
Threat Entry Updated 2025-05-08

CVE-2024-12274 - Before 1 Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).

PLUGIN Before 1

CVE-2024-12274

HIGH CVSS 7.5 2025-01-13
Threat Entry Updated 2025-05-08

CVE-2024-10562 - Before 1 Plugin

The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-10562

LOW CVSS 2.7 2025-01-07
Threat Entry Updated 2025-05-17

CVE-2024-11972 - Before 1 Plugin

The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.

PLUGIN Before 1

CVE-2024-11972

CRITICAL CVSS 9.8 2024-12-31
Threat Entry Updated 2025-05-17

CVE-2024-11842 - Before 1 Plugin

The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Before 1

CVE-2024-11842

MEDIUM CVSS 4.3 2024-12-27
Threat Entry Updated 2025-05-08

CVE-2024-11223 - Before 1 Plugin

The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-11223

MEDIUM CVSS 4.7 2024-12-26
Threat Entry Updated 2025-05-14

CVE-2024-11108 - Before 1 Plugin

The Serious Slider WordPress plugin before 1.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2024-11108

MEDIUM CVSS 5.4 2024-12-20
Threat Entry Updated 2025-05-07

CVE-2024-10704 - Before 1 Plugin

The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-10704

MEDIUM CVSS 4.8 2024-11-29
Threat Entry Updated 2025-11-13

CVE-2024-7056 - Before 1 Plugin

The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2024-7056

LOW CVSS 3.5 2024-11-25
Threat Entry Updated 2025-05-15

CVE-2024-5029 - Before 1 Plugin

The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

PLUGIN Before 1

CVE-2024-5029

MEDIUM CVSS 4.8 2024-11-21
Threat Entry Updated 2025-05-15

CVE-2024-10482 - Before 1 Plugin

The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

PLUGIN Before 1

CVE-2024-10482

MEDIUM CVSS 5.4 2024-11-21
Threat Entry Updated 2025-05-15

CVE-2024-5030 - Before 1 Plugin

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack

PLUGIN Before 1

CVE-2024-5030

LOW CVSS 3.8 2024-11-18
Threat Entry Updated 2024-11-06

CVE-2024-7877 - Before 1 Plugin

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 1

CVE-2024-7877

MEDIUM CVSS 4.8 2024-11-05
Scroll to top