Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 161-180 of 837 records
Threat Entry Updated 2025-08-22

CVE-2024-1287 - Before 1 Plugin

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

PLUGIN Before 1

CVE-2024-1287

MEDIUM CVSS 6.5 2024-07-30
Threat Entry Updated 2025-04-10

CVE-2024-5882 - Before 1 Plugin

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

PLUGIN Before 1

CVE-2024-5882

HIGH CVSS 7.5 2024-07-29
Threat Entry Updated 2025-04-10

CVE-2024-5883 - Before 1 Plugin

The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2024-5883

MEDIUM CVSS 4.7 2024-07-29
Threat Entry Updated 2025-03-19

CVE-2024-6244 - Before 1 Plugin

The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

PLUGIN Before 1

CVE-2024-6244

HIGH CVSS 8.8 2024-07-22
Threat Entry Updated 2024-11-21

CVE-2024-6271 - Before 1 Plugin

The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack

PLUGIN Before 1

CVE-2024-6271

MEDIUM CVSS 5.4 2024-07-22
Threat Entry Updated 2026-01-30

CVE-2024-6243 - Before 1 Plugin

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

PLUGIN Before 1

CVE-2024-6243

MEDIUM CVSS 4.8 2024-07-22
Threat Entry Updated 2024-11-21

CVE-2024-5004 - Before 1 Plugin

The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2024-5004

MEDIUM CVSS 4.8 2024-07-22
Threat Entry Updated 2025-03-17

CVE-2024-6289 - Before 1 Plugin

The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

PLUGIN Before 1

CVE-2024-6289

MEDIUM CVSS 6.1 2024-07-15
Threat Entry Updated 2025-05-20

CVE-2024-5713 - Before 1 Plugin

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

PLUGIN Before 1

CVE-2024-5713

MEDIUM CVSS 5.4 2024-07-13
Threat Entry Updated 2025-05-16

CVE-2024-6070 - Before 1 Plugin

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2024-6070

MEDIUM CVSS 4.8 2024-07-13
Threat Entry Updated 2025-05-13

CVE-2024-5167 - Before 1 Plugin

The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist menu via a CSRF attack

PLUGIN Before 1

CVE-2024-5167

HIGH CVSS 8.1 2024-07-13
Threat Entry Updated 2025-06-13

CVE-2024-4977 - Before 1 Plugin

The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2024-4977

MEDIUM CVSS 6.8 2024-07-13
Threat Entry Updated 2025-05-13

CVE-2024-5028 - Before 1 Plugin

The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

PLUGIN Before 1

CVE-2024-5028

MEDIUM CVSS 6.5 2024-07-13
Threat Entry Updated 2025-05-15

CVE-2024-4272 - Before 1 Plugin

The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

PLUGIN Before 1

CVE-2024-4272

MEDIUM CVSS 6.1 2024-07-13
Threat Entry Updated 2025-05-15

CVE-2024-4269 - Before 1 Plugin

The SVG Block WordPress plugin before 1.1.20 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

PLUGIN Before 1

CVE-2024-4269

MEDIUM CVSS 6.1 2024-07-13
Threat Entry Updated 2025-05-15

CVE-2024-4602 - Before 1 Plugin

The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2024-4602

MEDIUM CVSS 5.4 2024-07-13
Threat Entry Updated 2025-05-15

CVE-2024-3632 - Before 1 Plugin

The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Before 1

CVE-2024-3632

MEDIUM CVSS 6.8 2024-07-13
Threat Entry Updated 2025-06-09

CVE-2024-3963 - Before 1 Plugin

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2024-3963

MEDIUM CVSS 6.5 2024-07-13
Threat Entry Updated 2025-05-13

CVE-2024-3753 - Before 1 Plugin

The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2024-3753

MEDIUM CVSS 5.9 2024-07-13
Threat Entry Updated 2025-05-13

CVE-2024-3919 - Before 1 Plugin

The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2024-3919

MEDIUM CVSS 4.6 2024-07-13
Scroll to top