Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15
Critical0
High6
Medium9
Reset
Showing 1-15 of 15 records
Threat Entry Updated 2025-12-29

CVE-2025-13417 - Before 10 Plugin

The Plugin Organizer WordPress plugin before 10.2.4 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers to perform SQL injection attacks.

PLUGIN Before 10

CVE-2025-13417

HIGH CVSS 8.6 2025-12-29
Threat Entry Updated 2025-08-14

CVE-2025-6790 - Before 10 Plugin

The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

PLUGIN Before 10

CVE-2025-6790

MEDIUM CVSS 4.3 2025-08-14
Threat Entry Updated 2025-05-17

CVE-2024-10893 - Before 10 Plugin

The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 10

CVE-2024-10893

MEDIUM CVSS 4.8 2024-12-03
Threat Entry Updated 2025-05-15

CVE-2024-10027 - Before 10 Plugin

The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 10

CVE-2024-10027

MEDIUM CVSS 4.8 2024-11-07
Threat Entry Updated 2025-05-20

CVE-2024-5715 - Before 10 Plugin

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 10

CVE-2024-5715

HIGH CVSS 7.1 2024-07-13
Threat Entry Updated 2025-05-16

CVE-2024-5744 - Before 10 Plugin

The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

PLUGIN Before 10

CVE-2024-5744

MEDIUM CVSS 6.8 2024-07-13
Threat Entry Updated 2025-05-06

CVE-2024-5080 - Before 10 Plugin

The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server

PLUGIN Before 10

CVE-2024-5080

HIGH CVSS 8.8 2024-07-13
Threat Entry Updated 2025-05-06

CVE-2024-5077 - Before 10 Plugin

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Before 10

CVE-2024-5077

MEDIUM CVSS 6.8 2024-07-13
Threat Entry Updated 2025-05-06

CVE-2024-5079 - Before 10 Plugin

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks

PLUGIN Before 10

CVE-2024-5079

MEDIUM CVSS 6.1 2024-07-13
Threat Entry Updated 2025-05-06

CVE-2024-5076 - Before 10 Plugin

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

PLUGIN Before 10

CVE-2024-5076

HIGH CVSS 8.8 2024-07-13
Threat Entry Updated 2025-05-06

CVE-2024-5075 - Before 10 Plugin

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 10

CVE-2024-5075

MEDIUM CVSS 5.9 2024-07-13
Threat Entry Updated 2025-05-02

CVE-2024-5074 - Before 10 Plugin

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 10

CVE-2024-5074

MEDIUM CVSS 5.4 2024-07-13
Threat Entry Updated 2025-06-17

CVE-2024-4749 - Before 10 Plugin

The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

PLUGIN Before 10

CVE-2024-4749

HIGH CVSS 8.3 2024-06-04
Threat Entry Updated 2025-03-21

CVE-2023-0261 - Before 10 Plugin

The WP TripAdvisor Review Slider WordPress plugin before 10.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

PLUGIN Before 10

CVE-2023-0261

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2024-11-21

CVE-2021-24794 - Before 10 Plugin

The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed.

PLUGIN Before 10

CVE-2021-24794

MEDIUM CVSS 4.8 2021-11-01
Scroll to top