Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 181-200 of 664 records
Threat Entry Updated 2025-05-08

CVE-2023-7201 - Before 2 Plugin

The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

PLUGIN Before 2

CVE-2023-7201

MEDIUM CVSS 6.5 2024-04-15
Threat Entry Updated 2025-05-08

CVE-2024-1746 - Before 2 Plugin

The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2024-1746

MEDIUM CVSS 5.4 2024-04-15
Threat Entry Updated 2025-04-08

CVE-2024-1306 - Before 2 Plugin

The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as editing entries, and we consider it a medium risk.

PLUGIN Before 2

CVE-2024-1306

MEDIUM CVSS 5.4 2024-04-15
Threat Entry Updated 2025-04-08

CVE-2024-1712 - Before 2 Plugin

The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2024-1712

MEDIUM CVSS 4.7 2024-04-15
Threat Entry Updated 2025-05-09

CVE-2024-0881 - Before 2 Plugin

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

PLUGIN Before 2

CVE-2024-0881

MEDIUM CVSS 5.4 2024-04-11
Threat Entry Updated 2025-05-08

CVE-2024-2428 - Before 2 Plugin

The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks

PLUGIN Before 2

CVE-2024-2428

MEDIUM CVSS 4.7 2024-04-10
Threat Entry Updated 2025-05-13

CVE-2024-1664 - Before 2 Plugin

The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2024-1664

MEDIUM CVSS 6.1 2024-04-09
Threat Entry Updated 2025-05-19

CVE-2024-1956 - Before 2 Plugin

The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2024-1956

MEDIUM CVSS 6.1 2024-04-08
Threat Entry Updated 2025-05-19

CVE-2024-1958 - Before 2 Plugin

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users

PLUGIN Before 2

CVE-2024-1958

MEDIUM CVSS 4.8 2024-04-08
Threat Entry Updated 2025-05-19

CVE-2024-1292 - Before 2 Plugin

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2024-1292

MEDIUM CVSS 4.7 2024-04-08
Threat Entry Updated 2025-05-07

CVE-2024-1745 - Before 2 Plugin

The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress plugin before 2.3.7 settings, making it possible for users with at least the Author role to edit them.

PLUGIN Before 2

CVE-2024-1745

MEDIUM CVSS 4.3 2024-03-26
Threat Entry Updated 2025-04-01

CVE-2024-1962 - Before 2 Plugin

The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack

PLUGIN Before 2

CVE-2024-1962

HIGH CVSS 8.8 2024-03-25
Threat Entry Updated 2025-04-01

CVE-2024-1231 - Before 2 Plugin

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack

PLUGIN Before 2

CVE-2024-1231

MEDIUM CVSS 6.8 2024-03-25
Threat Entry Updated 2025-04-01

CVE-2024-1232 - Before 2 Plugin

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete downloads via a CSRF attack

PLUGIN Before 2

CVE-2024-1232

MEDIUM CVSS 4.8 2024-03-25
Threat Entry Updated 2025-06-27

CVE-2024-1564 - Before 2 Plugin

The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode

PLUGIN Before 2

CVE-2024-1564

MEDIUM CVSS 4.3 2024-03-25
Threat Entry Updated 2025-05-05

CVE-2023-7246 - Before 2 Plugin

The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2023-7246

MEDIUM CVSS 5.4 2024-03-20
Threat Entry Updated 2025-03-28

CVE-2024-0820 - Before 2 Plugin

The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2024-0820

MEDIUM CVSS 5.4 2024-03-18
Threat Entry Updated 2025-05-09

CVE-2024-1290 - Before 2 Plugin

The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and leak, valid password reset URLs, which they can use to take over any accounts.

PLUGIN Before 2

CVE-2024-1290

MEDIUM CVSS 6.5 2024-03-11
Threat Entry Updated 2025-05-01

CVE-2024-1068 - Before 2 Plugin

The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins.

PLUGIN Before 2

CVE-2024-1068

HIGH CVSS 7.2 2024-03-11
Threat Entry Updated 2025-05-01

CVE-2024-0561 - Before 2 Plugin

The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2024-0561

MEDIUM CVSS 5.4 2024-03-11
Scroll to top