Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 121-140 of 472 records
Threat Entry Updated 2024-10-07

CVE-2024-5417 - Before 3 Plugin

The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2024-5417

MEDIUM CVSS 5.4 2024-08-29
Threat Entry Updated 2025-05-17

CVE-2024-6715 - Before 3 Plugin

The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39

PLUGIN Before 3

CVE-2024-6715

MEDIUM CVSS 6.1 2024-08-23
Threat Entry Updated 2025-05-27

CVE-2024-6884 - Before 3 Plugin

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2024-6884

MEDIUM CVSS 5.4 2024-08-08
Threat Entry Updated 2024-09-05

CVE-2024-6710 - Before 3 Plugin

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

PLUGIN Before 3

CVE-2024-6710

MEDIUM CVSS 5.4 2024-08-05
Threat Entry Updated 2025-06-10

CVE-2024-6536 - Before 3 Plugin

The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2024-6536

MEDIUM CVSS 5.4 2024-07-30
Threat Entry Updated 2025-05-30

CVE-2024-6366 - Before 3 Plugin

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

PLUGIN Before 3

CVE-2024-6366

CRITICAL CVSS 9.1 2024-07-29
Threat Entry Updated 2025-05-30

CVE-2024-6487 - Before 3 Plugin

The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2024-6487

MEDIUM CVSS 5.9 2024-07-29
Threat Entry Updated 2025-05-29

CVE-2024-6362 - Before 3 Plugin

The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2024-6362

MEDIUM CVSS 4.6 2024-07-29
Threat Entry Updated 2025-05-16

CVE-2024-4260 - Before 3 Plugin

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.

PLUGIN Before 3

CVE-2024-4260

MEDIUM CVSS 6.5 2024-07-23
Threat Entry Updated 2025-03-18

CVE-2024-5529 - Before 3 Plugin

The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2024-5529

MEDIUM CVSS 4.8 2024-07-22
Threat Entry Updated 2025-05-13

CVE-2024-5472 - Before 3 Plugin

The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2024-5472

HIGH CVSS 7.1 2024-07-13
Threat Entry Updated 2025-05-13

CVE-2024-5575 - Before 3 Plugin

The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 3

CVE-2024-5575

MEDIUM CVSS 4.7 2024-07-13
Threat Entry Updated 2025-05-13

CVE-2024-5442 - Before 3 Plugin

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2024-5442

MEDIUM CVSS 5.9 2024-07-13
Threat Entry Updated 2025-05-13

CVE-2024-3964 - Before 3 Plugin

The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2024-3964

MEDIUM CVSS 5.9 2024-07-13
Threat Entry Updated 2025-05-13

CVE-2024-3710 - Before 3 Plugin

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2024-3710

MEDIUM CVSS 6.8 2024-07-13
Threat Entry Updated 2025-05-13

CVE-2024-3751 - Before 3 Plugin

The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2024-3751

MEDIUM CVSS 4.8 2024-07-13
Threat Entry Updated 2024-11-21

CVE-2024-5626 - Before 3 Plugin

The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2024-5626

MEDIUM CVSS 6.1 2024-07-12
Threat Entry Updated 2024-11-21

CVE-2024-2640 - Before 3 Plugin

The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2024-2640

MEDIUM CVSS 5.4 2024-07-12
Threat Entry Updated 2024-11-21

CVE-2024-4655 - Before 3 Plugin

The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2024-4655

MEDIUM CVSS 5.4 2024-07-11
Threat Entry Updated 2024-11-21

CVE-2024-4664 - Before 3 Plugin

The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Before 3

CVE-2024-4664

MEDIUM CVSS 4.8 2024-06-27
Scroll to top