Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 141-160 of 472 records
Threat Entry Updated 2025-03-26

CVE-2024-4149 - Before 3 Plugin

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2024-4149

MEDIUM CVSS 4.8 2024-06-13
Threat Entry Updated 2024-11-21

CVE-2024-4145 - Before 3 Plugin

The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks (such as within a multi-site network).

PLUGIN Before 3

CVE-2024-4145

HIGH CVSS 7.2 2024-06-13
Threat Entry Updated 2025-05-30

CVE-2024-4924 - Before 3 Plugin

The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2024-4924

MEDIUM CVSS 6.1 2024-06-12
Threat Entry Updated 2025-05-21

CVE-2024-4057 - Before 3 Plugin

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2024-4057

MEDIUM CVSS 6.1 2024-06-04
Threat Entry Updated 2025-05-21

CVE-2024-4469 - Before 3 Plugin

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.

PLUGIN Before 3

CVE-2024-4469

HIGH CVSS 7.5 2024-05-31
Threat Entry Updated 2025-05-21

CVE-2024-3939 - Before 3 Plugin

The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2024-3939

MEDIUM CVSS 5.4 2024-05-27
Threat Entry Updated 2025-05-21

CVE-2024-2744 - Before 3 Plugin

The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 3

CVE-2024-2744

MEDIUM CVSS 4.3 2024-05-17
Threat Entry Updated 2025-05-14

CVE-2024-3241 - Before 3 Plugin

The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2024-3241

MEDIUM CVSS 5.4 2024-05-14
Threat Entry Updated 2026-01-09

CVE-2023-5971 - Before 3 Plugin

The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2023-5971

MEDIUM CVSS 4.8 2024-05-14
Threat Entry Updated 2025-05-08

CVE-2024-3475 - Before 3 Plugin

The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

PLUGIN Before 3

CVE-2024-3475

HIGH CVSS 7.5 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-3471 - Before 3 Plugin

The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack

PLUGIN Before 3

CVE-2024-3471

LOW CVSS 3.4 2024-05-02
Threat Entry Updated 2025-04-14

CVE-2024-2837 - Before 3 Plugin

The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 3

CVE-2024-2837

MEDIUM CVSS 5.4 2024-04-26
Threat Entry Updated 2025-05-08

CVE-2024-2159 - Before 3 Plugin

The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2024-2159

MEDIUM CVSS 4.7 2024-04-26
Threat Entry Updated 2025-05-08

CVE-2024-3261 - Before 3 Plugin

The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The attack requires a specific view to be performed

PLUGIN Before 3

CVE-2024-3261

MEDIUM CVSS 4.8 2024-04-24
Threat Entry Updated 2025-05-08

CVE-2024-2972 - Before 3 Plugin

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2024-2972

LOW CVSS 3.8 2024-04-24
Threat Entry Updated 2025-05-30

CVE-2024-2761 - Before 3 Plugin

The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.

PLUGIN Before 3

CVE-2024-2761

MEDIUM CVSS 6.8 2024-04-19
Threat Entry Updated 2025-05-30

CVE-2024-2309 - Before 3 Plugin

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.4.0, wp-staging-pro WordPress plugin before 5.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2024-2309

MEDIUM CVSS 4.8 2024-04-17
Threat Entry Updated 2025-05-08

CVE-2024-1849 - Before 3 Plugin

The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL

PLUGIN Before 3

CVE-2024-1849

MEDIUM CVSS 5.4 2024-04-15
Threat Entry Updated 2025-05-08

CVE-2024-1660 - Before 3 Plugin

The Top Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2024-1660

MEDIUM CVSS 4.8 2024-04-15
Scroll to top