Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total291
Critical15
High59
Medium208
Reset
Showing 81-100 of 291 records
Threat Entry Updated 2024-11-21

CVE-2024-6094 - Before 4 Plugin

The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2024-6094

MEDIUM CVSS 4.8 2024-07-24
Threat Entry Updated 2024-11-21

CVE-2024-5630 - Before 4 Plugin

The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

PLUGIN Before 4

CVE-2024-5630

HIGH CVSS 8.8 2024-07-15
Threat Entry Updated 2025-05-13

CVE-2024-5644 - Before 4 Plugin

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 4

CVE-2024-5644

MEDIUM CVSS 5.4 2024-07-13
Threat Entry Updated 2025-05-13

CVE-2024-5627 - Before 4 Plugin

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks.

PLUGIN Before 4

CVE-2024-5627

MEDIUM CVSS 5.4 2024-07-13
Threat Entry Updated 2025-05-13

CVE-2024-5151 - Before 4 Plugin

The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 4

CVE-2024-5151

HIGH CVSS 7.1 2024-07-13
Threat Entry Updated 2025-05-02

CVE-2024-5034 - Before 4 Plugin

The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

PLUGIN Before 4

CVE-2024-5034

HIGH CVSS 8.8 2024-07-13
Threat Entry Updated 2025-05-02

CVE-2024-5033 - Before 4 Plugin

The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Before 4

CVE-2024-5033

MEDIUM CVSS 5.9 2024-07-13
Threat Entry Updated 2025-05-02

CVE-2024-5032 - Before 4 Plugin

The SULly WordPress plugin before 4.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 4

CVE-2024-5032

MEDIUM CVSS 4.7 2024-07-13
Threat Entry Updated 2025-06-10

CVE-2024-0974 - Before 4 Plugin

The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 4

CVE-2024-0974

MEDIUM CVSS 4.8 2024-07-12
Threat Entry Updated 2024-11-21

CVE-2024-6138 - Before 4 Plugin

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2024-6138

MEDIUM CVSS 4.8 2024-07-11
Threat Entry Updated 2025-05-13

CVE-2024-4305 - Before 4 Plugin

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 4

CVE-2024-4305

MEDIUM CVSS 6.8 2024-06-17
Threat Entry Updated 2024-11-21

CVE-2024-3288 - Before 4 Plugin

The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 4

CVE-2024-3288

MEDIUM CVSS 5.4 2024-06-07
Threat Entry Updated 2025-04-18

CVE-2024-4061 - Before 4 Plugin

The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 4

CVE-2024-4061

MEDIUM CVSS 4.8 2024-05-21
Threat Entry Updated 2025-05-21

CVE-2024-2189 - Before 4 Plugin

The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 4

CVE-2024-2189

MEDIUM CVSS 6.1 2024-05-21
Threat Entry Updated 2025-05-21

CVE-2024-3368 - Before 4 Plugin

The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 4

CVE-2024-3368

MEDIUM CVSS 6.1 2024-05-20
Threat Entry Updated 2025-05-14

CVE-2024-3239 - Before 4 Plugin

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 4

CVE-2024-3239

MEDIUM CVSS 5.4 2024-05-14
Threat Entry Updated 2025-06-17

CVE-2024-1076 - Before 4 Plugin

The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

PLUGIN Before 4

CVE-2024-1076

MEDIUM CVSS 6.5 2024-05-08
Threat Entry Updated 2025-05-08

CVE-2024-3476 - Before 4 Plugin

The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

PLUGIN Before 4

CVE-2024-3476

HIGH CVSS 8.8 2024-05-02
Threat Entry Updated 2025-03-25

CVE-2024-3474 - Before 4 Plugin

The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

PLUGIN Before 4

CVE-2024-3474

HIGH CVSS 8.8 2024-05-02
Threat Entry Updated 2025-05-13

CVE-2024-1846 - Before 4 Plugin

The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 4

CVE-2024-1846

MEDIUM CVSS 5.4 2024-04-15
Scroll to top