Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 2021-2040 of 3408 records
Threat Entry Updated 2024-10-02

CVE-2024-8741 - Changeset Plugin

The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2024-8741

MEDIUM CVSS 6.1 2024-09-25
Threat Entry Updated 2024-10-02

CVE-2024-8621 - Changeset Plugin

The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2024-8621

CRITICAL CVSS 9.9 2024-09-25
Threat Entry Updated 2024-10-02

CVE-2024-8549 - Changeset Plugin

The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2024-8549

MEDIUM CVSS 6.1 2024-09-25
Threat Entry Updated 2024-10-02

CVE-2024-8476 - Changeset Plugin

The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the wpeevent_plugin_buttons() function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2024-8476

MEDIUM CVSS 4.3 2024-09-25
Threat Entry Updated 2024-12-17

CVE-2024-8434 - Changeset Plugin

The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform actions like updating plugin settings.

PLUGIN Changeset

CVE-2024-8434

MEDIUM CVSS 4.3 2024-09-25
Threat Entry Updated 2024-09-30

CVE-2024-8917 - Changeset Plugin

The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.16.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Changeset

CVE-2024-8917

MEDIUM CVSS 6.4 2024-09-25
Threat Entry Updated 2024-09-30

CVE-2024-8801 - Changeset Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including private, draft, and pending Elementor templates.

PLUGIN Changeset

CVE-2024-8801

MEDIUM CVSS 4.3 2024-09-25
Threat Entry Updated 2025-08-26

CVE-2024-8267 - Changeset Plugin

The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute within the 'wp:radio-player' Gutenberg block in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-8267

MEDIUM CVSS 6.4 2024-09-25
Threat Entry Updated 2024-09-30

CVE-2023-5359 - Changeset Plugin

The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account information in successful conditions. This would not impact the WordPress users site in any way.

PLUGIN Changeset

CVE-2023-5359

LOW CVSS 3.7 2024-09-25
Threat Entry Updated 2024-09-26

CVE-2024-8791 - Changeset Plugin

The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID parameter is supplied through the update_core_user() function. This makes it possible for unauthenticated attackers to update the email address and password of arbitrary user accounts, including administrators, which can then be used to log in to those user accounts.

PLUGIN Changeset

CVE-2024-8791

CRITICAL CVSS 9.8 2024-09-24
Threat Entry Updated 2024-09-26

CVE-2024-8794 - Changeset Plugin

The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to the reset_user_password() function not verifying a user's identity prior to setting a password. This makes it possible for unauthenticated attackers to reset any user's passwords, including administrators. It's important to note that the attacker will not have access to the generated password, therefore, privilege escalation is not possible.

PLUGIN Changeset

CVE-2024-8794

MEDIUM CVSS 5.3 2024-09-24
Threat Entry Updated 2024-09-26

CVE-2024-8628 - Changeset Plugin

The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-meta' shortcode in all versions up to, and including, 1.2.70.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-8628

MEDIUM CVSS 5.4 2024-09-24
Threat Entry Updated 2024-09-26

CVE-2024-8716 - Changeset Plugin

The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2024-8716

MEDIUM CVSS 6.1 2024-09-24
Threat Entry Updated 2024-09-27

CVE-2024-8662 - Changeset Plugin

The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.12. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2024-8662

MEDIUM CVSS 6.1 2024-09-24
Threat Entry Updated 2024-09-27

CVE-2024-8432 - Changeset Plugin

The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_appearance() function in all versions up to, and including, 5.0.48. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the booking form's CSS.

PLUGIN Changeset

CVE-2024-8432

MEDIUM CVSS 4.3 2024-09-24
Threat Entry Updated 2024-09-25

CVE-2024-8853 - Changeset Plugin

The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.

PLUGIN Changeset

CVE-2024-8853

CRITICAL CVSS 9.8 2024-09-20
Threat Entry Updated 2024-09-25

CVE-2024-6641 - Changeset Plugin

The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 1.2.6. This is due to use of an incorrect regular expression within the "Stop User Enumeration" feature. This makes it possible for unauthenticated attackers to bypass intended security restrictions and expose site usernames.

PLUGIN Changeset

CVE-2024-6641

MEDIUM CVSS 5.3 2024-09-18
Threat Entry Updated 2024-09-27

CVE-2024-8761 - Changeset Plugin

The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient validation on the redirect url supplied via the link parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

PLUGIN Changeset

CVE-2024-8761

HIGH CVSS 7.2 2024-09-17
Threat Entry Updated 2024-09-27

CVE-2024-8490 - Changeset Plugin

The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email address, and password of an administrator account via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2024-8490

HIGH CVSS 8.8 2024-09-17
Threat Entry Updated 2024-09-27

CVE-2024-6482 - Changeset Plugin

The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the 'lwp_update_password_action' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to any other role, including Administrator. The vulnerability was partially patched in version 1.7.40. The login with phone number pro plugin was required to exploit the vulnerability in versions 1.7.40 - 1.7.49.

PLUGIN Changeset

CVE-2024-6482

HIGH CVSS 8.8 2024-09-14
Scroll to top