Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 2801-2820 of 3408 records
Threat Entry Updated 2025-01-07

CVE-2024-1653 - Changeset Plugin

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxUpdateFolderPosition in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the folder position of categories as well as update the metadata of other taxonomies.

PLUGIN Changeset

CVE-2024-1653

MEDIUM CVSS 4.3 2024-02-27
Threat Entry Updated 2025-01-07

CVE-2024-1652 - Changeset Plugin

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxClearCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to clear categories.

PLUGIN Changeset

CVE-2024-1652

MEDIUM CVSS 4.3 2024-02-27
Threat Entry Updated 2025-01-07

CVE-2024-1650 - Changeset Plugin

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxRenameCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to rename categories.

PLUGIN Changeset

CVE-2024-1650

MEDIUM CVSS 4.3 2024-02-27
Threat Entry Updated 2025-01-07

CVE-2024-1649 - Changeset Plugin

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete categories.

PLUGIN Changeset

CVE-2024-1649

MEDIUM CVSS 4.3 2024-02-27
Threat Entry Updated 2025-03-10

CVE-2024-1698 - Changeset Plugin

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2024-1698

CRITICAL CVSS 9.8 2024-02-27
Threat Entry Updated 2025-01-15

CVE-2024-1686 - Changeset Plugin

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing authorization e in all versions up to, and including, 1.1.2 via the apply_layout function due to a missing capability check. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve arbitrary order data which may contain PII.

PLUGIN Changeset

CVE-2024-1686

MEDIUM CVSS 5.3 2024-02-27
Threat Entry Updated 2025-01-16

CVE-2024-1323 - Changeset Plugin

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type Grid Widget Title in all versions up to, and including, 2.10.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-1323

MEDIUM CVSS 6.4 2024-02-27
Threat Entry Updated 2025-01-16

CVE-2024-1165 - Changeset Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files to arbitrary locations on the server

PLUGIN Changeset

CVE-2024-1165

MEDIUM CVSS 4.3 2024-02-26
Threat Entry Updated 2025-02-05

CVE-2023-5775 - Changeset Plugin

The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated attackers, with administrator-level access, to retrieve the password from the password input field in the UI or from the options table where the password is stored.

PLUGIN Changeset

CVE-2023-5775

LOW CVSS 2.2 2024-02-26
Threat Entry Updated 2025-01-15

CVE-2024-1362 - Changeset Plugin

The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the cp_shortcode_refresh() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2024-1362

MEDIUM CVSS 4.3 2024-02-23
Threat Entry Updated 2025-01-15

CVE-2024-1361 - Changeset Plugin

The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the apiCall() function. This makes it possible for unauthenticated attackers to call a limited set of functions that can be used to import images, delete posts, or save theme data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2024-1361

MEDIUM CVSS 4.3 2024-02-23
Threat Entry Updated 2025-02-05

CVE-2024-1360 - Changeset Theme

The Colibri WP theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.94. This is due to missing or incorrect nonce validation on the colibriwp_install_plugin() function. This makes it possible for unauthenticated attackers to install recommended plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Changeset

CVE-2024-1360

MEDIUM CVSS 4.3 2024-02-23
Threat Entry Updated 2025-02-07

CVE-2024-1053 - Changeset Plugin

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to email the attendees list to themselves.

PLUGIN Changeset

CVE-2024-1053

MEDIUM CVSS 4.3 2024-02-22
Threat Entry Updated 2025-01-31

CVE-2024-0593 - Changeset Plugin

The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.

PLUGIN Changeset

CVE-2024-0593

MEDIUM CVSS 5.3 2024-02-21
Threat Entry Updated 2025-01-28

CVE-2024-1108 - Changeset Plugin

The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_init() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to change the settings of the plugin, which can also cause a denial of service due to a misconfiguration.

PLUGIN Changeset

CVE-2024-1108

MEDIUM CVSS 6.5 2024-02-21
Threat Entry Updated 2025-02-04

CVE-2024-1510 - Changeset Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_tooltip shortcode in all versions up to, and including, 7.0.2 due to insufficient input sanitization and output escaping on user supplied attributes and user supplied tags. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-1510

MEDIUM CVSS 6.4 2024-02-20
Threat Entry Updated 2024-12-18

CVE-2024-1512 - Changeset Plugin

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2024-1512

CRITICAL CVSS 9.8 2024-02-17
Threat Entry Updated 2025-01-23

CVE-2024-0708 - Changeset Plugin

The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.2. This makes it possible for unauthenticated attackers to access landing pages that may not be public.

PLUGIN Changeset

CVE-2024-0708

MEDIUM CVSS 5.3 2024-02-15
Threat Entry Updated 2024-11-21

CVE-2024-0842 - Changeset Plugin

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.5. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in the server running out of resources.

PLUGIN Changeset

CVE-2024-0842

HIGH CVSS 7.5 2024-02-09
Threat Entry Updated 2024-11-21

CVE-2024-1122 - Changeset Plugin

The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible for unauthenticated attackers to export event data.

PLUGIN Changeset

CVE-2024-1122

MEDIUM CVSS 5.3 2024-02-09
Scroll to top