Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,407
Critical199
High721
Medium2,463
Reset
Showing 1521-1540 of 3407 records
Threat Entry Updated 2025-08-12

CVE-2024-13323 - Changeset Plugin

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-13323

MEDIUM CVSS 6.4 2025-01-14
Threat Entry Updated 2025-02-25

CVE-2024-12877 - Changeset Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files on the server that makes remote code execution possible. Please note this was only partially patched in 3.19.3, a fully sufficient patch was not released until 3.19.4. However, another…

PLUGIN Changeset

CVE-2024-12877

CRITICAL CVSS 9.8 2025-01-11
Threat Entry Updated 2025-02-07

CVE-2024-12304 - Changeset Plugin

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via button block link in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-12304

MEDIUM CVSS 6.4 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-12627 - Changeset Plugin

The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.5 via deserialization of untrusted input from post content passed to the capture_email AJAX action. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system,…

PLUGIN Changeset

CVE-2024-12627

HIGH CVSS 7.5 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-12204 - Changeset Plugin

The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in the class-cx-rest.php file in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create 100% off coupons, delete posts, delete leads, and update coupon statuses.

PLUGIN Changeset

CVE-2024-12204

MEDIUM CVSS 5.4 2025-01-11
Threat Entry Updated 2025-01-16

CVE-2024-13183 - Changeset Plugin

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-13183

MEDIUM CVSS 6.4 2025-01-10
Threat Entry Updated 2025-01-16

CVE-2025-0311 - Changeset Plugin

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2025-0311

MEDIUM CVSS 6.4 2025-01-10
Threat Entry Updated 2025-01-08

CVE-2024-11423 - Changeset Plugin

The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints such as /wp-json/gifting/recharge-giftcard in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to recharge a gift card balance, without making a payment along with reducing gift card balances without purchasing anything.

PLUGIN Changeset

CVE-2024-11423

HIGH CVSS 7.5 2025-01-08
Threat Entry Updated 2025-01-08

CVE-2024-12337 - Changeset Plugin

The Shipping via Planzer for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘processed-ids’ parameter in all versions up to, and including, 1.0.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2024-12337

MEDIUM CVSS 6.1 2025-01-08
Threat Entry Updated 2025-01-08

CVE-2024-12712 - Changeset Plugin

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order statuses.

PLUGIN Changeset

CVE-2024-12712

MEDIUM CVSS 5.3 2025-01-08
Threat Entry Updated 2025-03-13

CVE-2024-9939 - Changeset Plugin

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory.

PLUGIN Changeset

CVE-2024-9939

HIGH CVSS 7.5 2025-01-08
Threat Entry Updated 2025-04-17

CVE-2024-12045 - Changeset Plugin

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value of the Google Maps block in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Changeset

CVE-2024-12045

MEDIUM CVSS 4.4 2025-01-08
Threat Entry Updated 2025-04-03

CVE-2024-12852 - Changeset Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-12852

MEDIUM CVSS 6.4 2025-01-08
Threat Entry Updated 2025-04-17

CVE-2024-11613 - Changeset Plugin

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined directory path. This makes it possible for unauthenticated attackers to execute code on the server.

PLUGIN Changeset

CVE-2024-11613

CRITICAL CVSS 9.8 2025-01-08
Threat Entry Updated 2025-03-06

CVE-2024-12584 - Changeset Plugin

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6.2 via the 'duplicate' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract potentially sensitive data from draft, scheduled (future), private, and password protected posts.

PLUGIN Changeset

CVE-2024-12584

MEDIUM CVSS 4.3 2025-01-08
Threat Entry Updated 2025-02-26

CVE-2024-10585 - Changeset Plugin

The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.

PLUGIN Changeset

CVE-2024-10585

MEDIUM CVSS 5.3 2025-01-08
Threat Entry Updated 2025-01-17

CVE-2024-11271 - Changeset Plugin

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing capability check on several functions in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify webinars.

PLUGIN Changeset

CVE-2024-11271

HIGH CVSS 8.8 2025-01-08
Threat Entry Updated 2025-01-17

CVE-2024-11270 - Changeset Plugin

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary files that can lead to remote code execution.

PLUGIN Changeset

CVE-2024-11270

HIGH CVSS 8.8 2025-01-08
Threat Entry Updated 2025-01-08

CVE-2024-12112 - Changeset Plugin

The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'add_form_Emsfb' AJAX action in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping and missing authorization checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-12112

MEDIUM CVSS 6.4 2025-01-08
Threat Entry Updated 2025-07-11

CVE-2024-12713 - Changeset Plugin

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password protected, private, or draft posts that they should not have access to.

PLUGIN Changeset

CVE-2024-12713

MEDIUM CVSS 5.3 2025-01-08
Scroll to top