Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High0
Medium4
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2025-06-04

CVE-2024-7758 - Stylish Price List Plugin

The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Stylish Price List

CVE-2024-7758

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-05-15

CVE-2024-10472 - Stylish Price List Plugin

The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Stylish Price List

CVE-2024-10472

MEDIUM CVSS 5.9 2025-03-25
Threat Entry Updated 2024-11-21

CVE-2021-24770 - Stylish Price List Plugin

The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as subscriber, to upload arbitrary images.

PLUGIN Stylish Price List

CVE-2021-24770

MEDIUM CVSS 6.5 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24757 - Stylish Price List Plugin

The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.

PLUGIN Stylish Price List

CVE-2021-24757

MEDIUM CVSS 5.3 2021-11-01
Scroll to top