Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total179
Critical16
High33
Medium129
Reset
Showing 61-80 of 179 records
Threat Entry Updated 2024-10-07

CVE-2024-6926 - Through 2 Plugin

The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN Through 2

CVE-2024-6926

CRITICAL CVSS 9.8 2024-09-04
Threat Entry Updated 2024-10-07

CVE-2024-6927 - Through 2 Plugin

The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Through 2

CVE-2024-6927

MEDIUM CVSS 4.8 2024-08-29
Threat Entry Updated 2025-05-27

CVE-2024-6460 - Through 2 Plugin

The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

PLUGIN Through 2

CVE-2024-6460

CRITICAL CVSS 9.8 2024-08-16
Threat Entry Updated 2025-05-30

CVE-2024-6021 - Through 2 Plugin

The Donation Block For PayPal WordPress plugin through 2.1.0 does not sanitise and escape form submissions, leading to a stored cross-site scripting vulnerability

PLUGIN Through 2

CVE-2024-6021

MEDIUM CVSS 6.8 2024-07-30
Threat Entry Updated 2026-01-02

CVE-2024-6230 - Through 2 Plugin

The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack

PLUGIN Through 2

CVE-2024-6230

MEDIUM CVSS 6.5 2024-07-30
Threat Entry Updated 2025-08-20

CVE-2024-6226 - Through 2 Plugin

The WpStickyBar WordPress plugin through 2.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Through 2

CVE-2024-6226

MEDIUM CVSS 6.1 2024-07-30
Threat Entry Updated 2025-05-28

CVE-2024-5809 - Through 2 Plugin

The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin users

PLUGIN Through 2

CVE-2024-5809

MEDIUM CVSS 6.1 2024-07-30
Threat Entry Updated 2025-05-28

CVE-2024-5808 - Through 2 Plugin

The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in admin perform such action via a CSRF attack

PLUGIN Through 2

CVE-2024-5808

MEDIUM CVSS 4.3 2024-07-30
Threat Entry Updated 2025-08-20

CVE-2024-5765 - Through 2 Plugin

The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN Through 2

CVE-2024-5765

CRITICAL CVSS 9.8 2024-07-30
Threat Entry Updated 2025-05-19

CVE-2024-4758 - Through 2 Plugin

The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

PLUGIN Through 2

CVE-2024-4758

HIGH CVSS 7.6 2024-06-26
Threat Entry Updated 2025-04-30

CVE-2024-4959 - Through 2 Plugin

The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Through 2

CVE-2024-4959

MEDIUM CVSS 4.8 2024-06-26
Threat Entry Updated 2025-04-30

CVE-2024-4957 - Through 2 Plugin

The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Through 2

CVE-2024-4957

MEDIUM CVSS 4.3 2024-06-26
Threat Entry Updated 2024-11-21

CVE-2024-4616 - Through 2 Plugin

The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users

PLUGIN Through 2

CVE-2024-4616

MEDIUM CVSS 6.1 2024-06-21
Threat Entry Updated 2025-03-18

CVE-2024-4970 - Through 2 Plugin

The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Through 2

CVE-2024-4970

MEDIUM CVSS 4.8 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-4969 - Through 2 Plugin

The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attackers to make logged in admin enable/disable widgets via a CSRF attack

PLUGIN Through 2

CVE-2024-4969

MEDIUM CVSS 4.3 2024-06-21
Threat Entry Updated 2025-05-13

CVE-2024-4480 - Through 2 Plugin

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Through 2

CVE-2024-4480

MEDIUM CVSS 6.1 2024-06-14
Threat Entry Updated 2025-07-11

CVE-2024-4751 - Through 2 Plugin

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Through 2

CVE-2024-4751

MEDIUM CVSS 4.3 2024-06-14
Threat Entry Updated 2025-03-13

CVE-2024-4005 - Through 2 Plugin

The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Through 2

CVE-2024-4005

MEDIUM CVSS 4.8 2024-06-14
Threat Entry Updated 2025-05-13

CVE-2024-2218 - Through 2 Plugin

The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Through 2

CVE-2024-2218

MEDIUM CVSS 4.6 2024-06-14
Threat Entry Updated 2025-05-29

CVE-2024-4756 - Through 2 Plugin

The WP Backpack WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Through 2

CVE-2024-4756

MEDIUM CVSS 5.4 2024-06-07
Scroll to top