Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical1
High0
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2024-11-28

CVE-2024-11082 - Tumult Hype Animations Plugin

The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hypeanimations_panel() function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Tumult Hype Animations

CVE-2024-11082

CRITICAL CVSS 9.9 2024-11-28
Threat Entry Updated 2024-11-08

CVE-2024-10543 - Tumult Hype Animations Plugin

The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hypeanimations_getcontent function in all versions up to, and including, 1.9.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve animation information.

PLUGIN Tumult Hype Animations

CVE-2024-10543

MEDIUM CVSS 4.3 2024-11-06
Scroll to top