Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total70
Critical8
High22
Medium39
Reset
Showing 41-60 of 70 records
Threat Entry Updated 2025-02-14

CVE-2025-23492 - WordPress 淘宝客插件 Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CantonBolo WordPress 淘宝客插件 allows Reflected XSS. This issue affects WordPress 淘宝客插件: from n/a through 1.1.2.

PLUGIN WordPress 淘宝客插件

CVE-2025-23492

HIGH CVSS 7.1 2025-02-14
Threat Entry Updated 2024-12-13

CVE-2024-54326 - WordPress Core

Missing Authorization vulnerability in Eyal Fitoussi GEO my WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GEO my WordPress: from n/a through 4.5.0.4.

CORE WordPress Core

CVE-2024-54326

MEDIUM CVSS 6.5 2024-12-13
Threat Entry Updated 2024-11-01

CVE-2024-43235 - WordPress Core

Missing Authorization vulnerability in MetaBox.Io Meta Box – WordPress Custom Fields Framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta Box – WordPress Custom Fields Framework: from n/a through 5.9.10.

CORE WordPress Core

CVE-2024-43235

HIGH CVSS 7.1 2024-11-01
Threat Entry Updated 2024-11-01

CVE-2024-38792 - WordPress Core

Missing Authorization vulnerability in ConveyThis Translate Team Language Translate Widget for WordPress – ConveyThis allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Language Translate Widget for WordPress – ConveyThis: from n/a through 234.

CORE WordPress Core

CVE-2024-38792

MEDIUM CVSS 5.3 2024-11-01
Threat Entry Updated 2024-11-01

CVE-2024-37218 - WordPress Core

Missing Authorization vulnerability in WordPress Page Builder Sandwich Team Page Builder Sandwich – Front-End Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page Builder Sandwich – Front-End Page Builder: from n/a through 5.1.0.

CORE WordPress Core

CVE-2024-37218

MEDIUM CVSS 4.3 2024-11-01
Threat Entry Updated 2024-10-07

CVE-2024-47327 - WordPress Core

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eyal Fitoussi GEO my WordPress allows Reflected XSS.This issue affects GEO my WordPress: from n/a through 4.5.0.3.

CORE WordPress Core

CVE-2024-47327

HIGH CVSS 7.1 2024-10-06
Threat Entry Updated 2024-11-21

CVE-2024-32111 - WordPress Core

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through 6.0.8, from 5.9 through 5.9.9, from 5.8 through 5.8.9, from 5.7 through 5.7.11, from 5.6 through 5.6.13, from 5.5 through 5.5.14, from 5.4 through 5.4.15, from 5.3 through 5.3.17, from 5.2 through 5.2.20, from 5.1 through 5.1.18, from 5.0 through 5.0.21, from 4.9 through 4.9.25,…

CORE WordPress Core

CVE-2024-32111

MEDIUM CVSS 5.0 2024-06-25
Threat Entry Updated 2024-11-21

CVE-2024-31111 - WordPress Core

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through 6.0.8, from 5.9 through 5.9.9.

CORE WordPress Core

CVE-2024-31111

MEDIUM CVSS 6.5 2024-06-25
Threat Entry Updated 2024-11-21

CVE-2024-6307 - WordPress Core

WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to insufficient input sanitization and output escaping on URLs. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CORE WordPress Core

CVE-2024-6307

MEDIUM CVSS 6.4 2024-06-25
Threat Entry Updated 2024-11-21

CVE-2024-4787 - WordPress Core

The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 3.1.75. This is due to insufficient limitations on the email recipient and the content in the 'send_pdf' and the 'send_pdf_front' functions which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.

CORE WordPress Core

CVE-2024-4787

MEDIUM CVSS 5.8 2024-06-19
Threat Entry Updated 2024-11-21

CVE-2024-34801 - WordPress Core

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mervin Praison Praison SEO WordPress allows Stored XSS.This issue affects Praison SEO WordPress: from n/a through 4.0.15.

CORE WordPress Core

CVE-2024-34801

MEDIUM CVSS 6.5 2024-06-03
Threat Entry Updated 2024-11-21

CVE-2024-32692 - WordPress Core

Missing Authorization vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 6.9.

CORE WordPress Core

CVE-2024-32692

HIGH CVSS 8.2 2024-05-17
Threat Entry Updated 2024-11-21

CVE-2024-34573 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pootlepress Pootle Pagebuilder – WordPress Page builder allows Stored XSS.This issue affects Pootle Pagebuilder – WordPress Page builder: from n/a through 5.7.1.

CORE WordPress Core

CVE-2024-34573

MEDIUM CVSS 6.5 2024-05-08
Threat Entry Updated 2026-01-05

CVE-2024-4439 - WordPress Core

WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. In addition, it also makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that have the comment block present and display the comment author's avatar.

CORE WordPress Core

CVE-2024-4439

HIGH CVSS 7.2 2024-05-03
Threat Entry Updated 2024-11-21

CVE-2023-5692 - WordPress Core

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.

CORE WordPress Core

CVE-2023-5692

MEDIUM CVSS 5.3 2024-04-05
Threat Entry Updated 2026-01-07

CVE-2024-31210 - WordPress Core

WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for installation (in order to move the file into place outside of the `uploads` directory) then the uploaded file remains temporary available in the Media Library despite it not being allowed. If the `DISALLOW_FILE_EDIT` constant is set to `true` on…

CORE WordPress Core

CVE-2024-31210

HIGH CVSS 7.6 2024-04-04
Threat Entry Updated 2026-01-02

CVE-2024-31211 - WordPress Core

WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.

CORE WordPress Core

CVE-2024-31211

MEDIUM CVSS 5.5 2024-04-04
Threat Entry Updated 2025-04-23

CVE-2023-5561 - WordPress Core

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CORE WordPress Core

CVE-2023-5561

MEDIUM CVSS 5.3 2023-10-16
Threat Entry Updated 2024-11-21

CVE-2023-39999 - WordPress Core

Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from…

CORE WordPress Core

CVE-2023-39999

MEDIUM CVSS 4.3 2023-10-13
Threat Entry Updated 2025-04-24

CVE-2023-2745 - WordPress Core

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.

CORE WordPress Core

CVE-2023-2745

MEDIUM CVSS 5.4 2023-05-17
Scroll to top