Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14,273
Critical855
High2,814
Medium10,408
Reset
Showing 5461-5480 of 14273 records
Threat Entry Updated 2025-02-25

CVE-2024-13456 - Easy Quiz Maker Plugin

The Easy Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wqt-question' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Quiz Maker

CVE-2024-13456

MEDIUM CVSS 6.4 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13365 - Security Malware Scan Plugin

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Security Malware Scan

CVE-2024-13365

CRITICAL CVSS 9.8 2025-02-12
Threat Entry Updated 2025-02-20

CVE-2024-12296 - Superio Plugin

The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'import_page_options' function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

PLUGIN Superio

CVE-2024-12296

HIGH CVSS 8.8 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13435 - Ebook Downloader Plugin

The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ebook Downloader

CVE-2024-13435

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13437 - Book A Room Plugin

The Book a Room plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9. This is due to missing or incorrect nonce validation on the 'bookaroom_Settings' page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Book A Room

CVE-2024-13437

MEDIUM CVSS 4.3 2025-02-12
Threat Entry Updated 2025-02-20

CVE-2024-12213 - Superio Plugin

The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites.

PLUGIN Superio

CVE-2024-12213

CRITICAL CVSS 9.8 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-12315 - Export All Posts Products Orders Refunds Users Plugin

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/smack_uci_uploads/exports/ directory which can contain information like exported user data.

PLUGIN Export All Posts Products Orders Refunds Users

CVE-2024-12315

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-18

CVE-2024-13814 - Global Gallery Plugin

The The Global Gallery - WordPress Responsive Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 9.1.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.

PLUGIN Global Gallery

CVE-2024-13814

MEDIUM CVSS 5.4 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13821 - Booking Calendar Plugin

The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved.

PLUGIN Booking Calendar

CVE-2024-13821

MEDIUM CVSS 5.3 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13794 - Hide My Wp Ghost Plugin

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the plugin not properly restricting the /wp-register.php path. This makes it possible for unauthenticated attackers to discover the hidden login page location.

PLUGIN Hide My Wp Ghost

CVE-2024-13794

MEDIUM CVSS 5.3 2025-02-12
Threat Entry Updated 2025-02-12

CVE-2024-13714 - Ia Image Bank And Custom Image Creation Plugin

The All-Images.ai – IA Image Bank and Custom Image creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_get_image_by_url' function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Ia Image Bank And Custom Image Creation

CVE-2024-13714

HIGH CVSS 8.8 2025-02-12
Threat Entry Updated 2025-02-24

CVE-2024-13600 - Majestic Support Plugin

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the 'majesticsupportdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/majesticsupportdata directory which can contain file attachments included in support tickets.

PLUGIN Majestic Support

CVE-2024-13600

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-18

CVE-2024-13601 - Majestic Support Plugin

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via the 'exportusereraserequest' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export ticket data for any user.

PLUGIN Majestic Support

CVE-2024-13601

MEDIUM CVSS 4.3 2025-02-12
Threat Entry Updated 2025-02-24

CVE-2024-13374 - Wp Table Manager Plugin

The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary file names and directories.

PLUGIN Wp Table Manager

CVE-2024-13374

MEDIUM CVSS 4.3 2025-02-12
Threat Entry Updated 2025-02-24

CVE-2024-13800 - Convertplus Plugin

The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice' AJAX endpoint in all versions up to, and including, 3.5.30. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to '1' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to set some values…

PLUGIN Convertplus

CVE-2024-13800

HIGH CVSS 8.1 2025-02-12
Threat Entry Updated 2025-02-24

CVE-2024-13656 - Click Mag Plugin

The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to, and including, 3.6.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary option values on the WordPress site. This can be leveraged to delete an option that would create an error on the site and deny service to legitimate users.

PLUGIN Click Mag

CVE-2024-13656

HIGH CVSS 8.1 2025-02-12
Threat Entry Updated 2025-02-24

CVE-2024-13769 - Puzzles Plugin

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the 'theme_options_ajax_post_action' AJAX action in all versions up to, and including, 4.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings and inject malicious web scripts. The developer opted to remove the software from the repository, so an update is not available and it is recommended to find a replacement software.

PLUGIN Puzzles

CVE-2024-13769

MEDIUM CVSS 6.4 2025-02-12
Threat Entry Updated 2025-02-24

CVE-2024-13665 - Admire Extra Plugin

The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Admire Extra

CVE-2024-13665

MEDIUM CVSS 6.4 2025-02-12
Threat Entry Updated 2025-02-24

CVE-2024-13658 - Ngg Smart Image Search Plugin

The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ngg Smart Image Search

CVE-2024-13658

MEDIUM CVSS 6.4 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13421 - Real Estate 7 Plugin

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.

PLUGIN Real Estate 7

CVE-2024-13421

CRITICAL CVSS 9.8 2025-02-12
Scroll to top