Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14,273
Critical855
High2,814
Medium10,408
Reset
Showing 5561-5580 of 14273 records
Threat Entry Updated 2025-02-24

CVE-2025-0365 - Jupiter X Core Plugin

The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Jupiter X Core

CVE-2025-0365

MEDIUM CVSS 6.5 2025-02-01
Threat Entry Updated 2025-05-07

CVE-2024-13099 - Widget4call Plugin

The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Widget4call

CVE-2024-13099

MEDIUM CVSS 5.4 2025-02-01
Threat Entry Updated 2025-05-07

CVE-2024-13098 - Wordpress Email Newsletter Plugin

The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Wordpress Email Newsletter

CVE-2024-13098

MEDIUM CVSS 5.4 2025-02-01
Threat Entry Updated 2025-05-12

CVE-2024-13097 - Wp Finance Plugin

The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Wp Finance

CVE-2024-13097

MEDIUM CVSS 5.4 2025-02-01
Threat Entry Updated 2025-05-12

CVE-2024-12768 - Responsive Iframe Plugin

The Responsive iframe WordPress plugin through 1.2.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Responsive Iframe

CVE-2024-12768

MEDIUM CVSS 5.4 2025-02-01
Threat Entry Updated 2025-05-12

CVE-2024-13096 - Wp Finance Plugin

The WP Finance WordPress plugin through 1.3.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

PLUGIN Wp Finance

CVE-2024-13096

MEDIUM CVSS 4.6 2025-02-01
Threat Entry Updated 2025-02-24

CVE-2024-12041 - Directorist Plugin

The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including including usernames, email addresses, names, and more information about users.

PLUGIN Directorist

CVE-2024-12041

MEDIUM CVSS 5.3 2025-02-01
Threat Entry Updated 2025-02-24

CVE-2024-13343 - Woocommerce Customers Manager Plugin

The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new_roles() function in all versions up to, and including, 31.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

PLUGIN Woocommerce Customers Manager

CVE-2024-13343

HIGH CVSS 8.8 2025-02-01
Threat Entry Updated 2025-02-24

CVE-2024-12171 - Wsdesk Plugin

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'eh_crm_agent_add_user' AJAX action in all versions up to, and including, 3.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new administrative user accounts.

PLUGIN Wsdesk

CVE-2024-12171

HIGH CVSS 8.8 2025-02-01
Threat Entry Updated 2025-02-24

CVE-2024-13547 - Athemes Addons For Elementor Plugin

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Athemes Addons For Elementor

CVE-2024-13547

MEDIUM CVSS 6.4 2025-02-01
Threat Entry Updated 2025-02-24

CVE-2024-12620 - Animategl Animations Plugin

The AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'agl_json' AJAX action in all versions up to, and including, 1.4.23. This makes it possible for unauthenticated attackers to update the plugin's settings.

PLUGIN Animategl Animations

CVE-2024-12620

MEDIUM CVSS 5.3 2025-02-01
Threat Entry Updated 2025-02-24

CVE-2024-12184 - Wordpress Contact Forms Plugin

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to download other user submitted forms.

PLUGIN Wordpress Contact Forms

CVE-2024-12184

MEDIUM CVSS 5.3 2025-02-01
Threat Entry Updated 2025-02-21

CVE-2024-13651 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_deactivate() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset some of the plugin's settings.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2024-13651

MEDIUM CVSS 4.3 2025-02-01
Threat Entry Updated 2025-02-24

CVE-2024-11780 - Site Search 360 Plugin

The Site Search 360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ss360-resultblock' shortcode in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Site Search 360

CVE-2024-11780

MEDIUM CVSS 6.4 2025-02-01
Threat Entry Updated 2025-02-18

CVE-2024-12415 - Infographic And List Builder Ilist Plugin

The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.9.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Infographic And List Builder Ilist

CVE-2024-12415

MEDIUM CVSS 6.5 2025-01-31
Threat Entry Updated 2025-02-18

CVE-2024-13662 - Ehive Objects Image Grid Plugin

The eHive Objects Image Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ehive_objects_image_grid' shortcode in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ehive Objects Image Grid

CVE-2024-13662

MEDIUM CVSS 6.4 2025-01-31
Threat Entry Updated 2025-08-11

CVE-2024-12267 - Drag And Drop Multiple File Upload Contact Form 7 Plugin

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to delete limited arbitrary files on the server. It is not possible to delete files like wp-config.php that would make RCE possible.

PLUGIN Drag And Drop Multiple File Upload Contact Form 7

CVE-2024-12267

MEDIUM CVSS 5.3 2025-01-31
Threat Entry Updated 2025-01-31

CVE-2024-12037 - Changeset Plugin

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bf_new_submission_link' shortcode in all versions up to, and including, 2.8.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2024-12037

MEDIUM CVSS 6.4 2025-01-31
Threat Entry Updated 2025-02-11

CVE-2024-13472 - Woocommerce Product Table Plugin

The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.9.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The same 'sc_attrs' parameter is vulnerable to Reflected Cross-Site Scripting as well.

PLUGIN Woocommerce Product Table

CVE-2024-13472

HIGH CVSS 7.3 2025-01-31
Threat Entry Updated 2025-01-31

CVE-2025-24563 - Allows Reflected Xss Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGlow Cleanup – Directory Listing & Classifieds WordPress Plugin allows Reflected XSS. This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through 1.0.4.

PLUGIN Allows Reflected Xss

CVE-2025-24563

HIGH CVSS 7.1 2025-01-31
Scroll to top