Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,048
Critical983
High3,296
Medium11,512
Reset
Showing 8781-8800 of 16048 records
Threat Entry Updated 2024-11-22

CVE-2024-9967 - Wp Show More Plugin

The WP show more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_more shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Show More

CVE-2024-9967

MEDIUM CVSS 6.4 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9853 - Idsk Toolkit Plugin

The ID-SK Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Idsk Toolkit

CVE-2024-9853

MEDIUM CVSS 6.4 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9642 - Editor Custom Color Palette Plugin

The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Editor Custom Color Palette

CVE-2024-9642

MEDIUM CVSS 6.4 2024-10-26
Threat Entry Updated 2025-07-10

CVE-2024-9637 - Wpschoolpress Plugin

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with teacher-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

PLUGIN Wpschoolpress

CVE-2024-9637

HIGH CVSS 8.8 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-8392 - Sogrid Plugin

The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.2 via the 'tab' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.…

PLUGIN Sogrid

CVE-2024-8392

HIGH CVSS 7.2 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-10092 - Download Monitor Plugin

The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to revoke existing API keys and generate new ones.

PLUGIN Download Monitor

CVE-2024-10092

MEDIUM CVSS 4.3 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9456 - Wp Awesome Login Plugin

The WP Awesome Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Wp Awesome Login

CVE-2024-9456

MEDIUM CVSS 6.4 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-8870 - Mailchimp Wp Plugin

The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Mailchimp Wp

CVE-2024-8870

MEDIUM CVSS 6.1 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9933 - Watchtowerhq Plugin

The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.6. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login' function. This makes it possible for unauthenticated attackers to log in to the WatchTowerHQ client administrator user.

PLUGIN Watchtowerhq

CVE-2024-9933

CRITICAL CVSS 9.8 2024-10-26
Threat Entry Updated 2026-01-23

CVE-2024-9932 - Wux Blog Editor Plugin

The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wux Blog Editor

CVE-2024-9932

CRITICAL CVSS 9.8 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9931 - Wux Blog Editor Plugin

The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to log in to the first administrator user.

PLUGIN Wux Blog Editor

CVE-2024-9931

CRITICAL CVSS 9.8 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9930 - Sb Core Plugin

The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2.3.2. This is due to missing validation on the user being supplied in the 'verify_email' action. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator. The vulnerability is in the Account extension.

PLUGIN Sb Core

CVE-2024-9930

CRITICAL CVSS 9.8 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9890 - User Toolkit Plugin

The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. This is due to an improper capability check in the 'switchUser' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator.

PLUGIN User Toolkit

CVE-2024-9890

HIGH CVSS 8.8 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9626 - Editorial Assistant By Sovrn Plugin

The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload attachment files (such as jpg, png, txt, zip), and set the post featured image.

PLUGIN Editorial Assistant By Sovrn

CVE-2024-9626

MEDIUM CVSS 4.3 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9454 - Pripre Plugin

The PriPre plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Pripre

CVE-2024-9454

MEDIUM CVSS 6.4 2024-10-26
Threat Entry Updated 2025-05-28

CVE-2024-9613 - Formfacade Plugin

The FormFacade – WordPress plugin for Google Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'userId' and 'publishId' parameters in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Formfacade

CVE-2024-9613

MEDIUM CVSS 6.1 2024-10-26
Threat Entry Updated 2025-05-28

CVE-2024-9462 - Poll Maker Plugin

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll settings in all versions up to, and including, 5.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Poll Maker

CVE-2024-9462

MEDIUM CVSS 5.5 2024-10-26
Threat Entry Updated 2025-05-28

CVE-2024-9475 - Poll Maker Plugin

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the order_by parameter in all versions up to, and including, 5.4.6 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Poll Maker

CVE-2024-9475

MEDIUM CVSS 4.9 2024-10-26
Threat Entry Updated 2025-01-16

CVE-2024-10091 - Elements Kit Elementor Addons Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elements Kit Elementor Addons

CVE-2024-10091

MEDIUM CVSS 6.4 2024-10-26
Threat Entry Updated 2024-11-05

CVE-2024-9585 - Image Map Pro Plugin

The Image Map Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'save_project' function with an arbitrary shortcode in versions up to, and including, 6.0.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Image Map Pro

CVE-2024-9585

MEDIUM CVSS 6.4 2024-10-25
Scroll to top