Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,048
Critical983
High3,296
Medium11,512
Reset
Showing 8881-8900 of 16048 records
Threat Entry Updated 2024-10-29

CVE-2024-8790 - Social Share With Floating Bar Plugin

The Social Share With Floating Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Social Share With Floating Bar

CVE-2024-8790

MEDIUM CVSS 6.1 2024-10-18
Threat Entry Updated 2024-10-29

CVE-2024-8740 - Getresponse Forms Plugin

The GetResponse Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Getresponse Forms

CVE-2024-8740

MEDIUM CVSS 6.1 2024-10-18
Threat Entry Updated 2024-10-29

CVE-2024-10049 - Woo Edit Templates Plugin

The Edit WooCommerce Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Woo Edit Templates

CVE-2024-10049

MEDIUM CVSS 6.1 2024-10-18
Threat Entry Updated 2024-11-01

CVE-2024-10040 - Infinite Scroll Plugin

The Infinite-Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation on the process_ajax_edit and process_ajax_delete function. This makes it possible for unauthenticated attackers to make changes to plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Infinite Scroll

CVE-2024-10040

MEDIUM CVSS 5.3 2024-10-18
Threat Entry Updated 2024-10-29

CVE-2024-10014 - Flat Ui Button Plugin

The Flat UI Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's flatbtn shortcode in version 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Flat Ui Button

CVE-2024-10014

MEDIUM CVSS 6.4 2024-10-18
Threat Entry Updated 2025-12-12

CVE-2024-9898 - Parallax Image Plugin

The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dd-parallax shortcode in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Parallax Image

CVE-2024-9898

MEDIUM CVSS 6.4 2024-10-17
Threat Entry Updated 2024-10-18

CVE-2024-9184 - Sendpulse Web Push Plugin

The SendPulse Free Web Push plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.6 due to incorrect use of the wp_kses_allowed_html function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sendpulse Web Push

CVE-2024-9184

HIGH CVSS 7.2 2024-10-17
Threat Entry Updated 2024-10-18

CVE-2024-8920 - Custom Web Fonts Manager Plugin

The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Custom Web Fonts Manager

CVE-2024-8920

MEDIUM CVSS 6.4 2024-10-17
Threat Entry Updated 2024-10-18

CVE-2024-9951 - Wp Photo Album Plus Plugin

The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' parameter in all versions up to, and including, 8.8.05.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Photo Album Plus

CVE-2024-9951

MEDIUM CVSS 6.1 2024-10-17
Threat Entry Updated 2024-11-21

CVE-2024-9213 - Persian Woocommerce Sms Plugin

The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Persian Woocommerce Sms

CVE-2024-9213

MEDIUM CVSS 6.1 2024-10-17
Threat Entry Updated 2025-01-29

CVE-2024-9352 - Forminator Forms Plugin

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.35.1. This is due to missing or incorrect nonce validation on the custom form 'create_module' function. This makes it possible for unauthenticated attackers to create draft forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Forminator Forms

CVE-2024-9352

MEDIUM CVSS 4.3 2024-10-17
Threat Entry Updated 2025-01-29

CVE-2024-9351 - Forminator Forms Plugin

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.35.1. This is due to missing or incorrect nonce validation on the quiz 'create_module' function. This makes it possible for unauthenticated attackers to create draft quizzes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Forminator Forms

CVE-2024-9351

MEDIUM CVSS 4.3 2024-10-17
Threat Entry Updated 2025-05-17

CVE-2024-5429 - Logo Slider Plugin

The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Logo Slider

CVE-2024-5429

HIGH CVSS 7.6 2024-10-17
Threat Entry Updated 2024-10-18

CVE-2024-9263 - Wp Timetics Ai Powered Appointment Booking Calendar And Online Scheduling Plugin

The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to reset the emails and passwords of arbitrary user accounts, including administrators, which makes account takeover and privilege escalation possible.

PLUGIN Wp Timetics Ai Powered Appointment Booking Calendar And Online Scheduling

CVE-2024-9263

CRITICAL CVSS 9.8 2024-10-17
Threat Entry Updated 2025-12-12

CVE-2024-9347 - Wp Extended Plugin

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpext-export' parameter in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Extended

CVE-2024-9347

MEDIUM CVSS 6.1 2024-10-17
Threat Entry Updated 2024-10-18

CVE-2024-8719 - Idx Plugin

The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like 'MaxBeds' and 'MinBeds' in all versions up to, and including, 3.14.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Idx

CVE-2024-8719

MEDIUM CVSS 6.1 2024-10-17
Threat Entry Updated 2025-01-10

CVE-2024-7417 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected posts.

PLUGIN Royal Elementor Addons

CVE-2024-7417

MEDIUM CVSS 4.3 2024-10-17
Threat Entry Updated 2024-11-18

CVE-2024-49593 - Advanced Custom Fields Plugin

In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF, then you can follow the process shown at the advancedcustomfields.com blog URL within the References section below.

PLUGIN Advanced Custom Fields

CVE-2024-49593

MEDIUM CVSS 5.3 2024-10-17
Threat Entry Updated 2024-10-18

CVE-2024-9863 - Miniorange Firebase Sms Otp Verification Plugin

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form is disabled.

PLUGIN Miniorange Firebase Sms Otp Verification

CVE-2024-9863

CRITICAL CVSS 9.8 2024-10-17
Threat Entry Updated 2025-06-05

CVE-2024-9940 - Calculated Fields Form Plugin

The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views form submissions in their email.

PLUGIN Calculated Fields Form

CVE-2024-9940

MEDIUM CVSS 5.3 2024-10-17
Scroll to top