Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,048
Critical983
High3,296
Medium11,512
Reset
Showing 8901-8920 of 16048 records
Threat Entry Updated 2025-01-28

CVE-2024-9862 - Otp Verification With Firebase Plugin

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources, and the user current password check is missing. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.

PLUGIN Otp Verification With Firebase

CVE-2024-9862

CRITICAL CVSS 9.8 2024-10-17
Threat Entry Updated 2025-01-28

CVE-2024-9861 - Otp Verification With Firebase Plugin

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the phone number associated with that user.

PLUGIN Otp Verification With Firebase

CVE-2024-9861

HIGH CVSS 8.1 2024-10-17
Threat Entry Updated 2024-10-18

CVE-2024-9240 - Redi Restaurant Reservation Plugin

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 24.0902. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Redi Restaurant Reservation

CVE-2024-9240

MEDIUM CVSS 6.1 2024-10-17
Threat Entry Updated 2024-10-18

CVE-2024-9215 - Publishpress Authors Plugin

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and including, 4.7.1 via the action_edited_author() due to missing validation on the 'authors-user_id' user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to update arbitrary user accounts email addresses, including administrators, which can then be leveraged to reset that user's account password and gain access.

PLUGIN Publishpress Authors

CVE-2024-9215

HIGH CVSS 8.8 2024-10-17
Threat Entry Updated 2024-10-16

CVE-2024-9893 - Nextend Facebook Connect Plugin

The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

PLUGIN Nextend Facebook Connect

CVE-2024-9893

CRITICAL CVSS 9.8 2024-10-16
Threat Entry Updated 2024-10-16

CVE-2024-8921 - Zita Site Library Plugin

The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Zita Site Library

CVE-2024-8921

MEDIUM CVSS 6.4 2024-10-16
Threat Entry Updated 2025-11-07

CVE-2024-9444 - Elementsready Plugin

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Elementsready

CVE-2024-9444

MEDIUM CVSS 6.4 2024-10-16
Threat Entry Updated 2024-10-30

CVE-2024-9061 - Wp Popup Builder Plugin

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. NOTE: This vulnerability was partially fixed in version 1.3.5 with a nonce check, which effectively prevented access to the affected function. However, version…

PLUGIN Wp Popup Builder

CVE-2024-9061

HIGH CVSS 7.3 2024-10-16
Threat Entry Updated 2024-10-30

CVE-2024-9540 - Sina Extension For Elementor Plugin

The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.7 via the render function in widgets/advanced/sina-modal-box.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft Elementor template data.

PLUGIN Sina Extension For Elementor

CVE-2024-9540

MEDIUM CVSS 4.3 2024-10-16
Threat Entry Updated 2024-10-30

CVE-2021-4452 - Google Language Translator Plugin

The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Specifically affects users with older browsers that lack proper URL encoding support.

PLUGIN Google Language Translator

CVE-2021-4452

HIGH CVSS 7.1 2024-10-16
Threat Entry Updated 2024-10-16

CVE-2023-7296 - Bigbluebutton Plugin

The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewer code fields in versions up to, and including, 3.0.0-beta.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with author privileges or higher to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Bigbluebutton

CVE-2023-7296

MEDIUM CVSS 6.4 2024-10-16
Threat Entry Updated 2024-10-16

CVE-2023-7295 - Video Grid Plugin

The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Video Grid

CVE-2023-7295

MEDIUM CVSS 6.1 2024-10-16
Threat Entry Updated 2025-12-31

CVE-2024-9582 - Accordion Slider Plugin

The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an accordion slider in all versions up to, and including, 1.9.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: Successful exploitation by Contributor-level users requires an Administrator-level user to provide access to the plugin's admin area via the `Access` plugin setting, which is…

PLUGIN Accordion Slider

CVE-2024-9582

MEDIUM CVSS 6.4 2024-10-16
Threat Entry Updated 2024-10-17

CVE-2024-8507 - File Manager Plugin

The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to missing or incorrect nonce validation on the 'mk_file_folder_manager' ajax action. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN File Manager

CVE-2024-8507

HIGH CVSS 8.8 2024-10-16
Threat Entry Updated 2024-10-17

CVE-2024-8746 - File Manager Plugin

The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to the File Manager by an administrator, to download and upload arbitrary backup files on the affected site's server which may make remote code execution possible.

PLUGIN File Manager

CVE-2024-8746

HIGH CVSS 7.5 2024-10-16
Threat Entry Updated 2024-10-17

CVE-2024-8918 - File Manager Plugin

The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to a lack of proper checks on allowed file types. This makes it possible for unauthenticated attackers, with permissions granted by an administrator, to upload .css and .js files, which could lead to Stored Cross-Site Scripting.

PLUGIN File Manager

CVE-2024-8918

HIGH CVSS 7.4 2024-10-16
Threat Entry Updated 2024-10-17

CVE-2023-7294 - Donations Plugin

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to create a mollie payment profile.

PLUGIN Donations

CVE-2023-7294

HIGH CVSS 7.1 2024-10-16
Threat Entry Updated 2024-10-17

CVE-2023-7291 - Donations Plugin

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_mollie_account function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to set up a mollie account.

PLUGIN Donations

CVE-2023-7291

HIGH CVSS 7.1 2024-10-16
Threat Entry Updated 2024-10-17

CVE-2023-7289 - Donations Plugin

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to change plugin API keys.

PLUGIN Donations

CVE-2023-7289

MEDIUM CVSS 5.4 2024-10-16
Threat Entry Updated 2024-10-17

CVE-2023-7293 - Donations Plugin

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_mollie_account_details function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to verify the existence of a mollie account.

PLUGIN Donations

CVE-2023-7293

MEDIUM CVSS 4.3 2024-10-16
Scroll to top