Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,048
Critical983
High3,296
Medium11,512
Reset
Showing 8941-8960 of 16048 records
Threat Entry Updated 2025-05-17

CVE-2024-9305 - Apppresser Plugin

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_password() and validate_reset_password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator.

PLUGIN Apppresser

CVE-2024-9305

HIGH CVSS 8.1 2024-10-16
Threat Entry Updated 2024-10-16

CVE-2024-9521 - Seo Manager Plugin

The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Seo Manager

CVE-2024-9521

MEDIUM CVSS 6.4 2024-10-16
Threat Entry Updated 2024-10-16

CVE-2024-9647 - Kama Spamblock Plugin

The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Kama Spamblock

CVE-2024-9647

MEDIUM CVSS 6.1 2024-10-16
Threat Entry Updated 2025-02-27

CVE-2024-9649 - Wp Ulike Plugin

The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7.4. This is due to missing or incorrect nonce validation on the wp_ulike_delete_history_api() function. This makes it possible for unauthenticated attackers to delete engagements via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Ulike

CVE-2024-9649

MEDIUM CVSS 4.3 2024-10-16
Threat Entry Updated 2024-10-16

CVE-2024-9105 - Ultimateai Plugin

The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This is due to insufficient verification on the user being supplied in the 'ultimate_ai_register_or_login_with_google' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

PLUGIN Ultimateai

CVE-2024-9105

CRITICAL CVSS 9.8 2024-10-16
Threat Entry Updated 2025-02-11

CVE-2024-8787 - Smart Online Order For Clover Plugin

The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Smart Online Order For Clover

CVE-2024-8787

MEDIUM CVSS 6.1 2024-10-16
Threat Entry Updated 2024-10-16

CVE-2024-9104 - Ultimateai Plugin

The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. This is due to the improper empty value check and a missing default activated value check in the 'ultimate_ai_change_pass' function. This makes it possible for unauthenticated attackers to reset the password of the first user, whose account is not yet activated or the first user who activated their account, who are subscribers.

PLUGIN Ultimateai

CVE-2024-9104

MEDIUM CVSS 5.6 2024-10-16
Threat Entry Updated 2024-11-08

CVE-2024-8541 - Discount Rules For Woocommerce Plugin

The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.6.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a site administrator into performing an action such as clicking on a link. Please note that this is only exploitable when the 'Leave a…

PLUGIN Discount Rules For Woocommerce

CVE-2024-8541

MEDIUM CVSS 4.7 2024-10-16
Threat Entry Updated 2024-10-17

CVE-2024-9895 - Smart Online Order For Clover Plugin

The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Smart Online Order For Clover

CVE-2024-9895

MEDIUM CVSS 6.4 2024-10-15
Threat Entry Updated 2024-10-15

CVE-2024-9837 - Auto Date Year Month Plugin

The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Auto Date Year Month

CVE-2024-9837

HIGH CVSS 7.3 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-9944 - Woocommerce Plugin

The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views order form submissions.

PLUGIN Woocommerce

CVE-2024-9944

MEDIUM CVSS 5.3 2024-10-15
Threat Entry Updated 2024-10-19

CVE-2024-9820 - Wp 2fa With Telegram Plugin

The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.

PLUGIN Wp 2fa With Telegram

CVE-2024-9820

MEDIUM CVSS 6.5 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-9687 - Wp 2fa With Telegram Plugin

The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient validation of the user-controlled key on the 'validate_tg' action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator.

PLUGIN Wp 2fa With Telegram

CVE-2024-9687

HIGH CVSS 8.8 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-6757 - Website Builder Plugin

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.

PLUGIN Website Builder

CVE-2024-6757

MEDIUM CVSS 4.3 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-9548 - Slimstat Analytics Plugin

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping when logging visitor requests. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slimstat Analytics

CVE-2024-9548

HIGH CVSS 7.2 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-9546 - Wpide Plugin

The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution results. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Wpide

CVE-2024-9546

MEDIUM CVSS 5.3 2024-10-15
Threat Entry Updated 2025-01-16

CVE-2024-8902 - Elementor Addon Elements Plugin

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function in modules/data-table/widgets/data-table.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

PLUGIN Elementor Addon Elements

CVE-2024-8902

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-8757 - Wp Post Author Plugin

The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_user_id parameter in all versions up to, and including, 3.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be…

PLUGIN Wp Post Author

CVE-2024-8757

HIGH CVSS 7.2 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9696 - Rescue Shortcodes Plugin

The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' shortcode in all versions up to, and including, 2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rescue Shortcodes

CVE-2024-9696

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2025-08-09

CVE-2024-9595 - Tablepress Plugin

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tablepress

CVE-2024-9595

MEDIUM CVSS 6.4 2024-10-12
Scroll to top