Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 9641-9660 of 16088 records
Threat Entry Updated 2024-08-05

CVE-2024-7257 - Woocommerce Extra Product Options Plugin

The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Woocommerce Extra Product Options

CVE-2024-7257

CRITICAL CVSS 9.8 2024-08-03
Threat Entry Updated 2025-04-10

CVE-2024-7031 - Filester Plugin

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' function in all versions up to, and including, 1.8.2. This makes it possible for authenticated attackers, with a role that has been granted permissions by an Administrator, to update the plugin settings for user role restrictions, including allowing file types such as .php to be uploaded.

PLUGIN Filester

CVE-2024-7031

HIGH CVSS 7.5 2024-08-03
Threat Entry Updated 2024-08-05

CVE-2024-7291 - Jetformbuilder Plugin

The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-level and above permissions, to register as super-admins on the sites configured as multi-sites.

PLUGIN Jetformbuilder

CVE-2024-7291

HIGH CVSS 7.2 2024-08-03
Threat Entry Updated 2025-08-22

CVE-2024-6477 - Before 1 Plugin

The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address

PLUGIN Before 1

CVE-2024-6477

HIGH CVSS 7.5 2024-08-03
Threat Entry Updated 2025-06-06

CVE-2024-6390 - Before 9 Plugin

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 9

CVE-2024-6390

MEDIUM CVSS 5.9 2024-08-03
Threat Entry Updated 2025-06-05

CVE-2024-6704 - Wpdiscuz Plugin

The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to comments when rich editing is disabled.

PLUGIN Wpdiscuz

CVE-2024-6704

MEDIUM CVSS 5.3 2024-08-02
Threat Entry Updated 2025-01-29

CVE-2024-4643 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘end_redirect_link’ parameter in versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-4643

MEDIUM CVSS 6.4 2024-08-02
Threat Entry Updated 2024-08-02

CVE-2024-3238 - Superfly Responsive Menu Plugin

The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.29. This is due to missing or incorrect nonce validation on the ajax_handle_delete_icons() function. This makes it possible for unauthenticated attackers to delete arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Please not the CSRF was patched in 5.0.28, however, adequate directory traversal protection wasn't introduced until 5.0.30.

PLUGIN Superfly Responsive Menu

CVE-2024-3238

HIGH CVSS 8.8 2024-08-02
Threat Entry Updated 2025-04-11

CVE-2024-5595 - Essential Blocks Plugin

The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Essential Blocks

CVE-2024-5595

MEDIUM CVSS 5.4 2024-08-02
Threat Entry Updated 2025-03-01

CVE-2024-3827 - Spectra Plugin

The Spectra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block ids in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Spectra

CVE-2024-3827

MEDIUM CVSS 6.4 2024-08-02
Threat Entry Updated 2025-02-05

CVE-2024-7389 - Forminator Plugin

The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API key and make unauthorized changes to the plugin's HubSpot integration or expose personally identifiable information from plugin users using the HubSpot integration.

PLUGIN Forminator

CVE-2024-7389

HIGH CVSS 7.5 2024-08-02
Threat Entry Updated 2025-03-01

CVE-2024-6567 - Ebook Store Plugin

The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin utilizing fpdi-protection and not preventing direct access to test files that have display_errors set to true. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Ebook Store

CVE-2024-6567

MEDIUM CVSS 5.3 2024-08-02
Threat Entry Updated 2025-02-06

CVE-2024-2455 - Element Pack Plugin

The Element Pack - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget wrapper link URL in all versions up to, and including, 7.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-2455

MEDIUM CVSS 6.4 2024-08-01
Threat Entry Updated 2025-03-01

CVE-2024-6346 - Comboblocks Plugin

The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the redirectURL parameter of the Date Countdown widget, in all versions up to, and including, 2.2.85a due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Comboblocks

CVE-2024-6346

MEDIUM CVSS 6.4 2024-08-01
Threat Entry Updated 2025-03-01

CVE-2024-7302 - Blog2social Plugin

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 3gp2 file uploads in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the 3gp2 file.

PLUGIN Blog2social

CVE-2024-7302

MEDIUM CVSS 6.4 2024-08-01
Threat Entry Updated 2024-11-21

CVE-2024-5330 - Breakdance Plugin

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Breakdance

CVE-2024-5330

MEDIUM CVSS 6.4 2024-08-01
Threat Entry Updated 2024-11-21

CVE-2024-5331 - Breakdance Plugin

The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions.

PLUGIN Breakdance

CVE-2024-5331

MEDIUM CVSS 4.3 2024-08-01
Threat Entry Updated 2025-05-29

CVE-2024-3983 - Woocommerce Customers Manager Plugin

The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks

PLUGIN Woocommerce Customers Manager

CVE-2024-3983

HIGH CVSS 8.1 2024-08-01
Threat Entry Updated 2025-04-10

CVE-2024-6529 - Ultimate Classified Listings Plugin

The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Ultimate Classified Listings

CVE-2024-6529

HIGH CVSS 7.1 2024-08-01
Threat Entry Updated 2025-06-09

CVE-2024-6496 - Light Poll Plugin

The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers to make logged in users perform such action via a CSRF attack

PLUGIN Light Poll

CVE-2024-6496

MEDIUM CVSS 6.5 2024-08-01
Scroll to top