Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 9661-9680 of 16088 records
Threat Entry Updated 2025-06-10

CVE-2024-4090 - And Sticky Header For Any Plugin

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN And Sticky Header For Any

CVE-2024-4090

MEDIUM CVSS 4.8 2024-08-01
Threat Entry Updated 2025-07-16

CVE-2024-2872 - Socialdriver Framework Plugin

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Socialdriver Framework

CVE-2024-2872

MEDIUM CVSS 4.8 2024-08-01
Threat Entry Updated 2025-05-29

CVE-2024-1747 - Woocommerce Customers Manager Plugin

The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said metadata values.

PLUGIN Woocommerce Customers Manager

CVE-2024-1747

MEDIUM CVSS 6.5 2024-08-01
Threat Entry Updated 2024-11-21

CVE-2024-2090 - Remote Content Shortcode Plugin

The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5 via the remote_content shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Remote Content Shortcode

CVE-2024-2090

MEDIUM CVSS 6.4 2024-08-01
Threat Entry Updated 2024-11-23

CVE-2024-6698 - Fundengine Plugin

The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta which can be leveraged to update their capabilities to gain administrator access.

PLUGIN Fundengine

CVE-2024-6698

HIGH CVSS 8.8 2024-08-01
Threat Entry Updated 2024-11-23

CVE-2024-6687 - Ctt Expresso Para Woocommerce Plugin

The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via the /wp-content/uploads/cepw directory. The generated .pdf and log files are publicly accessible and contain sensitive information such as sender and receiver names, phone numbers, physical addresses, and email addresses

PLUGIN Ctt Expresso Para Woocommerce

CVE-2024-6687

MEDIUM CVSS 5.3 2024-08-01
Threat Entry Updated 2025-03-21

CVE-2024-6208 - Download Manager Plugin

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Download Manager

CVE-2024-6208

MEDIUM CVSS 6.4 2024-07-31
Threat Entry Updated 2025-03-07

CVE-2024-7135 - Tainacan Plugin

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Tainacan

CVE-2024-7135

MEDIUM CVSS 6.5 2024-07-31
Threat Entry Updated 2025-02-05

CVE-2024-6725 - Formidable Forms Plugin

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with form editing permissions and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Formidable Forms

CVE-2024-6725

MEDIUM CVSS 4.9 2024-07-31
Threat Entry Updated 2024-07-31

CVE-2024-2508 - Wp Mobile Menu Plugin

The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_menu_item_icon function in all versions up to, and including, 2.8.4.4. This makes it possible for unauthenticated attackers to add the '_mobmenu_icon' post meta to arbitrary posts with an arbitrary (but sanitized) value. NOTE: Version 2.8.4.4 contains a partial fix for this vulnerability.

PLUGIN Wp Mobile Menu

CVE-2024-2508

MEDIUM CVSS 5.3 2024-07-31
Threat Entry Updated 2024-07-31

CVE-2024-6770 - V Form Plugin

The Lifetime free Drag & Drop Contact Form Builder for WordPress VForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN V Form

CVE-2024-6770

HIGH CVSS 7.2 2024-07-31
Threat Entry Updated 2026-01-30

CVE-2024-6412 - Html Forms Plugin

The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

PLUGIN Html Forms

CVE-2024-6412

MEDIUM CVSS 6.5 2024-07-31
Threat Entry Updated 2025-06-10

CVE-2024-6272 - Spidercontacts Plugin

The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Spidercontacts

CVE-2024-6272

MEDIUM CVSS 6.1 2024-07-31
Threat Entry Updated 2025-05-06

CVE-2024-6408 - Slider By 10web Plugin

The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Slider By 10web

CVE-2024-6408

MEDIUM CVSS 5.4 2024-07-31
Threat Entry Updated 2025-07-07

CVE-2024-6165 - Before 2 Plugin

The WANotifier WordPress plugin before 2.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2024-6165

MEDIUM CVSS 4.8 2024-07-31
Threat Entry Updated 2025-03-13

CVE-2024-5901 - Siteorigin Widgets Bundle Plugin

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget in all versions up to, and including, 1.62.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Siteorigin Widgets Bundle

CVE-2024-5901

MEDIUM CVSS 6.4 2024-07-30
Threat Entry Updated 2025-02-06

CVE-2024-7100 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_button shortcode in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-7100

MEDIUM CVSS 6.4 2024-07-30
Threat Entry Updated 2025-06-10

CVE-2024-6536 - Zephyr Project Manager Plugin

The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Zephyr Project Manager

CVE-2024-6536

MEDIUM CVSS 5.4 2024-07-30
Threat Entry Updated 2025-05-28

CVE-2024-5975 - Cz Loan Management Plugin

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN Cz Loan Management

CVE-2024-5975

CRITICAL CVSS 9.1 2024-07-30
Scroll to top