Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 9681-9700 of 16088 records
Threat Entry Updated 2026-01-02

CVE-2024-6230 - Pardakht Delkhah Plugin

The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack

PLUGIN Pardakht Delkhah

CVE-2024-6230

MEDIUM CVSS 6.5 2024-07-30
Threat Entry Updated 2025-08-20

CVE-2024-6226 - Wpstickybar Plugin

The WpStickyBar WordPress plugin through 2.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Wpstickybar

CVE-2024-6226

MEDIUM CVSS 6.1 2024-07-30
Threat Entry Updated 2025-05-29

CVE-2024-6223 - Send Email Only On Reply To My Comment Plugin

The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Send Email Only On Reply To My Comment

CVE-2024-6223

MEDIUM CVSS 6.1 2024-07-30
Threat Entry Updated 2025-05-28

CVE-2024-5809 - Wp Ajax Contact Form Plugin

The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin users

PLUGIN Wp Ajax Contact Form

CVE-2024-5809

MEDIUM CVSS 6.1 2024-07-30
Threat Entry Updated 2025-05-29

CVE-2024-6224 - Send Email Only On Reply To My Comment Plugin

The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Send Email Only On Reply To My Comment

CVE-2024-6224

MEDIUM CVSS 5.9 2024-07-30
Threat Entry Updated 2025-05-28

CVE-2024-5808 - Wp Ajax Contact Form Plugin

The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in admin perform such action via a CSRF attack

PLUGIN Wp Ajax Contact Form

CVE-2024-5808

MEDIUM CVSS 4.3 2024-07-30
Threat Entry Updated 2025-08-20

CVE-2024-5765 - Wpstickybar Plugin

The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN Wpstickybar

CVE-2024-5765

CRITICAL CVSS 9.8 2024-07-30
Threat Entry Updated 2025-05-28

CVE-2024-5807 - Business Card Plugin

The Business Card WordPress plugin through 1.0.0 does not prevent high privilege users like administrators from uploading malicious PHP files, which could allow them to run arbitrary code on servers hosting their site, even in MultiSite configurations.

PLUGIN Business Card

CVE-2024-5807

HIGH CVSS 7.2 2024-07-30
Threat Entry Updated 2025-05-28

CVE-2024-3669 - Web Directory Free Plugin

The Web Directory Free WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Web Directory Free

CVE-2024-3669

MEDIUM CVSS 6.8 2024-07-30
Threat Entry Updated 2025-08-22

CVE-2024-1287 - Pmpro Member Directory Plugin

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

PLUGIN Pmpro Member Directory

CVE-2024-1287

MEDIUM CVSS 6.5 2024-07-30
Threat Entry Updated 2025-05-28

CVE-2024-4096 - Responsive Tabs Plugin

The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks

PLUGIN Responsive Tabs

CVE-2024-4096

MEDIUM CVSS 5.9 2024-07-30
Threat Entry Updated 2025-05-30

CVE-2024-3113 - Whatsapp Social And Advanced Form Builder With Easy Lead Collection Plugin

The FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection WordPress plugin before 2.12.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Whatsapp Social And Advanced Form Builder With Easy Lead Collection

CVE-2024-3113

MEDIUM CVSS 5.9 2024-07-30
Threat Entry Updated 2025-03-13

CVE-2024-3986 - Before 2 Plugin

The SportsPress WordPress plugin before 2.7.22 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2024-3986

MEDIUM CVSS 4.8 2024-07-30
Threat Entry Updated 2025-10-02

CVE-2024-1286 - Pmpro Membership Maps Plugin

The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site.

PLUGIN Pmpro Membership Maps

CVE-2024-1286

MEDIUM CVSS 4.9 2024-07-30
Threat Entry Updated 2025-05-30

CVE-2024-6366 - User Profile Builder Plugin

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

PLUGIN User Profile Builder

CVE-2024-6366

CRITICAL CVSS 9.1 2024-07-29
Threat Entry Updated 2025-04-10

CVE-2024-5882 - Ultimate Classified Listings Plugin

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

PLUGIN Ultimate Classified Listings

CVE-2024-5882

HIGH CVSS 7.5 2024-07-29
Threat Entry Updated 2025-05-30

CVE-2024-6487 - Inline Related Posts Plugin

The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Inline Related Posts

CVE-2024-6487

MEDIUM CVSS 5.9 2024-07-29
Threat Entry Updated 2025-07-07

CVE-2024-5285 - Wp Affiliate Platform Plugin

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack

PLUGIN Wp Affiliate Platform

CVE-2024-5285

MEDIUM CVSS 5.5 2024-07-29
Threat Entry Updated 2025-05-29

CVE-2024-4483 - Email Encoder Plugin

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting

PLUGIN Email Encoder

CVE-2024-4483

MEDIUM CVSS 5.4 2024-07-29
Scroll to top