Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 9701-9720 of 16088 records
Threat Entry Updated 2025-04-10

CVE-2024-5883 - Ultimate Classified Listings Plugin

The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Ultimate Classified Listings

CVE-2024-5883

MEDIUM CVSS 4.7 2024-07-29
Threat Entry Updated 2025-05-29

CVE-2024-6362 - Ultimate Blocks Plugin

The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Ultimate Blocks

CVE-2024-6362

MEDIUM CVSS 4.6 2024-07-29
Threat Entry Updated 2025-02-10

CVE-2024-6703 - Contact Form Plugin

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ and 'btn_txt' parameters in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for attackers with the Form Manager permissions and Subscriber+ user role, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Contact Form

CVE-2024-6703

MEDIUM CVSS 4.9 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6897 - Athemes Starter Sites Plugin

The aThemes Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Athemes Starter Sites

CVE-2024-6897

MEDIUM CVSS 6.4 2024-07-27
Threat Entry Updated 2025-02-06

CVE-2024-6627 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Happy Addons For Elementor

CVE-2024-6627

MEDIUM CVSS 6.4 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6521 - Contact Form Plugin

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Contact Form

CVE-2024-6521

MEDIUM CVSS 5.5 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6520 - Contact Form Plugin

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Contact Form

CVE-2024-6520

MEDIUM CVSS 5.5 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6518 - Contact Form Plugin

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Contact Form

CVE-2024-6518

MEDIUM CVSS 5.5 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-5614 - Piotnet Addons For Elementor Plugin

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 via the 'pafe_posts_list' function. This makes it possible for unauthenticated attackers to extract sensitive data including titles and excerpts of future, draft, and pending blog posts.

PLUGIN Piotnet Addons For Elementor

CVE-2024-5614

MEDIUM CVSS 5.3 2024-07-27
Threat Entry Updated 2025-02-19

CVE-2024-6458 - Woocommerce Product Table Plugin

The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a missing capability check on the wcpt_presets__duplicate_preset_to_table function in all versions up to, and including, 3.5.1. This makes it possible for authenticated attackers with subscriber access and above to change titles of arbitrary posts. Missing sanitization can lead to Stored Cross-Site Scripting when viewed by an admin via the WooCommerce Product Table.

PLUGIN Woocommerce Product Table

CVE-2024-6458

MEDIUM CVSS 6.4 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6569 - Forms For Campaign Monitor Plugin

The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is due the plugin not properly restricting direct access to /forms/views/admin/create.php and display_errors being enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Forms For Campaign Monitor

CVE-2024-6569

MEDIUM CVSS 5.3 2024-07-27
Threat Entry Updated 2025-08-08

CVE-2024-5969 - Aiomatic Plugin

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.

PLUGIN Aiomatic

CVE-2024-5969

MEDIUM CVSS 5.8 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6634 - Mastercurrency Wp Plugin

The Master Currency WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currencyconverterform shortcode in all versions up to, and including, 1.1.61 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mastercurrency Wp

CVE-2024-6634

MEDIUM CVSS 6.4 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6591 - Ultimate Auction Plugin

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_callback' and 'resend_auction_email_callback' functions in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to craft emails that include links and send to any email address.

PLUGIN Ultimate Auction

CVE-2024-6591

MEDIUM CVSS 5.8 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6661 - Parity Pricing With Discount Rules Plugin

The ParityPress – Parity Pricing with Discount Rules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Discount Text' in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Parity Pricing With Discount Rules

CVE-2024-6661

MEDIUM CVSS 5.5 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6573 - Intelligence Plugin

The Intelligence plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.0. This is due the plugin not preventing direct access to the /vendor/levelten/intel/realtime/index.php file and display_errors being enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Intelligence

CVE-2024-6573

MEDIUM CVSS 5.3 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6566 - Aramex Shipping Woocommerce Plugin

The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.21. This is due the plugin not preventing direct access to the composer-setup.php file which also has display_errors enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Aramex Shipping Woocommerce

CVE-2024-6566

MEDIUM CVSS 5.3 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6549 - Admin Post Navigation Plugin

The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Admin Post Navigation

CVE-2024-6549

MEDIUM CVSS 5.3 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6548 - Add Admin Javascript Plugin

The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Add Admin Javascript

CVE-2024-6548

MEDIUM CVSS 5.3 2024-07-27
Threat Entry Updated 2024-11-21

CVE-2024-6547 - Add Admin Css Plugin

The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Add Admin Css

CVE-2024-6547

MEDIUM CVSS 5.3 2024-07-27
Scroll to top