Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 9741-9760 of 16088 records
Threat Entry Updated 2024-11-21

CVE-2024-7027 - Woocommerce Pdf Vouchers Plugin

The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.9.3. This is due to insufficient verification on the user being supplied during a QR code login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing Voucher Vendor user on the site, if they have access to the user id.

PLUGIN Woocommerce Pdf Vouchers

CVE-2024-7027

HIGH CVSS 7.3 2024-07-24
Threat Entry Updated 2024-11-21

CVE-2024-6756 - Social Auto Poster Plugin

The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Contributor-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible. An attacker can use CVE-2024-6754 to exploit with subscriber-level access.

PLUGIN Social Auto Poster

CVE-2024-6756

HIGH CVSS 8.8 2024-07-24
Threat Entry Updated 2024-11-21

CVE-2024-6753 - Social Auto Poster Plugin

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Social Auto Poster

CVE-2024-6753

HIGH CVSS 7.2 2024-07-24
Threat Entry Updated 2024-11-21

CVE-2024-6755 - Social Auto Poster Plugin

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multiple’ function in all versions up to, and including, 5.3.14. This makes it possible for unauthenticated attackers to delete arbitrary posts.

PLUGIN Social Auto Poster

CVE-2024-6755

MEDIUM CVSS 6.5 2024-07-24
Threat Entry Updated 2024-11-21

CVE-2024-6752 - Social Auto Poster Plugin

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Social Auto Poster

CVE-2024-6752

MEDIUM CVSS 6.4 2024-07-24
Threat Entry Updated 2024-11-21

CVE-2024-6754 - Social Auto Poster Plugin

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary post metadata.

PLUGIN Social Auto Poster

CVE-2024-6754

MEDIUM CVSS 5.4 2024-07-24
Threat Entry Updated 2024-11-21

CVE-2024-6750 - Social Auto Poster Plugin

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.3.14. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin options.

PLUGIN Social Auto Poster

CVE-2024-6750

HIGH CVSS 7.3 2024-07-24
Threat Entry Updated 2024-11-21

CVE-2024-6751 - Social Auto Poster Plugin

The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin options.

PLUGIN Social Auto Poster

CVE-2024-6751

MEDIUM CVSS 6.3 2024-07-24
Threat Entry Updated 2025-08-25

CVE-2024-6420 - Hide My Wp Ghost Plugin

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

PLUGIN Hide My Wp Ghost

CVE-2024-6420

HIGH CVSS 8.6 2024-07-23
Threat Entry Updated 2025-05-20

CVE-2024-6231 - Request A Quote Plugin

The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Request A Quote

CVE-2024-6231

MEDIUM CVSS 5.9 2024-07-23
Threat Entry Updated 2025-05-16

CVE-2024-4260 - Page Builder Gutenberg Blocks Plugin

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.

PLUGIN Page Builder Gutenberg Blocks

CVE-2024-4260

MEDIUM CVSS 6.5 2024-07-23
Threat Entry Updated 2024-11-21

CVE-2024-6885 - Maxi Blocks Plugin

The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maxi_remove_custom_image_size and maxi_add_custom_image_size functions in all versions up to, and including, 1.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Maxi Blocks

CVE-2024-6885

HIGH CVSS 8.1 2024-07-23
Threat Entry Updated 2024-11-21

CVE-2024-6828 - Redux Framework Plugin

The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution.

PLUGIN Redux Framework

CVE-2024-6828

HIGH CVSS 7.2 2024-07-23
Threat Entry Updated 2025-06-10

CVE-2024-37262 - Online Booking Scheduling Calendar Plugin

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita allows Reflected XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.2.

PLUGIN Online Booking Scheduling Calendar

CVE-2024-37262

HIGH CVSS 7.1 2024-07-22
Threat Entry Updated 2024-11-21

CVE-2024-37259 - Wp Extended Plugin

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended allows Reflected XSS.This issue affects The Ultimate WordPress Toolkit – WP Extended: from n/a through 2.4.7.

PLUGIN Wp Extended

CVE-2024-37259

HIGH CVSS 7.1 2024-07-22
Threat Entry Updated 2025-03-19

CVE-2024-6244 - Pz Frontend Manager Plugin

The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

PLUGIN Pz Frontend Manager

CVE-2024-6244

HIGH CVSS 8.8 2024-07-22
Threat Entry Updated 2024-11-21

CVE-2024-5973 - Masterstudy Lms Plugin

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

PLUGIN Masterstudy Lms

CVE-2024-5973

HIGH CVSS 8.8 2024-07-22
Threat Entry Updated 2024-11-21

CVE-2024-6271 - Community Events Plugin

The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack

PLUGIN Community Events

CVE-2024-6271

MEDIUM CVSS 5.4 2024-07-22
Threat Entry Updated 2026-01-30

CVE-2024-6243 - Html Forms Plugin

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

PLUGIN Html Forms

CVE-2024-6243

MEDIUM CVSS 4.8 2024-07-22
Threat Entry Updated 2025-03-18

CVE-2024-5529 - Wp Quicklatex Plugin

The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Wp Quicklatex

CVE-2024-5529

MEDIUM CVSS 4.8 2024-07-22
Scroll to top