Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 9761-9780 of 16088 records
Threat Entry Updated 2024-11-21

CVE-2024-5004 - Cm Popup Plugin For Wordpress

The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Cm Popup Plugin For Wordpress

CVE-2024-5004

MEDIUM CVSS 4.8 2024-07-22
Threat Entry Updated 2024-11-21

CVE-2024-37519 - Premium Blocks For Gutenburg Plugin

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress allows Stored XSS.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through 2.1.27.

PLUGIN Premium Blocks For Gutenburg

CVE-2024-37519

MEDIUM CVSS 6.5 2024-07-21
Threat Entry Updated 2024-11-21

CVE-2024-37556 - Wordpress Notification Bar Plugin

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SeedProd WordPress Notification Bar allows Stored XSS.This issue affects WordPress Notification Bar: from n/a through 1.3.10.

PLUGIN Wordpress Notification Bar

CVE-2024-37556

MEDIUM CVSS 5.9 2024-07-21
Threat Entry Updated 2025-03-20

CVE-2024-6848 - Post And Page Builder Plugin

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 1.26.6 due to insufficient input sanitization and output escaping affecting the boldgrid_canvas_image AJAX endpoint. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Post And Page Builder

CVE-2024-6848

MEDIUM CVSS 6.4 2024-07-20
Threat Entry Updated 2025-04-05

CVE-2024-6497 - Seo Plugin By Squirrly Seo

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 12.3.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Seo Plugin By Squirrly Seo

CVE-2024-6497

HIGH CVSS 8.8 2024-07-20
Threat Entry Updated 2024-11-21

CVE-2024-37959 - Power Bi Embedded Plugin

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Atlas Public Policy Power BI Embedded for WordPress allows Stored XSS.This issue affects Power BI Embedded for WordPress: from n/a through 1.1.7.

PLUGIN Power Bi Embedded

CVE-2024-37959

MEDIUM CVSS 6.5 2024-07-20
Threat Entry Updated 2025-02-11

CVE-2024-6636 - Woocommerce Social Login Plugin

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator while registering for an account.

PLUGIN Woocommerce Social Login

CVE-2024-6636

CRITICAL CVSS 9.8 2024-07-20
Threat Entry Updated 2025-02-11

CVE-2024-6637 - Woocommerce Social Login Plugin

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password for any user, except an Administrator, if they know the email of user.

PLUGIN Woocommerce Social Login

CVE-2024-6637

HIGH CVSS 7.3 2024-07-20
Threat Entry Updated 2025-02-11

CVE-2024-6635 - Woocommerce Social Login Plugin

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an administrator, if they know the email of user.

PLUGIN Woocommerce Social Login

CVE-2024-6635

HIGH CVSS 7.3 2024-07-20
Threat Entry Updated 2025-02-04

CVE-2024-6491 - Getwid Plugin

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to set the MailChimp API key.

PLUGIN Getwid

CVE-2024-6491

MEDIUM CVSS 4.3 2024-07-20
Threat Entry Updated 2025-02-04

CVE-2024-6489 - Getwid Plugin

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_google_api_key function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to set the MailChimp API key.

PLUGIN Getwid

CVE-2024-6489

MEDIUM CVSS 5.3 2024-07-20
Threat Entry Updated 2024-11-21

CVE-2024-6694 - Wp Mail Smtp Plugin

The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated attackers, with administrative-level access and above, to view the SMTP password for the supplied server. Although this would not be useful for attackers in most cases, if an administrator account becomes compromised this could be useful information to an attacker in a limited environment.

PLUGIN Wp Mail Smtp

CVE-2024-6694

LOW CVSS 2.7 2024-07-20
Threat Entry Updated 2024-11-21

CVE-2024-3934 - Woocommerce Mercadopago Plugin

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.1 via the mercadopagoDownloadLog function. This makes it possible for authenticated attackers, with subscriber-level access and above, to download and read the contents of arbitrary files on the server, which can contain sensitive information. The arbitrary file download was patched in 7.5.1, while the missing authorization was corrected in version 7.6.2.

PLUGIN Woocommerce Mercadopago

CVE-2024-3934

MEDIUM CVSS 6.5 2024-07-20
Threat Entry Updated 2025-07-10

CVE-2024-2337 - Easy Testimonials Plugin

The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_grid ' shortcode in all versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Testimonials

CVE-2024-2337

MEDIUM CVSS 6.4 2024-07-20
Threat Entry Updated 2024-11-21

CVE-2024-6560 - Addonify Quick View Plugin

The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.16. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Addonify Quick View

CVE-2024-6560

MEDIUM CVSS 5.3 2024-07-20
Threat Entry Updated 2024-11-21

CVE-2024-5804 - Cf7 Conditional Fields Plugin

The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.13. This is due to missing or incorrect nonce validation on the wpcf7cf_admin_init function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Cf7 Conditional Fields

CVE-2024-5804

MEDIUM CVSS 4.3 2024-07-20
Threat Entry Updated 2024-11-21

CVE-2024-5977 - Givewp Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with GiveWP Worker-level access and above, to delete and update arbitrary posts.

PLUGIN Givewp

CVE-2024-5977

MEDIUM CVSS 5.4 2024-07-19
Threat Entry Updated 2024-11-21

CVE-2024-6799 - Yith Essential Kit For Woocommerce Plugin

The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_module', 'deactivate_module', and 'install_module' functions in all versions up to, and including, 2.34.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install, activate, and deactivate plugins from a pre-defined list of available YITH plugins.

PLUGIN Yith Essential Kit For Woocommerce

CVE-2024-6799

MEDIUM CVSS 4.3 2024-07-19
Threat Entry Updated 2024-11-21

CVE-2024-6338 - Fv Flowplayer Video Player Plugin

The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Fv Flowplayer Video Player

CVE-2024-6338

HIGH CVSS 8.8 2024-07-19
Threat Entry Updated 2024-11-21

CVE-2024-6205 - Payplus Payment Gateway Plugin

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.

PLUGIN Payplus Payment Gateway

CVE-2024-6205

CRITICAL CVSS 9.8 2024-07-19
Scroll to top