Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 9781-9800 of 16088 records
Threat Entry Updated 2025-05-16

CVE-2023-7269 - Before 2 Plugin

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Before 2

CVE-2023-7269

HIGH CVSS 7.5 2024-07-19
Threat Entry Updated 2025-05-16

CVE-2024-5604 - Bug Library Plugin

The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Bug Library

CVE-2024-5604

MEDIUM CVSS 5.9 2024-07-19
Threat Entry Updated 2025-05-16

CVE-2023-7268 - Before 2 Plugin

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets

PLUGIN Before 2

CVE-2023-7268

MEDIUM CVSS 6.5 2024-07-19
Threat Entry Updated 2024-11-21

CVE-2024-5997 - Custom Posts Or Users Plugin

The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_user and duplicate_post functions in all versions up to, and including, 0.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create duplicates of users and posts/pages.

PLUGIN Custom Posts Or Users

CVE-2024-5997

MEDIUM CVSS 4.3 2024-07-18
Threat Entry Updated 2025-01-16

CVE-2024-6455 - Elements Kit Elementor Addons Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, pending and private items.

PLUGIN Elements Kit Elementor Addons

CVE-2024-6455

MEDIUM CVSS 5.3 2024-07-18
Threat Entry Updated 2025-01-16

CVE-2024-3242 - Brizy Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageContent function called via storeImages in all versions up to, and including, 2.4.43. This makes it possible for authenticated attackers, with contributor access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. Version 2.4.44 prevents the upload of files ending in .sh and .php. Version 2.4.45 fully patches the issue.

PLUGIN Brizy

CVE-2024-3242

HIGH CVSS 8.8 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-5555 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘social-link-title’ parameter in all versions up to, and including, 5.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-5555

MEDIUM CVSS 6.4 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-5554 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘onclick_event’ parameter in all versions up to, and including, 5.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-5554

MEDIUM CVSS 6.4 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-6164 - Before 2 Plugin

The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

PLUGIN Before 2

CVE-2024-6164

CRITICAL CVSS 9.8 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2023-6708 - Svg Support Plugin

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping, even when the 'Sanitize SVG while uploading' feature is enabled. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that successful exploitation of this vulnerability requires the administrator to allow author-level users to upload SVG files.

PLUGIN Svg Support

CVE-2023-6708

MEDIUM CVSS 5.4 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-6705 - Reglevel Plugin

The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Reglevel

CVE-2024-6705

MEDIUM CVSS 5.5 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-6175 - Booking Ultra Pro Plugin

The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions in all versions up to, and including, 1.1.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify and delete. multiple plugin options and data such as payments, pricing, booking information, business hours, calendars, profile information, and email templates.

PLUGIN Booking Ultra Pro

CVE-2024-6175

MEDIUM CVSS 5.4 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-6599 - Meks Video Importer Plugin

The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capability check on the ajax_save_settings function in all versions up to, and including, 1.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's API keys

PLUGIN Meks Video Importer

CVE-2024-6599

MEDIUM CVSS 4.3 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-5726 - Timeline Event History Plugin

The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1 via deserialization of untrusted input 'timelines-data' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Timeline Event History

CVE-2024-5726

HIGH CVSS 8.8 2024-07-18
Threat Entry Updated 2025-02-10

CVE-2024-39682 - Cooked Plugin

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary HTML in pages that will be shown whenever a user accesses a compromised page. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

PLUGIN Cooked

CVE-2024-39682

MEDIUM CVSS 6.4 2024-07-18
Threat Entry Updated 2025-02-10

CVE-2024-39681 - Cooked Plugin

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they didn't intend to perform under their current authentication. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

PLUGIN Cooked

CVE-2024-39681

MEDIUM CVSS 5.4 2024-07-18
Threat Entry Updated 2025-02-10

CVE-2024-39680 - Cooked Plugin

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they didn't intend to perform under their current authentication. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

PLUGIN Cooked

CVE-2024-39680

MEDIUM CVSS 5.4 2024-07-18
Threat Entry Updated 2025-02-10

CVE-2024-39679 - Cooked Plugin

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they didn't intend to perform under their current authentication. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

PLUGIN Cooked

CVE-2024-39679

MEDIUM CVSS 4.3 2024-07-18
Threat Entry Updated 2025-02-10

CVE-2024-39678 - Cooked Plugin

Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they didn't intend to perform under their current authentication. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

PLUGIN Cooked

CVE-2024-39678

MEDIUM CVSS 4.3 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-6220 - Keydatas Plugin

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Keydatas

CVE-2024-6220

CRITICAL CVSS 9.8 2024-07-17
Scroll to top