Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 9921-9940 of 16088 records
Threat Entry Updated 2024-11-21

CVE-2024-5677 - Featured Image Generator Plugin

The Featured Image Generator plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability check on the fig_save_after_generate_image function in all versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary images to a post-related gallery.

PLUGIN Featured Image Generator

CVE-2024-5677

MEDIUM CVSS 4.3 2024-07-10
Threat Entry Updated 2024-11-21

CVE-2023-7062 - Advanced File Manager Shortcodes Plugin

The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4. This makes it possible for attackers with contributor access or higher to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Advanced File Manager Shortcodes

CVE-2023-7062

HIGH CVSS 8.8 2024-07-10
Threat Entry Updated 2024-11-21

CVE-2023-7061 - Advanced File Manager Shortcodes Plugin

The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.5.3. This makes it possible for authenticated attackers with contributor access or above to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Advanced File Manager Shortcodes

CVE-2023-7061

HIGH CVSS 8.8 2024-07-10
Threat Entry Updated 2024-11-21

CVE-2024-6391 - Oik Plugin

The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bw_button shortcode in all versions up to, and including, 4.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Oik

CVE-2024-6391

MEDIUM CVSS 6.4 2024-07-09
Threat Entry Updated 2025-06-09

CVE-2024-37499 - Online Booking Scheduling Calendar Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allows Path Traversal.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.2.

PLUGIN Online Booking Scheduling Calendar

CVE-2024-37499

MEDIUM CVSS 6.5 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-5946 - Squelch Tabs And Accordions Shortcodes Plugin

The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab’ shortcode in all versions up to, and including, 0.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Squelch Tabs And Accordions Shortcodes

CVE-2024-5946

MEDIUM CVSS 6.4 2024-07-09
Threat Entry Updated 2025-03-06

CVE-2024-4862 - Wpbits Addons For Elementor Page Builder Plugin

The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wpbits Addons For Elementor Page Builder

CVE-2024-4862

MEDIUM CVSS 6.4 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-6069 - Pie Register Plugin

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation/deactivation due to missing capability checks on the pieregister_install_addon, pieregister_activate_addon and pieregister_deactivate_addon functions in all versions up to, and including, 3.8.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install, activate and deactivate arbitrary plugins. As a result attackers might achieve code execution on the targeted server

PLUGIN Pie Register

CVE-2024-6069

HIGH CVSS 8.8 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-6168 - Just Custom Fields Plugin

The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on several AJAX function. This makes it possible for unauthenticated attackers to invoke this functionality intended for admin users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This enables subscribers to manage field groups, change visibility of items among other things.

PLUGIN Just Custom Fields

CVE-2024-6168

MEDIUM CVSS 4.3 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-6167 - Just Custom Fields Plugin

The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX functions in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke this functionality intended for admin users. This enables subscribers to manage field groups, change visibility of items among other things.

PLUGIN Just Custom Fields

CVE-2024-6167

MEDIUM CVSS 4.3 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-5992 - Cliengo Plugin

The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_chatbot_token' and 'update_chatbot_position' functions in all versions up to, and including, 3.0.1. This makes it possible for unauthenticated attackers to change chatbot settings, which can lead to unavailability or other changes to the chatbot.

PLUGIN Cliengo

CVE-2024-5992

MEDIUM CVSS 6.5 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-5937 - Simple Alert Boxes Plugin

The Simple Alert Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert shortcode in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Alert Boxes

CVE-2024-5937

MEDIUM CVSS 6.4 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-5993 - Cliengo Plugin

The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_session' function in all versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the session token of the chatbot.

PLUGIN Cliengo

CVE-2024-5993

MEDIUM CVSS 5.4 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-5856 - Comment Images Reloaded Plugin

The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the cir_delete_image AJAX action in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary media attachments.

PLUGIN Comment Images Reloaded

CVE-2024-5856

MEDIUM CVSS 4.3 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-5669 - Faq For Woocommerce Plugin

The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ffw_activate_template' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to store cross-site scripting that will trigger when viewing the dashboard templates or accessing FAQs.

PLUGIN Faq For Woocommerce

CVE-2024-5669

MEDIUM CVSS 6.4 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-5648 - Wisdm Reports For Learndash Plugin

The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.8.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update various plugin settings.

PLUGIN Wisdm Reports For Learndash

CVE-2024-5648

MEDIUM CVSS 5.4 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-5810 - Optimize Pagespeed Insights Score 90 100 Plugin

The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to overwrite CSS, update the trial settings, purge the cache, and find attachments.

PLUGIN Optimize Pagespeed Insights Score 90 100

CVE-2024-5810

MEDIUM CVSS 5.3 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-5704 - Faq For Woocommerce Plugin

The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add new and update existing FAQs, FAQ lists, and modify FAQ associations with products.

PLUGIN Faq For Woocommerce

CVE-2024-5704

MEDIUM CVSS 4.3 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-5456 - Pandavideo Plugin

The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 via the 'selected_button' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Pandavideo

CVE-2024-5456

HIGH CVSS 8.8 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-5479 - Easy Pixels By Jevnet Plugin

The Easy Pixels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 2.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Pixels By Jevnet

CVE-2024-5479

HIGH CVSS 7.2 2024-07-09
Scroll to top