Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 9981-10000 of 16088 records
Threat Entry Updated 2024-11-21

CVE-2024-3638 - Addons For Elementor Plugin

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Marquee Text Widget, Testimonials Widget, and Testimonial Slider widgets in all versions up to, and including, 8.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Addons For Elementor

CVE-2024-3638

MEDIUM CVSS 6.4 2024-07-04
Threat Entry Updated 2024-11-21

CVE-2024-2385 - Addons For Elementor Plugin

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.3.7 via several of the plugin's widgets through the 'style' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded…

PLUGIN Addons For Elementor

CVE-2024-2385

HIGH CVSS 8.8 2024-07-04
Threat Entry Updated 2024-11-21

CVE-2024-2926 - Addons For Elementor Plugin

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 8.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Addons For Elementor

CVE-2024-2926

MEDIUM CVSS 6.4 2024-07-04
Threat Entry Updated 2025-03-13

CVE-2024-38345 - Sola Testimonials Plugin

A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is exploited, an attacker allows a user who logs in to the WordPress site where the affected plugin is enabled to access a malicious page. As a result, the user may perform unintended operations on the WordPress site.

PLUGIN Sola Testimonials

CVE-2024-38345

HIGH CVSS 8.1 2024-07-04
Threat Entry Updated 2024-12-06

CVE-2024-38344 - Wp Tweet Walls Plugin

A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is exploited, an attacker allows a user who logs in to the WordPress site where the affected plugin is enabled to access a malicious page. As a result, the user may perform unintended operations on the WordPress site.

PLUGIN Wp Tweet Walls

CVE-2024-38344

MEDIUM CVSS 5.4 2024-07-04
Threat Entry Updated 2024-11-21

CVE-2024-6340 - Premium Addons For Elementor Plugin

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 4.10.35 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Premium Addons For Elementor

CVE-2024-6340

MEDIUM CVSS 6.4 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-6263 - Wp Lightbox 2 Plugin

The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 3.0.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Lightbox 2

CVE-2024-6263

MEDIUM CVSS 6.4 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-4482 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied 'text_days' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2024-4482

MEDIUM CVSS 6.4 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2376 - Wpqa Builder Plugin

The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

PLUGIN Wpqa Builder

CVE-2024-2376

HIGH CVSS 8.8 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2375 - Wpqa Builder Plugin

The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Wpqa Builder

CVE-2024-2375

MEDIUM CVSS 5.4 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2234 - Himer Plugin

The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Himer

CVE-2024-2234

MEDIUM CVSS 5.4 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2235 - Himer Plugin

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users vote on any polls, including those they don't have access to via a CSRF attack

PLUGIN Himer

CVE-2024-2235

MEDIUM CVSS 4.3 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2233 - Himer Plugin

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. These include declining and accepting group invitations or leaving a group

PLUGIN Himer

CVE-2024-2233

MEDIUM CVSS 4.3 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2040 - Himer Plugin

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users join private groups via a CSRF attack

PLUGIN Himer

CVE-2024-2040

MEDIUM CVSS 4.3 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-4543 - Snippet Shortcodes Plugin

The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.4. This is due to missing or incorrect nonce validation when adding or editing shortcodes. This makes it possible for unauthenticated attackers to modify shortcodes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Snippet Shortcodes

CVE-2024-4543

MEDIUM CVSS 4.3 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-6264 - Post Meta Data Manager Plugin

The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Post Meta Data Manager

CVE-2024-6264

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-4268 - Ultimate Blocks Plugin

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Blocks

CVE-2024-4268

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-6099 - Learnpress Plugin

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This is due to missing checks in the 'check_validate_fields' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.

PLUGIN Learnpress

CVE-2024-6099

MEDIUM CVSS 5.3 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-6088 - Learnpress Plugin

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function in all versions up to, and including, 4.2.6.8.1. This makes it possible for unauthenticated attackers to bypass disabled user registration to create a new account with the default role.

PLUGIN Learnpress

CVE-2024-6088

MEDIUM CVSS 5.3 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-6011 - Cost Calculator Builder Plugin

The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textarea.description’ parameter in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cost Calculator Builder

CVE-2024-6011

MEDIUM CVSS 4.4 2024-07-02
Scroll to top