Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 10101-10120 of 16088 records
Threat Entry Updated 2024-11-21

CVE-2024-4969 - Widget Bundle Plugin

The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attackers to make logged in admin enable/disable widgets via a CSRF attack

PLUGIN Widget Bundle

CVE-2024-4969

MEDIUM CVSS 4.3 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-4475 - Wp Logs Book Plugin

The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers to make a logged in admin clear the logs them via a CSRF attack

PLUGIN Wp Logs Book

CVE-2024-4475

MEDIUM CVSS 4.3 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-4474 - Wp Logs Book Plugin

The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Wp Logs Book

CVE-2024-4474

MEDIUM CVSS 4.3 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-4377 - Dot On Paper Shortcodes Plugin

The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Dot On Paper Shortcodes

CVE-2024-4377

MEDIUM CVSS 5.4 2024-06-21
Threat Entry Updated 2025-03-13

CVE-2024-4381 - Commonsbooking Plugin

The CB (legacy) WordPress plugin through 0.9.4.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Commonsbooking

CVE-2024-4381

MEDIUM CVSS 4.8 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-5756 - Icegram Express Plugin

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Icegram Express

CVE-2024-5756

CRITICAL CVSS 9.8 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-5455 - Plus Addons For Elementor Plugin

The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.5.4 via the 'magazine_style' parameter within the Dynamic Smart Showcase widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can…

PLUGIN Plus Addons For Elementor

CVE-2024-5455

HIGH CVSS 8.8 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-3961 - Convertkit Email Marketing Email Newsletter And Landing Pages Plugin

The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to subscribe users to tags. Financial damages may occur to site owners if their API quota is exceeded.

PLUGIN Convertkit Email Marketing Email Newsletter And Landing Pages

CVE-2024-3961

MEDIUM CVSS 5.3 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-5503 - Wp Blog Post Layouts Plugin

The WP Blog Post Layouts plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Wp Blog Post Layouts

CVE-2024-5503

HIGH CVSS 8.8 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-5344 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘forgoturl’ attribute within the plugin's WP Login & Register widget in all versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Plus Addons For Elementor

CVE-2024-5344

MEDIUM CVSS 6.1 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-1639 - License Manager For Woocommerce Plugin

The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with admin dashboard access (contributors by default due to WooCommerce) to view arbitrary decrypted license keys. The functions contain a referrer nonce check. However, these can be retrieved via the dashboard through the "license" JS variable.

PLUGIN License Manager For Woocommerce

CVE-2024-1639

MEDIUM CVSS 6.5 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-3610 - Wp Child Theme Generator Plugin

The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wctg_easy_child_theme() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to create a blank child theme and activate it cause the site to whitescreen.

PLUGIN Wp Child Theme Generator

CVE-2024-3610

MEDIUM CVSS 5.3 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-1955 - Hide Dashboard Notifications Plugin

The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'warning_notices_settings' function in all versions up to, and including, 1.3. This makes it possible for authenticated attackers, with contributor access and above, to modify the plugin's settings.

PLUGIN Hide Dashboard Notifications

CVE-2024-1955

MEDIUM CVSS 4.3 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2023-3352 - Smush Image Optimization – Optimize Images | Compress & Lazy Load Images | Convert WebP | Image CDN Plugin

The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability check on the delete_resmush_list() function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to delete the resmush list for Nextgen or the Media Library.

PLUGIN Smush Image Optimization – Optimize Images | Compress & Lazy Load Images | Convert WebP | Image CDN

CVE-2023-3352

MEDIUM CVSS 4.3 2024-06-21
Threat Entry Updated 2025-02-04

CVE-2024-5036 - Sina Extension For Elementor Plugin

The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sina Extension For Elementor

CVE-2024-5036

MEDIUM CVSS 6.4 2024-06-20
Threat Entry Updated 2025-05-09

CVE-2024-4098 - Shariff Wrapper Plugin

The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 via the shariff3uu_fetch_sharecounts function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Shariff Wrapper

CVE-2024-4098

CRITICAL CVSS 9.8 2024-06-20
Threat Entry Updated 2025-05-19

CVE-2024-5522 - Html5 Video Player Plugin

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

PLUGIN Html5 Video Player

CVE-2024-5522

MEDIUM CVSS 6.5 2024-06-20
Threat Entry Updated 2025-06-17

CVE-2024-5475 - Responsive Video Embed Plugin

The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Responsive Video Embed

CVE-2024-5475

MEDIUM CVSS 5.4 2024-06-20
Threat Entry Updated 2024-11-21

CVE-2024-4565 - Advanced Custom Fields Pro Plugin

The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access

PLUGIN Advanced Custom Fields Pro

CVE-2024-4565

MEDIUM CVSS 6.5 2024-06-20
Threat Entry Updated 2024-11-21

CVE-2024-5605 - Media Library Assistant Plugin

The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Media Library Assistant

CVE-2024-5605

HIGH CVSS 8.8 2024-06-20
Scroll to top