Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 10181-10200 of 16088 records
Threat Entry Updated 2025-02-07

CVE-2024-5871 - Woocommerce Social Login Plugin

The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Woocommerce Social Login

CVE-2024-5871

CRITICAL CVSS 9.8 2024-06-15
Threat Entry Updated 2025-02-07

CVE-2024-5868 - Woocommerce Social Login Plugin

The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.

PLUGIN Woocommerce Social Login

CVE-2024-5868

MEDIUM CVSS 6.5 2024-06-15
Threat Entry Updated 2024-11-21

CVE-2024-5263 - Elementskit Plugin

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elementskit

CVE-2024-5263

MEDIUM CVSS 6.4 2024-06-15
Threat Entry Updated 2024-11-21

CVE-2024-4479 - Jeg Elementor Kit Plugin

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_enable and sg_accordion_style attributes within the plugin's JKit - Tabs and JKit - Accordion widget, respectively, in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Jeg Elementor Kit

CVE-2024-4479

MEDIUM CVSS 6.4 2024-06-15
Threat Entry Updated 2024-11-21

CVE-2024-3815 - Newspaper Plugin

The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Newspaper

CVE-2024-3815

MEDIUM CVSS 5.5 2024-06-15
Threat Entry Updated 2024-11-21

CVE-2024-3814 - Tagdiv Composer Plugin

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tagdiv Composer

CVE-2024-3814

MEDIUM CVSS 5.5 2024-06-15
Threat Entry Updated 2024-11-21

CVE-2024-3813 - Tagdiv Composer Plugin

The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

PLUGIN Tagdiv Composer

CVE-2024-3813

HIGH CVSS 8.8 2024-06-15
Threat Entry Updated 2024-11-21

CVE-2023-6696 - Popup Builder Plugin

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 4.3.1. While some functions contain a nonce check, the nonce can be obtained from the profile page of a logged-in user. This allows subscribers to perform several actions including deleting subscribers and perform blind Server-Side Request Forgery.

PLUGIN Popup Builder

CVE-2023-6696

HIGH CVSS 8.1 2024-06-15
Threat Entry Updated 2024-11-21

CVE-2024-2544 - Popup Builder Plugin

The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform multiple unauthorized actions, such as deleting subscribers, and importing subscribers to conduct stored cross-site scripting attacks.

PLUGIN Popup Builder

CVE-2024-2544

HIGH CVSS 7.4 2024-06-15
Threat Entry Updated 2024-11-21

CVE-2024-2024 - Folders Plugin

The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_folders_file_upload' function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Folders

CVE-2024-2024

HIGH CVSS 8.8 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-2023 - Folders And Folders Pro Plugin

The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 in Folders Pro via the 'handle_folders_file_upload' function. This makes it possible for authenticated attackers, with author access and above, to upload files to arbitrary locations on the server.

PLUGIN Folders And Folders Pro

CVE-2024-2023

MEDIUM CVSS 4.3 2024-06-14
Threat Entry Updated 2025-02-20

CVE-2024-2472 - Latepoint Plugin

The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's cabinets, including the ability to view PII such as email addresses and to change their LatePoint user password, which may or may not be associated with a WordPress account.

PLUGIN Latepoint

CVE-2024-2472

CRITICAL CVSS 9.1 2024-06-14
Threat Entry Updated 2025-02-07

CVE-2024-4863 - Gutenberg Blocks With Ai Plugin

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘titleFont’ parameter in all versions up to, and including, 3.2.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Blocks With Ai

CVE-2024-4863

MEDIUM CVSS 6.4 2024-06-14
Threat Entry Updated 2025-02-11

CVE-2024-5994 - Wp Go Maps Plugin

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38. This makes it possible for authenticated attackers that have been explicitly granted permissions by an administrator, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Version 9.0.39 adds a caution to make administrators aware of the possibility for abuse if permissions are granted to lower-level users.

PLUGIN Wp Go Maps

CVE-2024-5994

MEDIUM CVSS 6.4 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-5551 - Wp Staging Plugin

The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or incorrect nonce validation on the 'sub' parameter called from the WP STAGING WordPress Backup Plugin - Backup Duplicator & Migration plugin. This makes it possible for unauthenticated attackers to include any local files that end in '-settings.php' via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Staging

CVE-2024-5551

HIGH CVSS 7.5 2024-06-14
Threat Entry Updated 2025-06-06

CVE-2024-5155 - Inquiry Cart Plugin

The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Inquiry Cart

CVE-2024-5155

MEDIUM CVSS 6.1 2024-06-14
Threat Entry Updated 2025-05-13

CVE-2024-4480 - Prayer Plugin

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Prayer

CVE-2024-4480

MEDIUM CVSS 6.1 2024-06-14
Threat Entry Updated 2025-07-11

CVE-2024-4751 - Prayer Plugin

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Prayer

CVE-2024-4751

MEDIUM CVSS 4.3 2024-06-14
Threat Entry Updated 2025-01-10

CVE-2024-4404 - Elementskit Plugin

The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' function. This can allow authenticated attackers, with contributor-level permissions and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Elementskit

CVE-2024-4404

HIGH CVSS 8.5 2024-06-14
Scroll to top