Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,088
Critical989
High3,304
Medium11,522
Reset
Showing 10201-10220 of 16088 records
Threat Entry Updated 2024-11-21

CVE-2024-3966 - Pray For Me Plugin

The Pray For Me WordPress plugin through 1.0.4 does not sanitise and escape some parameters, which could unauthenticated visitors to perform Cross-Site Scripting attacks that trigger when an admin visits the Prayer Requests in the WP Admin

PLUGIN Pray For Me

CVE-2024-3966

MEDIUM CVSS 6.1 2024-06-14
Threat Entry Updated 2025-03-24

CVE-2024-4270 - Svgmagic Plugin

The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

PLUGIN Svgmagic

CVE-2024-4270

MEDIUM CVSS 5.4 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-3978 - Wordpress Jitsi Shortcode Plugin

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Wordpress Jitsi Shortcode

CVE-2024-3978

MEDIUM CVSS 5.4 2024-06-14
Threat Entry Updated 2025-05-13

CVE-2024-3965 - Pray For Me Plugin

The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Pray For Me

CVE-2024-3965

MEDIUM CVSS 5.4 2024-06-14
Threat Entry Updated 2025-03-13

CVE-2024-4005 - Social Pixel Plugin

The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Social Pixel

CVE-2024-4005

MEDIUM CVSS 4.8 2024-06-14
Threat Entry Updated 2025-03-25

CVE-2024-3992 - Amen Plugin

The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Amen

CVE-2024-3992

MEDIUM CVSS 4.8 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-3977 - Wordpress Jitsi Shortcode Plugin

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wordpress Jitsi Shortcode

CVE-2024-3977

MEDIUM CVSS 4.8 2024-06-14
Threat Entry Updated 2025-05-13

CVE-2024-4271 - Svgator Plugin

The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

PLUGIN Svgator

CVE-2024-4271

MEDIUM CVSS 4.6 2024-06-14
Threat Entry Updated 2025-05-13

CVE-2024-3993 - Azan Plugin

The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Azan

CVE-2024-3993

MEDIUM CVSS 4.6 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-3972 - Similarity Plugin

The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Similarity

CVE-2024-3972

MEDIUM CVSS 4.3 2024-06-14
Threat Entry Updated 2025-03-13

CVE-2024-3971 - Similarity Plugin

The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

PLUGIN Similarity

CVE-2024-3971

MEDIUM CVSS 4.3 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-2122 - Foogallery Plugin

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up to, and including, 2.4.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Foogallery

CVE-2024-2122

MEDIUM CVSS 6.4 2024-06-14
Threat Entry Updated 2025-07-03

CVE-2024-3754 - Alemha Watermark Plugin

The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Alemha Watermark

CVE-2024-3754

MEDIUM CVSS 4.7 2024-06-14
Threat Entry Updated 2025-05-13

CVE-2024-2218 - Luckywp Table Of Contents Plugin

The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Luckywp Table Of Contents

CVE-2024-2218

MEDIUM CVSS 4.6 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-1295 - Events Calendar Plugin

The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)

PLUGIN Events Calendar

CVE-2024-1295

MEDIUM CVSS 6.5 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-4936 - Canto Plugin

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. This required allow_url_include to be enabled on the target site in order to exploit.

PLUGIN Canto

CVE-2024-4936

CRITICAL CVSS 9.8 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-1094 - Owered Appointment Booking With Visual Seat Plan And Ultimate Calendar Scheduling Plugin

The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the make_staff() function in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to grant users staff permissions.

PLUGIN Owered Appointment Booking With Visual Seat Plan And Ultimate Calendar Scheduling

CVE-2024-1094

HIGH CVSS 7.3 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-0892 - Schema App Structured Data For Schemaorg Plugin

The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the MarkUpdate function. This makes it possible for unauthenticated attackers to update and delete post metadata via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Schema App Structured Data For Schemaorg

CVE-2024-0892

MEDIUM CVSS 4.3 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2023-6492 - Create A Responsive Html Sitemap Plugin

The Simple Sitemap – Create a Responsive HTML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.13. This is due to missing or incorrect nonce validation in the 'admin_notices' hook found in class-settings.php. This makes it possible for unauthenticated attackers to reset the plugin options to a default state via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Create A Responsive Html Sitemap

CVE-2023-6492

MEDIUM CVSS 4.3 2024-06-14
Threat Entry Updated 2025-02-11

CVE-2024-37308 - Cooked Plugin

The Cooked Pro recipe plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `_recipe_settings[post_title]` parameter in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. A patch is available at commit 8cf88f334ccbf11134080bbb655c66f1cfe77026 and will be part of version 1.8.0.

PLUGIN Cooked

CVE-2024-37308

MEDIUM CVSS 5.4 2024-06-13
Scroll to top