Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,135
Critical989
High3,304
Medium11,522
Reset
Showing 10581-10600 of 16135 records
Threat Entry Updated 2024-11-21

CVE-2024-4431 - Lastudio Element Kit Plugin

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Lastudio Element Kit

CVE-2024-4431

MEDIUM CVSS 6.4 2024-05-23
Threat Entry Updated 2024-11-21

CVE-2024-4895 - Wpdatatables Plugin

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CSV import functionality in all versions up to, and including, 3.4.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wpdatatables

CVE-2024-4895

MEDIUM CVSS 4.7 2024-05-23
Threat Entry Updated 2024-11-21

CVE-2024-4783 - Jquery T Countdown Widget Plugin

The jQuery T(-) Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tminus shortcode in all versions up to, and including, 2.3.25 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Jquery T Countdown Widget

CVE-2024-4783

MEDIUM CVSS 6.4 2024-05-23
Threat Entry Updated 2024-11-21

CVE-2024-4486 - Awesome Contact Form7 For Elementor Plugin

The Awesome Contact Form7 for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'AEP Contact Form 7' widget in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Awesome Contact Form7 For Elementor

CVE-2024-4486

MEDIUM CVSS 6.4 2024-05-23
Threat Entry Updated 2025-03-06

CVE-2024-1855 - Wpcafe Plugin

The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.23 via the wpc_check_for_submission function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application.

PLUGIN Wpcafe

CVE-2024-1855

MEDIUM CVSS 5.3 2024-05-23
Threat Entry Updated 2024-11-21

CVE-2023-6844 - Iframe Plugin

The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to and including 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Iframe

CVE-2023-6844

MEDIUM CVSS 5.0 2024-05-23
Threat Entry Updated 2024-11-21

CVE-2024-3065 - Paypal Pay Buy Donation And Cart Buttons Shortcode Plugin

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Paypal Pay Buy Donation And Cart Buttons Shortcode

CVE-2024-3065

MEDIUM CVSS 4.4 2024-05-23
Threat Entry Updated 2025-02-27

CVE-2024-3926 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-3926

MEDIUM CVSS 6.4 2024-05-22
Threat Entry Updated 2024-11-21

CVE-2024-4261 - Lead Form Builder Plugin

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.

PLUGIN Lead Form Builder

CVE-2024-4261

MEDIUM CVSS 5.4 2024-05-22
Threat Entry Updated 2024-11-21

CVE-2024-4262 - Piotnet Addons For Elementor Plugin

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.4.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Piotnet Addons For Elementor

CVE-2024-4262

HIGH CVSS 7.2 2024-05-22
Threat Entry Updated 2025-01-31

CVE-2024-5031 - Memberpress Plugin

The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.11.29 via the 'mepr-user-file' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Memberpress

CVE-2024-5031

HIGH CVSS 8.5 2024-05-22
Threat Entry Updated 2025-01-24

CVE-2024-5025 - Memberpress Plugin

The Memberpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arglist’ parameter in all versions up to, and including, 1.11.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Memberpress

CVE-2024-5025

MEDIUM CVSS 6.4 2024-05-22
Threat Entry Updated 2024-11-21

CVE-2024-3495 - Country State City Auto Dropdown Plugin

The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Country State City Auto Dropdown

CVE-2024-3495

CRITICAL CVSS 9.8 2024-05-22
Threat Entry Updated 2025-02-27

CVE-2024-4896 - Wpb Elementor Addons Plugin

The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wpb Elementor Addons

CVE-2024-4896

MEDIUM CVSS 6.4 2024-05-22
Threat Entry Updated 2025-03-24

CVE-2024-4362 - Siteorigin Widgets Bundle Plugin

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 1.60.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Siteorigin Widgets Bundle

CVE-2024-4362

MEDIUM CVSS 6.4 2024-05-22
Threat Entry Updated 2024-11-21

CVE-2024-2036 - Apply Online Plugin

The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the aol_modal_box AJAX action in all versions up to, and including, 2.6. This makes it possible for authenticated attackers, with subscriber access or higher, to view Application submissions.

PLUGIN Apply Online

CVE-2024-2036

MEDIUM CVSS 4.3 2024-05-22
Threat Entry Updated 2025-02-05

CVE-2024-5147 - Wpzoom Elementor Addons Plugin

The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.37 via the 'grid_style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Wpzoom Elementor Addons

CVE-2024-5147

CRITICAL CVSS 9.8 2024-05-22
Threat Entry Updated 2025-02-06

CVE-2024-4157 - Contact Form Plugin

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or…

PLUGIN Contact Form

CVE-2024-4157

HIGH CVSS 7.5 2024-05-22
Threat Entry Updated 2024-11-21

CVE-2024-3671 - Print O Matic Plugin

The Print-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'print-me' shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes such as 'tag'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Print O Matic

CVE-2024-3671

MEDIUM CVSS 6.4 2024-05-22
Threat Entry Updated 2024-11-21

CVE-2024-3666 - Opal Estate Pro Plugin

The Opal Estate Pro – Property Management and Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the agent latitude and longitude parameters in all versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Opal Estate Pro

CVE-2024-3666

MEDIUM CVSS 6.4 2024-05-22
Scroll to top