Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,139
Critical992
High3,318
Medium11,534
Reset
Showing 11001-11020 of 16139 records
Threat Entry Updated 2024-11-21

CVE-2023-7030 - Collapse O Matic Plugin

The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' shortcode in all versions up to, and including, 1.8.5.5 due to insufficient input sanitization and output escaping on the 'tag' user supplied attribute. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Collapse O Matic

CVE-2023-7030

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-02-06

CVE-2023-6962 - Wp Meta Seo Plugin

The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible for unauthenticated attackers to disclose potentially sensitive information via the meta description of password-protected posts.

PLUGIN Wp Meta Seo

CVE-2023-6962

MEDIUM CVSS 5.3 2024-05-02
Threat Entry Updated 2025-03-05

CVE-2023-6731 - Wp Show Posts Plugin

The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber access and above, to view arbitrary post metadata, list posts, and view terms and taxonomies.

PLUGIN Wp Show Posts

CVE-2023-6731

MEDIUM CVSS 4.3 2024-05-02
Threat Entry Updated 2025-01-28

CVE-2023-6214 - Ht Mega For Elementor Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order data including products and customer PII.

PLUGIN Ht Mega For Elementor

CVE-2023-6214

HIGH CVSS 7.5 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-3005 - La Studio Element Kit For Elementor Plugin

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's LaStudioKit Post Author widget in all versions up to, and including, 1.3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN La Studio Element Kit For Elementor

CVE-2024-3005

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-02-03

CVE-2024-3883 - 3d Flipbook Plugin

The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all versions up to, and including, 1.15.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN 3d Flipbook

CVE-2024-3883

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-3280 - Follow Us Badges Plugin

The Follow Us Badges plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsite_follow_us_badges shortcode in all versions up to, and including, 3.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Follow Us Badges

CVE-2024-3280

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-02-27

CVE-2024-3490 - Wp Recipe Maker Plugin

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-roundup-item shortcode in all versions up to, and including, 9.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Recipe Maker

CVE-2024-3490

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-3478 - Herd Effects Plugin

The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks

PLUGIN Herd Effects

CVE-2024-3478

MEDIUM CVSS 6.1 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-3481 - Counter Box Plugin

The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks

PLUGIN Counter Box

CVE-2024-3481

MEDIUM CVSS 5.2 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-3476 - Side Menu Lite Plugin

The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

PLUGIN Side Menu Lite

CVE-2024-3476

HIGH CVSS 8.8 2024-05-02
Threat Entry Updated 2025-03-25

CVE-2024-3474 - Wow Skype Buttons Plugin

The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

PLUGIN Wow Skype Buttons

CVE-2024-3474

HIGH CVSS 8.8 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-3475 - Sticky Buttons Plugin

The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

PLUGIN Sticky Buttons

CVE-2024-3475

HIGH CVSS 7.5 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-3472 - Modal Window Plugin

The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack

PLUGIN Modal Window

CVE-2024-3472

MEDIUM CVSS 5.9 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-3477 - Popup Box Plugin

The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks

PLUGIN Popup Box

CVE-2024-3477

MEDIUM CVSS 4.3 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-3471 - Button Generator Plugin

The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack

PLUGIN Button Generator

CVE-2024-3471

LOW CVSS 3.4 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-2405 - Float Menu Plugin

The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.

PLUGIN Float Menu

CVE-2024-2405

MEDIUM CVSS 4.5 2024-05-02
Threat Entry Updated 2025-01-15

CVE-2024-0334 - Jeg Elementor Kit Plugin

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attribute of a link in several Elementor widgets in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Jeg Elementor Kit

CVE-2024-0334

MEDIUM CVSS 6.4 2024-05-01
Threat Entry Updated 2025-05-08

CVE-2024-3591 - Geo Controller Plugin

The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

PLUGIN Geo Controller

CVE-2024-3591

MEDIUM CVSS 6.5 2024-05-01
Threat Entry Updated 2024-11-21

CVE-2024-2663 - Zd Youtube Flv Player Plugin

The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.6 via the $_GET['image'] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Zd Youtube Flv Player

CVE-2024-2663

HIGH CVSS 8.3 2024-04-30
Scroll to top