Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,139
Critical992
High3,318
Medium11,534
Reset
Showing 11341-11360 of 16139 records
Threat Entry Updated 2024-11-21

CVE-2024-1994 - Image Watermark Plugin

The Image Watermark plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the watermark_action_ajax() function in all versions up to, and including, 1.7.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to apply and remove watermarks from images.

PLUGIN Image Watermark

CVE-2024-1994

MEDIUM CVSS 4.3 2024-04-06
Threat Entry Updated 2024-11-21

CVE-2024-2499 - Squelch Tabs And Accordions Shortcodes Plugin

The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordions' shortcode in all versions up to, and including, 0.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Squelch Tabs And Accordions Shortcodes

CVE-2024-2499

MEDIUM CVSS 6.4 2024-04-05
Threat Entry Updated 2025-02-27

CVE-2024-3217 - Wp Directory Kit Plugin

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Directory Kit

CVE-2024-3217

HIGH CVSS 8.8 2024-04-05
Threat Entry Updated 2025-01-08

CVE-2024-2115 - Learnpress Plugin

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. This is due to missing or incorrect nonce validation on the filter_users functions. This makes it possible for unauthenticated attackers to elevate their privileges to that of a teacher via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Learnpress

CVE-2024-2115

HIGH CVSS 8.8 2024-04-05
Threat Entry Updated 2025-05-13

CVE-2024-2509 - Gutenberg Blocks By Kadence Blocks Plugin

The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Gutenberg Blocks By Kadence Blocks

CVE-2024-2509

MEDIUM CVSS 6.5 2024-04-05
Threat Entry Updated 2024-11-21

CVE-2024-1418 - Cgc Maintenance Mode Plugin

The CGC Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2 via the REST API. This makes it possible for unauthenticated attackers to view protected posts via REST API even when maintenance mode is enabled.

PLUGIN Cgc Maintenance Mode

CVE-2024-1418

MEDIUM CVSS 5.3 2024-04-04
Threat Entry Updated 2024-11-21

CVE-2024-2008 - Modal Popup Box Plugin

The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.2 via deserialization of untrusted input in the awl_modal_popup_box_shortcode function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Modal Popup Box

CVE-2024-2008

HIGH CVSS 8.8 2024-04-04
Threat Entry Updated 2025-02-07

CVE-2024-2919 - Gutenberg Blocks With Ai Plugin

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CountUp Widget in all versions up to, and including, 3.2.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Blocks With Ai

CVE-2024-2919

MEDIUM CVSS 6.4 2024-04-04
Threat Entry Updated 2024-11-21

CVE-2024-2830 - WordPress Tag and Category Manager – AI Autotagger Plugin

The WordPress Tag and Category Manager – AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'st_tag_cloud' shortcode in all versions up to, and including, 3.13.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN WordPress Tag and Category Manager – AI Autotagger

CVE-2024-2830

MEDIUM CVSS 6.4 2024-04-04
Threat Entry Updated 2025-03-13

CVE-2024-3022 - Bookingpress Plugin

The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in the 'bookingpress_process_upload' function in all versions up to, and including 1.0.87. This allows an authenticated attacker with administrator-level capabilities or higher to upload arbitrary files on the affected site's server, enabling remote code execution.

PLUGIN Bookingpress

CVE-2024-3022

HIGH CVSS 7.2 2024-04-04
Threat Entry Updated 2025-10-02

CVE-2024-2868 - Shoplentor Plugin

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slitems parameter in the WL Special Day Offer Widget in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shoplentor

CVE-2024-2868

MEDIUM CVSS 6.4 2024-04-04
Threat Entry Updated 2024-11-21

CVE-2024-3030 - Announce From The Dashboard Plugin

The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Announce From The Dashboard

CVE-2024-3030

MEDIUM CVSS 4.4 2024-04-04
Threat Entry Updated 2025-01-16

CVE-2024-2803 - Elements Kit Elementor Addons Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elements Kit Elementor Addons

CVE-2024-2803

MEDIUM CVSS 6.4 2024-04-04
Threat Entry Updated 2025-04-07

CVE-2024-2322 - Woocommerce Cart Abandonment Recovery Plugin

The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admins delete arbitrary email templates as well as delete and unsubscribe users from abandoned orders via CSRF attacks.

PLUGIN Woocommerce Cart Abandonment Recovery

CVE-2024-2322

MEDIUM CVSS 6.8 2024-04-03
Threat Entry Updated 2025-03-17

CVE-2024-2879 - Layerslider Plugin

The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Layerslider

CVE-2024-2879

CRITICAL CVSS 9.8 2024-04-03
Threat Entry Updated 2025-01-15

CVE-2024-3162 - Jeg Elementor Kit Plugin

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget Attributes in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32721 is likely a duplicate of this issue.

PLUGIN Jeg Elementor Kit

CVE-2024-3162

MEDIUM CVSS 6.4 2024-04-03
Threat Entry Updated 2025-01-15

CVE-2024-1327 - Jeg Elementor Kit Plugin

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image box widget in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Jeg Elementor Kit

CVE-2024-1327

MEDIUM CVSS 6.4 2024-04-03
Threat Entry Updated 2024-11-21

CVE-2024-1807 - Product Sort And Display For Woocommerce Plugin

The Product Sort and Display for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the psad_update_product_cat_custom_meta_ajax function in all versions up to, and including, 2.4.1. This makes it possible for unauthenticated attackers to hide product categories.

PLUGIN Product Sort And Display For Woocommerce

CVE-2024-1807

MEDIUM CVSS 6.5 2024-04-02
Threat Entry Updated 2024-11-21

CVE-2024-1946 - Genesis Blocks Plugin

The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Genesis Blocks

CVE-2024-1946

MEDIUM CVSS 6.4 2024-04-02
Scroll to top