Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,139
Critical992
High3,318
Medium11,534
Reset
Showing 11361-11380 of 16139 records
Threat Entry Updated 2024-11-21

CVE-2024-1732 - Sharkdropship Dropshipping & Affiliate for for AliExpress Plugin

The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wads_removeProductFromShop() function in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to delete arbitrary posts.

PLUGIN Sharkdropship Dropshipping & Affiliate for for AliExpress

CVE-2024-1732

MEDIUM CVSS 5.3 2024-04-02
Threat Entry Updated 2025-08-27

CVE-2024-2931 - Wpfront User Role Editor Plugin

The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfront_user_role_editor_assign_roles_user_autocomplete AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract retrieve a list of all user email addresses who are registered on the site.

PLUGIN Wpfront User Role Editor

CVE-2024-2931

MEDIUM CVSS 4.3 2024-04-02
Threat Entry Updated 2025-01-08

CVE-2024-2925 - Beaver Builder Plugin

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 2.8.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Beaver Builder

CVE-2024-2925

MEDIUM CVSS 6.4 2024-04-02
Threat Entry Updated 2025-01-28

CVE-2024-2839 - Colibri Page Builder Plugin

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_post_title' shortcode in all versions up to, and including, 1.0.263 due to insufficient input sanitization and output escaping on user supplied attributes such as 'heading_type'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Colibri Page Builder

CVE-2024-2839

MEDIUM CVSS 6.4 2024-04-02
Threat Entry Updated 2024-11-21

CVE-2024-2924 - Creative Addons For Elementor Plugin

The Creative Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.5.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Creative Addons For Elementor

CVE-2024-2924

MEDIUM CVSS 6.4 2024-04-02
Threat Entry Updated 2025-02-27

CVE-2024-2791 - Metform Elementor Contact Form Builder Plugin

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 3.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Metform Elementor Contact Form Builder

CVE-2024-2791

MEDIUM CVSS 6.4 2024-04-02
Threat Entry Updated 2025-05-07

CVE-2024-1274 - My Calendar Plugin

The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)

PLUGIN My Calendar

CVE-2024-1274

MEDIUM CVSS 5.4 2024-04-02
Threat Entry Updated 2025-08-15

CVE-2024-1504 - Secupress Plugin

The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5.1. This is due to missing or incorrect nonce validation on the secupress_blackhole_ban_ip() function. This makes it possible for unauthenticated attackers to block a user's IP via a forged request granted they can trick the user into performing an action such as clicking on a link.

PLUGIN Secupress

CVE-2024-1504

MEDIUM CVSS 4.3 2024-04-02
Threat Entry Updated 2025-05-13

CVE-2024-2369 - Page Builder Gutenberg Blocks Plugin

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Page Builder Gutenberg Blocks

CVE-2024-2369

MEDIUM CVSS 5.4 2024-04-02
Threat Entry Updated 2025-05-07

CVE-2024-2278 - Before 1 Plugin

Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2024-2278

MEDIUM CVSS 6.1 2024-04-01
Threat Entry Updated 2025-06-10

CVE-2024-1526 - Hubbub Lite Plugin

The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.

PLUGIN Hubbub Lite

CVE-2024-1526

MEDIUM CVSS 5.3 2024-04-01
Threat Entry Updated 2025-05-13

CVE-2024-2263 - Before 1 Plugin

Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2024-2263

MEDIUM CVSS 4.8 2024-04-01
Threat Entry Updated 2025-05-13

CVE-2024-2262 - Before 1 Plugin

Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs

PLUGIN Before 1

CVE-2024-2262

MEDIUM CVSS 4.7 2024-04-01
Threat Entry Updated 2024-11-21

CVE-2024-31103 - Kanban Boards for WordPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kanban for WordPress Kanban Boards for WordPress allows Reflected XSS.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21.

PLUGIN Kanban Boards for WordPress

CVE-2024-31103

HIGH CVSS 7.1 2024-03-31
Threat Entry Updated 2024-11-21

CVE-2024-31104 - GetResponse for WordPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GetResponse GetResponse for WordPress allows Stored XSS.This issue affects GetResponse for WordPress: from n/a through 5.5.33.

PLUGIN GetResponse for WordPress

CVE-2024-31104

MEDIUM CVSS 6.5 2024-03-31
Threat Entry Updated 2025-04-09

CVE-2024-31108 - Iflychat Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iFlyChat Team iFlyChat – WordPress Chat iflychat allows Stored XSS.This issue affects iFlyChat – WordPress Chat: from n/a through 4.7.2.

PLUGIN Iflychat

CVE-2024-31108

MEDIUM CVSS 6.5 2024-03-31
Threat Entry Updated 2025-01-08

CVE-2024-3018 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Register Form" widget (disabled by default). This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Essential Addons For Elementor

CVE-2024-3018

HIGH CVSS 8.8 2024-03-30
Threat Entry Updated 2025-01-15

CVE-2024-2491 - Powerpack Addons For Elementor Plugin

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the *_html_tag* attribute of multiple widgets in all versions up to, and including, 2.7.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Powerpack Addons For Elementor

CVE-2024-2491

MEDIUM CVSS 6.4 2024-03-30
Threat Entry Updated 2024-11-21

CVE-2024-2948 - Favorites Plugin

The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user_favorites' shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping on user supplied attributes such as 'no_favorites'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Favorites

CVE-2024-2948

HIGH CVSS 7.2 2024-03-30
Scroll to top