Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,189
Critical995
High3,341
Medium11,575
Reset
Showing 11381-11400 of 16189 records
Threat Entry Updated 2025-01-17

CVE-2024-1428 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘element_pack_wrapper_link’ attribute of the Trailer Box widget in all versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-1428

MEDIUM CVSS 6.4 2024-04-06
Threat Entry Updated 2025-01-17

CVE-2024-0837 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-0837

MEDIUM CVSS 6.4 2024-04-06
Threat Entry Updated 2025-02-27

CVE-2024-2949 - Wp Carousel Plugin

The Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel widget in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Carousel

CVE-2024-2949

MEDIUM CVSS 6.4 2024-04-06
Threat Entry Updated 2025-02-24

CVE-2024-2471 - Foogallery Plugin

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and 'Override Type') in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Foogallery

CVE-2024-2471

MEDIUM CVSS 6.4 2024-04-06
Threat Entry Updated 2025-05-08

CVE-2024-2444 - Inline Related Posts Plugin

The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Inline Related Posts

CVE-2024-2444

MEDIUM CVSS 4.8 2024-04-06
Threat Entry Updated 2025-02-11

CVE-2024-3216 - Woocommerce Pdf Invoices Packing Slips Delivery Notes And Shipping Labels Plugin

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wt_pklist_reset_settings() function in all versions up to, and including, 4.4.2. This makes it possible for unauthenticated attackers to reset all of the plugin's settings.

PLUGIN Woocommerce Pdf Invoices Packing Slips Delivery Notes And Shipping Labels

CVE-2024-3216

MEDIUM CVSS 5.3 2024-04-06
Threat Entry Updated 2025-02-27

CVE-2024-2950 - Easy Seo Plugin

The BoldGrid Easy SEO – Simple and Effective SEO plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.14 via meta information (og:description) This makes it possible for unauthenticated attackers to view the first 130 characters of a password protected post which can contain sensitive information.

PLUGIN Easy Seo

CVE-2024-2950

MEDIUM CVSS 5.3 2024-04-06
Threat Entry Updated 2024-11-21

CVE-2024-2656 - Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce

CVE-2024-2656

MEDIUM CVSS 4.4 2024-04-06
Threat Entry Updated 2025-05-06

CVE-2024-1385 - Wp Stateless Plugin

The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the dismiss_notices() function in all versions up to, and including, 3.4.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary option values to the current time, which may completely take a site offline.

PLUGIN Wp Stateless

CVE-2024-1385

HIGH CVSS 7.1 2024-04-06
Threat Entry Updated 2025-01-07

CVE-2024-3245 - Embedpress Plugin

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Youtube block in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Embedpress

CVE-2024-3245

MEDIUM CVSS 6.4 2024-04-06
Threat Entry Updated 2024-11-21

CVE-2024-1994 - Image Watermark Plugin

The Image Watermark plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the watermark_action_ajax() function in all versions up to, and including, 1.7.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to apply and remove watermarks from images.

PLUGIN Image Watermark

CVE-2024-1994

MEDIUM CVSS 4.3 2024-04-06
Threat Entry Updated 2024-11-21

CVE-2024-2499 - Squelch Tabs And Accordions Shortcodes Plugin

The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordions' shortcode in all versions up to, and including, 0.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Squelch Tabs And Accordions Shortcodes

CVE-2024-2499

MEDIUM CVSS 6.4 2024-04-05
Threat Entry Updated 2025-02-27

CVE-2024-3217 - Wp Directory Kit Plugin

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Directory Kit

CVE-2024-3217

HIGH CVSS 8.8 2024-04-05
Threat Entry Updated 2025-01-08

CVE-2024-2115 - Learnpress Plugin

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. This is due to missing or incorrect nonce validation on the filter_users functions. This makes it possible for unauthenticated attackers to elevate their privileges to that of a teacher via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Learnpress

CVE-2024-2115

HIGH CVSS 8.8 2024-04-05
Threat Entry Updated 2025-05-13

CVE-2024-2509 - Gutenberg Blocks By Kadence Blocks Plugin

The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Gutenberg Blocks By Kadence Blocks

CVE-2024-2509

MEDIUM CVSS 6.5 2024-04-05
Threat Entry Updated 2024-11-21

CVE-2024-1418 - Cgc Maintenance Mode Plugin

The CGC Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2 via the REST API. This makes it possible for unauthenticated attackers to view protected posts via REST API even when maintenance mode is enabled.

PLUGIN Cgc Maintenance Mode

CVE-2024-1418

MEDIUM CVSS 5.3 2024-04-04
Threat Entry Updated 2024-11-21

CVE-2024-2008 - Modal Popup Box Plugin

The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.2 via deserialization of untrusted input in the awl_modal_popup_box_shortcode function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Modal Popup Box

CVE-2024-2008

HIGH CVSS 8.8 2024-04-04
Threat Entry Updated 2025-02-07

CVE-2024-2919 - Gutenberg Blocks With Ai Plugin

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CountUp Widget in all versions up to, and including, 3.2.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Blocks With Ai

CVE-2024-2919

MEDIUM CVSS 6.4 2024-04-04
Threat Entry Updated 2024-11-21

CVE-2024-2830 - WordPress Tag and Category Manager – AI Autotagger Plugin

The WordPress Tag and Category Manager – AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'st_tag_cloud' shortcode in all versions up to, and including, 3.13.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN WordPress Tag and Category Manager – AI Autotagger

CVE-2024-2830

MEDIUM CVSS 6.4 2024-04-04
Threat Entry Updated 2025-03-13

CVE-2024-3022 - Bookingpress Plugin

The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in the 'bookingpress_process_upload' function in all versions up to, and including 1.0.87. This allows an authenticated attacker with administrator-level capabilities or higher to upload arbitrary files on the affected site's server, enabling remote code execution.

PLUGIN Bookingpress

CVE-2024-3022

HIGH CVSS 7.2 2024-04-04
Scroll to top