Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,189
Critical995
High3,341
Medium11,575
Reset
Showing 11421-11440 of 16189 records
Threat Entry Updated 2025-06-10

CVE-2024-1526 - Hubbub Lite Plugin

The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.

PLUGIN Hubbub Lite

CVE-2024-1526

MEDIUM CVSS 5.3 2024-04-01
Threat Entry Updated 2025-05-13

CVE-2024-2263 - Before 1 Plugin

Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2024-2263

MEDIUM CVSS 4.8 2024-04-01
Threat Entry Updated 2025-05-13

CVE-2024-2262 - Before 1 Plugin

Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs

PLUGIN Before 1

CVE-2024-2262

MEDIUM CVSS 4.7 2024-04-01
Threat Entry Updated 2024-11-21

CVE-2024-31103 - Kanban Boards for WordPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kanban for WordPress Kanban Boards for WordPress allows Reflected XSS.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21.

PLUGIN Kanban Boards for WordPress

CVE-2024-31103

HIGH CVSS 7.1 2024-03-31
Threat Entry Updated 2024-11-21

CVE-2024-31104 - GetResponse for WordPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GetResponse GetResponse for WordPress allows Stored XSS.This issue affects GetResponse for WordPress: from n/a through 5.5.33.

PLUGIN GetResponse for WordPress

CVE-2024-31104

MEDIUM CVSS 6.5 2024-03-31
Threat Entry Updated 2025-04-09

CVE-2024-31108 - Iflychat Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iFlyChat Team iFlyChat – WordPress Chat iflychat allows Stored XSS.This issue affects iFlyChat – WordPress Chat: from n/a through 4.7.2.

PLUGIN Iflychat

CVE-2024-31108

MEDIUM CVSS 6.5 2024-03-31
Threat Entry Updated 2025-01-08

CVE-2024-3018 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Register Form" widget (disabled by default). This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Essential Addons For Elementor

CVE-2024-3018

HIGH CVSS 8.8 2024-03-30
Threat Entry Updated 2025-01-15

CVE-2024-2491 - Powerpack Addons For Elementor Plugin

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the *_html_tag* attribute of multiple widgets in all versions up to, and including, 2.7.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Powerpack Addons For Elementor

CVE-2024-2491

MEDIUM CVSS 6.4 2024-03-30
Threat Entry Updated 2024-11-21

CVE-2024-2948 - Favorites Plugin

The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user_favorites' shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping on user supplied attributes such as 'no_favorites'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Favorites

CVE-2024-2948

HIGH CVSS 7.2 2024-03-30
Threat Entry Updated 2025-01-30

CVE-2024-2144 - Ultimate Addons For Beaver Builder Plugin

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Separator widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Addons For Beaver Builder

CVE-2024-2144

MEDIUM CVSS 6.4 2024-03-30
Threat Entry Updated 2025-01-30

CVE-2024-2143 - Ultimate Addons For Beaver Builder Plugin

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Addons For Beaver Builder

CVE-2024-2143

MEDIUM CVSS 6.4 2024-03-30
Threat Entry Updated 2025-01-30

CVE-2024-2142 - Ultimate Addons For Beaver Builder Plugin

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Info Table widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Addons For Beaver Builder

CVE-2024-2142

MEDIUM CVSS 6.4 2024-03-30
Threat Entry Updated 2025-01-30

CVE-2024-2141 - Ultimate Addons For Beaver Builder Plugin

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Addons For Beaver Builder

CVE-2024-2141

MEDIUM CVSS 6.4 2024-03-30
Threat Entry Updated 2025-01-30

CVE-2024-2140 - Ultimate Addons For Beaver Builder Plugin

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Icons widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Addons For Beaver Builder

CVE-2024-2140

MEDIUM CVSS 6.4 2024-03-30
Threat Entry Updated 2024-11-21

CVE-2024-2086 - Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files into Your WordPress Site Plugin

The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers to modify plugin settings as well as allowing full read/write/delete access to the Google Drive associated with the plugin.

PLUGIN Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files into Your WordPress Site

CVE-2024-2086

CRITICAL CVSS 10.0 2024-03-30
Threat Entry Updated 2025-01-16

CVE-2024-2047 - Elements Kit Elementor Addons Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the render_raw function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Elements Kit Elementor Addons

CVE-2024-2047

HIGH CVSS 8.8 2024-03-30
Threat Entry Updated 2024-11-21

CVE-2024-2794 - Gutenberg Block Editor Toolkit – EditorsKit Plugin

The Gutenberg Block Editor Toolkit – EditorsKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'editorskit' shortcode in all versions up to, and including, 1.40.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Block Editor Toolkit – EditorsKit

CVE-2024-2794

MEDIUM CVSS 6.4 2024-03-30
Threat Entry Updated 2024-11-21

CVE-2024-1692 - BoldGrid Easy SEO – Simple and Effective SEO Plugin

The BoldGrid Easy SEO – Simple and Effective SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the meta description field in all versions up to, and including, 1.6.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN BoldGrid Easy SEO – Simple and Effective SEO

CVE-2024-1692

MEDIUM CVSS 6.4 2024-03-30
Threat Entry Updated 2025-01-16

CVE-2024-1238 - Elements Kit Elementor Addons Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button ID parameter in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elements Kit Elementor Addons

CVE-2024-1238

MEDIUM CVSS 6.4 2024-03-30
Scroll to top