Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,189
Critical995
High3,341
Medium11,575
Reset
Showing 11561-11580 of 16189 records
Threat Entry Updated 2025-03-14

CVE-2024-0780 - Enjoy Social Feed Plugin

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing any authenticated users, such as subscriber to perform such action

PLUGIN Enjoy Social Feed

CVE-2024-0780

HIGH CVSS 8.8 2024-03-18
Threat Entry Updated 2025-05-05

CVE-2024-0779 - Enjoy Social Feed Plugin

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to admin_init, allowing unauthenticated users to call them and unlink arbitrary users Instagram Account for example

PLUGIN Enjoy Social Feed

CVE-2024-0779

HIGH CVSS 8.8 2024-03-18
Threat Entry Updated 2025-05-05

CVE-2024-0365 - Fancy Product Designer Plugin

The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.

PLUGIN Fancy Product Designer

CVE-2024-0365

MEDIUM CVSS 6.5 2024-03-18
Threat Entry Updated 2025-05-05

CVE-2024-0973 - Widget For Social Page Feeds Plugin

The Widget for Social Page Feeds WordPress plugin before 6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Widget For Social Page Feeds

CVE-2024-0973

MEDIUM CVSS 6.1 2024-03-18
Threat Entry Updated 2025-05-13

CVE-2024-0711 - Buttons Shortcode And Widget Plugin

The Buttons Shortcode and Widget WordPress plugin through 1.16 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Buttons Shortcode And Widget

CVE-2024-0711

MEDIUM CVSS 6.1 2024-03-18
Threat Entry Updated 2025-03-28

CVE-2024-0820 - Jobs For Plugin

The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Jobs For

CVE-2024-0820

MEDIUM CVSS 5.4 2024-03-18
Threat Entry Updated 2025-05-13

CVE-2024-0719 - Tabs Shortcode And Widget Plugin

The Tabs Shortcode and Widget WordPress plugin through 1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Tabs Shortcode And Widget

CVE-2024-0719

MEDIUM CVSS 5.4 2024-03-18
Threat Entry Updated 2025-05-05

CVE-2023-7085 - Through 3 Plugin

The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

PLUGIN Through 3

CVE-2023-7085

MEDIUM CVSS 5.4 2024-03-18
Threat Entry Updated 2025-03-27

CVE-2024-0951 - Advanced Social Feeds Widget Shortcode Plugin

The Advanced Social Feeds Widget & Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Advanced Social Feeds Widget Shortcode

CVE-2024-0951

MEDIUM CVSS 4.8 2024-03-18
Threat Entry Updated 2025-05-05

CVE-2023-7236 - Backup Bolt Plugin

The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors which could contain sensitive information.

PLUGIN Backup Bolt

CVE-2023-7236

MEDIUM CVSS 4.7 2024-03-18
Threat Entry Updated 2025-05-05

CVE-2024-1331 - Team Members Plugin

The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Team Members

CVE-2024-1331

MEDIUM CVSS 6.1 2024-03-18
Threat Entry Updated 2025-05-05

CVE-2024-1658 - Grid Shortcodes Plugin

The Grid Shortcodes WordPress plugin before 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Grid Shortcodes

CVE-2024-1658

MEDIUM CVSS 5.4 2024-03-18
Threat Entry Updated 2025-05-05

CVE-2024-1333 - Responsive Pricing Table Plugin

The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a page/post where the related shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Responsive Pricing Table

CVE-2024-1333

MEDIUM CVSS 5.4 2024-03-18
Threat Entry Updated 2024-11-21

CVE-2024-1857 - ultimate_gift_cards_for_woocommerce Plugin

The Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the wps_wgm_preview_email_template(). This makes it possible for unauthenticated attackers to read password protected and draft posts that may contain sensitive data.

PLUGIN ultimate_gift_cards_for_woocommerce

CVE-2024-1857

MEDIUM CVSS 5.3 2024-03-16
Threat Entry Updated 2025-04-18

CVE-2024-1733 - Word Replacer Pro Plugin

The Word Replacer Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the word_replacer_ultra() function in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to update arbitrary content on the affected WordPress site.

PLUGIN Word Replacer Pro

CVE-2024-1733

MEDIUM CVSS 5.3 2024-03-16
Threat Entry Updated 2025-04-18

CVE-2024-1685 - Social Media Share Buttons Plugin

The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserialization of untrusted input through the attachmentUrl parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Social Media Share Buttons

CVE-2024-1685

HIGH CVSS 8.8 2024-03-16
Threat Entry Updated 2025-01-17

CVE-2024-2042 - Elements Kit Elementor Addons Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elements Kit Elementor Addons

CVE-2024-2042

MEDIUM CVSS 6.4 2024-03-16
Threat Entry Updated 2025-01-17

CVE-2024-1239 - Elements Kit Elementor Addons Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blog post read more button in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elements Kit Elementor Addons

CVE-2024-1239

MEDIUM CVSS 6.4 2024-03-16
Threat Entry Updated 2025-01-08

CVE-2023-6525 - Elementskit Lite Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This primarily affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Elementskit Lite

CVE-2023-6525

MEDIUM CVSS 5.5 2024-03-16
Scroll to top