Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,189
Critical995
High3,341
Medium11,575
Reset
Showing 11581-11600 of 16189 records
Threat Entry Updated 2025-03-06

CVE-2024-2308 - Elementinvader Addons For Elementor Plugin

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link in the EliSlider in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elementinvader Addons For Elementor

CVE-2024-2308

MEDIUM CVSS 6.4 2024-03-16
Threat Entry Updated 2024-11-21

CVE-2024-2294 - Backuply – Backup, Restore, Migrate and Clone Plugin

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.7 via the backup_name parameter in the backuply_download_backup function. This makes it possible for attackers to have an account with only activate_plugins capability to access arbitrary files on the server, which can contain sensitive information. This only impacts sites hosted on Windows servers.

PLUGIN Backuply – Backup, Restore, Migrate and Clone

CVE-2024-2294

MEDIUM CVSS 4.9 2024-03-16
Threat Entry Updated 2025-01-23

CVE-2024-2399 - Premium Addons For Elementor Plugin

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.10.23 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Premium Addons For Elementor

CVE-2024-2399

MEDIUM CVSS 6.4 2024-03-15
Threat Entry Updated 2025-07-07

CVE-2024-1796 - Husky Products Filter Professional For Woocommerce Plugin

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'woof' shortcode in all versions up to, and including, 1.3.5.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'swoof_slug'. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Husky Products Filter Professional For Woocommerce

CVE-2024-1796

MEDIUM CVSS 6.4 2024-03-15
Threat Entry Updated 2025-01-23

CVE-2024-1795 - Husky Products Filter Professional For Woocommerce Plugin

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the 'name' parameter in the woof shortcode in all versions up to, and including, 1.3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Husky Products Filter Professional For Woocommerce

CVE-2024-1795

HIGH CVSS 8.8 2024-03-15
Threat Entry Updated 2025-07-07

CVE-2024-2249 - La Studio Element Kit For Elementor Plugin

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWrapper attribute found in several widgets in all versions up to, and including, 1.3.7.4 due to insufficient input sanitization and output escaping the user supplied attribute. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN La Studio Element Kit For Elementor

CVE-2024-2249

MEDIUM CVSS 6.4 2024-03-14
Threat Entry Updated 2025-01-23

CVE-2024-2256 - Oik Plugin

The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes such as bw_contact_button and bw_button shortcodes in all versions up to, and including, 4.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Oik

CVE-2024-2256

MEDIUM CVSS 6.4 2024-03-14
Threat Entry Updated 2025-01-17

CVE-2024-2242 - Contact Form 7 Plugin

The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Contact Form 7

CVE-2024-2242

MEDIUM CVSS 6.1 2024-03-13
Threat Entry Updated 2025-07-07

CVE-2024-2079 - Wpbakery Page Builder Addons Plugin

The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'per_line_mobile' shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wpbakery Page Builder Addons

CVE-2024-2079

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2024-11-21

CVE-2024-2293 - Site Reviews Plugin

The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Site Reviews

CVE-2024-2293

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-02-05

CVE-2024-2286 - Sky Addons For Elementor Plugin

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link URL value in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sky Addons For Elementor

CVE-2024-2286

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2024-11-21

CVE-2024-2172 - Malware Scanner Plugin

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This makes it possible for unauthenticated attackers to escalate their privileges to that of an administrator.

PLUGIN Malware Scanner

CVE-2024-2172

CRITICAL CVSS 9.8 2024-03-13
Threat Entry Updated 2024-11-21

CVE-2024-2194 - Wp Statistics Plugin

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Statistics

CVE-2024-2194

HIGH CVSS 7.2 2024-03-13
Threat Entry Updated 2025-01-23

CVE-2024-2239 - Premium Addons Plugin

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Premium Magic Scroll module in all versions up to, and including, 2.9.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Premium Addons

CVE-2024-2239

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-23

CVE-2024-2238 - Premium Addons Plugin

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Mouse Cursor module in all versions up to, and including, 2.9.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Premium Addons

CVE-2024-2238

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-23

CVE-2024-2237 - Premium Addons Plugin

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Global Badge module in all versions up to, and including, 2.9.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Premium Addons

CVE-2024-2237

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2024-11-21

CVE-2024-2252 - Droit Elementor Addons Plugin

The Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping on user supplied attributes such as URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Droit Elementor Addons

CVE-2024-2252

MEDIUM CVSS 5.4 2024-03-13
Threat Entry Updated 2025-05-23

CVE-2024-2020 - Calculated Fields Form Plugin

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href parameter in all versions up to, and including, 5.1.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the professional version or higher.

PLUGIN Calculated Fields Form

CVE-2024-2020

HIGH CVSS 7.2 2024-03-13
Threat Entry Updated 2025-01-22

CVE-2024-2126 - Orbit Fox Plugin

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Registration Form widget in all versions up to, and including, 2.10.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Orbit Fox

CVE-2024-2126

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2024-11-21

CVE-2024-2030 - Database for Contact Form 7, WPforms, Elementor forms Plugin

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Database for Contact Form 7, WPforms, Elementor forms

CVE-2024-2030

MEDIUM CVSS 6.4 2024-03-13
Scroll to top