Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,189
Critical995
High3,341
Medium11,575
Reset
Showing 11701-11720 of 16189 records
Threat Entry Updated 2025-01-21

CVE-2023-6825 - File Manager Plugin

The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file…

PLUGIN File Manager

CVE-2023-6825

CRITICAL CVSS 9.9 2024-03-13
Threat Entry Updated 2025-02-28

CVE-2023-5663 - News Announcement Scroll Plugin

The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN News Announcement Scroll

CVE-2023-5663

HIGH CVSS 8.8 2024-03-13
Threat Entry Updated 2025-01-21

CVE-2023-6809 - Beepress Plugin

The Custom fields shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied custom post meta values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Beepress

CVE-2023-6809

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-03-21

CVE-2023-6785 - Download Manager Plugin

The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).

PLUGIN Download Manager

CVE-2023-6785

MEDIUM CVSS 5.3 2024-03-13
Threat Entry Updated 2025-01-21

CVE-2024-1508 - Prime Slider Plugin

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings['title_tags']' attribute of the Mercury widget in all versions up to, and including, 3.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Prime Slider

CVE-2024-1508

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-21

CVE-2024-1507 - Prime Slider Plugin

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Rubix widget in all versions up to, and including, 3.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Prime Slider

CVE-2024-1507

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-03-05

CVE-2024-2123 - Ultimate Member Plugin

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Member

CVE-2024-2123

HIGH CVSS 7.2 2024-03-13
Threat Entry Updated 2025-02-11

CVE-2024-1582 - Wp Go Maps Plugin

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Go Maps

CVE-2024-1582

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-02-11

CVE-2023-4839 - Wp Go Maps Plugin

The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Wp Go Maps

CVE-2023-4839

MEDIUM CVSS 4.4 2024-03-13
Threat Entry Updated 2025-01-22

CVE-2023-7072 - Post Grid Plugin

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' REST API Endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including full draft posts and password protected posts, as well as the password for password-protected posts.

PLUGIN Post Grid

CVE-2023-7072

HIGH CVSS 7.5 2024-03-12
Threat Entry Updated 2025-01-22

CVE-2024-1421 - Ht Mega Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel widget in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ht Mega

CVE-2024-1421

MEDIUM CVSS 6.4 2024-03-12
Threat Entry Updated 2025-01-22

CVE-2024-1397 - Ht Mega Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on the 'titleTag' user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ht Mega

CVE-2024-1397

MEDIUM CVSS 6.4 2024-03-12
Threat Entry Updated 2025-01-22

CVE-2024-2395 - Bulgarisation For Woocommerce Plugin

The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to generate and delete labels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Bulgarisation For Woocommerce

CVE-2024-2395

HIGH CVSS 7.3 2024-03-12
Threat Entry Updated 2025-01-15

CVE-2024-0386 - Weforms Plugin

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Weforms

CVE-2024-0386

HIGH CVSS 7.2 2024-03-12
Threat Entry Updated 2025-01-22

CVE-2024-2107 - Blossom Spa Plugin

The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.4 via generated source. This makes it possible for unauthenticated attackers to extract sensitive data including contents of password-protected or scheduled posts.

PLUGIN Blossom Spa

CVE-2024-2107

MEDIUM CVSS 5.8 2024-03-12
Threat Entry Updated 2025-04-03

CVE-2024-2130 - Cww Companion Plugin

The CWW Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Module2 widget in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cww Companion

CVE-2024-2130

MEDIUM CVSS 6.4 2024-03-12
Threat Entry Updated 2025-03-13

CVE-2024-2031 - Video Conferencing With Zoom Plugin

The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoom_recordings_by_meeting' shortcode in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Video Conferencing With Zoom

CVE-2024-2031

MEDIUM CVSS 6.4 2024-03-12
Threat Entry Updated 2025-01-15

CVE-2023-4731 - Ladipage Plugin

The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to modify a variety of settings, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. An attacker can directly modify the 'ladipage_key' which enables them to create new posts on the website and inject malicious web scripts,

PLUGIN Ladipage

CVE-2023-4731

MEDIUM CVSS 4.3 2024-03-12
Threat Entry Updated 2025-01-15

CVE-2023-4729 - Ladipage Plugin

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to change the LadiPage key (a key fully controlled by the attacker), enabling them to freely create new pages, including web pages that trigger stored XSS via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ladipage

CVE-2023-4729

MEDIUM CVSS 4.3 2024-03-12
Threat Entry Updated 2025-01-15

CVE-2023-4728 - Ladipage Plugin

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to change the LadiPage key (a key fully controlled by the attacker), enabling them to freely create new pages, including web pages that trigger stored XSS

PLUGIN Ladipage

CVE-2023-4728

MEDIUM CVSS 4.3 2024-03-12
Scroll to top