Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,189
Critical995
High3,341
Medium11,575
Reset
Showing 11741-11760 of 16189 records
Threat Entry Updated 2025-01-15

CVE-2024-1125 - Eventprime Plugin

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the calendar_events_delete() function in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts.

PLUGIN Eventprime

CVE-2024-1125

MEDIUM CVSS 6.5 2024-03-09
Threat Entry Updated 2025-01-15

CVE-2024-1124 - Eventprime Plugin

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ep_send_attendees_email() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary emails with arbitrary content from the site.

PLUGIN Eventprime

CVE-2024-1124

MEDIUM CVSS 4.3 2024-03-09
Threat Entry Updated 2025-01-15

CVE-2024-1123 - Eventprime Plugin

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_frontend_event_submission() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the title and content of arbitrary posts. This can also be exploited by unauthenticated attackers when the allow_submission_by_anonymous_user setting is enabled.

PLUGIN Eventprime

CVE-2024-1123

MEDIUM CVSS 6.5 2024-03-09
Threat Entry Updated 2025-01-15

CVE-2024-2298 - Affiliate Toolkit Plugin

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to to perform unauthorized actions such as creating importing products.

PLUGIN Affiliate Toolkit

CVE-2024-2298

MEDIUM CVSS 4.3 2024-03-08
Threat Entry Updated 2025-01-15

CVE-2024-1851 - Affiliate Toolkit Plugin

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_create_list() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to to perform unauthorized actions such as creating product lists.

PLUGIN Affiliate Toolkit

CVE-2024-1851

MEDIUM CVSS 6.3 2024-03-08
Threat Entry Updated 2025-03-12

CVE-2024-1987 - Wp Members Plugin

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Members

CVE-2024-1987

MEDIUM CVSS 6.4 2024-03-08
Threat Entry Updated 2025-03-11

CVE-2024-1986 - Booster For Woocommerce Plugin

The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wc_add_new_product() function in all versions up to, and including, 7.1.7. This makes it possible for customer-level attackers, and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This is only exploitable when the user product upload functionality is enabled.

PLUGIN Booster For Woocommerce

CVE-2024-1986

HIGH CVSS 8.8 2024-03-07
Threat Entry Updated 2025-01-07

CVE-2024-1802 - Embedpress Plugin

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Wistia embed block in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the user supplied url. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Embedpress

CVE-2024-1802

MEDIUM CVSS 6.4 2024-03-07
Threat Entry Updated 2025-01-07

CVE-2024-2128 - Embedpress Plugin

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed widget in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Embedpress

CVE-2024-2128

MEDIUM CVSS 6.4 2024-03-07
Threat Entry Updated 2025-01-21

CVE-2024-0203 - Digits Plugin

The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_settings' function. This makes it possible for unauthenticated attackers to modify the default role of registered users to elevate user privileges via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Digits

CVE-2024-0203

HIGH CVSS 8.8 2024-03-07
Threat Entry Updated 2025-02-14

CVE-2024-2127 - Pagelayer Plugin

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Pagelayer

CVE-2024-2127

MEDIUM CVSS 6.4 2024-03-07
Threat Entry Updated 2025-02-07

CVE-2024-1773 - Pdf Invoices And Packing Slips For Woocommerce Plugin

The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7 via deserialization of untrusted input via the order_id parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data,…

PLUGIN Pdf Invoices And Packing Slips For Woocommerce

CVE-2024-1773

HIGH CVSS 8.8 2024-03-07
Threat Entry Updated 2025-01-21

CVE-2024-1170 - Post Form Plugin

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capability check on the handle_deleted_media function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to delete arbitrary media files.

PLUGIN Post Form

CVE-2024-1170

HIGH CVSS 8.2 2024-03-07
Threat Entry Updated 2025-01-21

CVE-2024-1169 - Post Form Plugin

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media upload due to a missing capability check on the buddyforms_upload_handle_dropped_media function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to upload media files.

PLUGIN Post Form

CVE-2024-1169

HIGH CVSS 7.5 2024-03-07
Threat Entry Updated 2025-01-21

CVE-2024-1534 - Booster For Woocommerce Plugin

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Booster For Woocommerce

CVE-2024-1534

MEDIUM CVSS 6.4 2024-03-07
Threat Entry Updated 2025-01-21

CVE-2024-1382 - Restaurant Reservations Plugin

The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layout attribute of the nd_rst_search shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where an uploaded PHP file may not be directly accessible.

PLUGIN Restaurant Reservations

CVE-2024-1382

HIGH CVSS 8.8 2024-03-07
Threat Entry Updated 2025-01-21

CVE-2024-2136 - Wpkoi Templates For Elementor Plugin

The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget in all versions up to, and including, 2.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wpkoi Templates For Elementor

CVE-2024-2136

MEDIUM CVSS 6.4 2024-03-07
Threat Entry Updated 2025-01-21

CVE-2024-1506 - Prime Slider Plugin

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Fiestar widget in all versions up to, and including, 3.13.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Prime Slider

CVE-2024-1506

MEDIUM CVSS 6.4 2024-03-07
Threat Entry Updated 2025-02-05

CVE-2024-1419 - The Plus Addons For Elementor Plugin

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attribute of the Header Meta Content widget in all versions up to, and including, 5.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN The Plus Addons For Elementor

CVE-2024-1419

MEDIUM CVSS 6.4 2024-03-07
Threat Entry Updated 2025-01-07

CVE-2024-1377 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Happy Addons For Elementor

CVE-2024-1377

MEDIUM CVSS 6.4 2024-03-07
Scroll to top