Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,189
Critical995
High3,341
Medium11,575
Reset
Showing 11761-11780 of 16189 records
Threat Entry Updated 2025-01-07

CVE-2024-1366 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Happy Addons For Elementor

CVE-2024-1366

MEDIUM CVSS 6.4 2024-03-07
Threat Entry Updated 2025-01-08

CVE-2024-1500 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and including, 1.3.91 due to insufficient input sanitization and output escaping on user supplied URLs. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Royal Elementor Addons

CVE-2024-1500

MEDIUM CVSS 5.4 2024-03-07
Threat Entry Updated 2025-04-23

CVE-2024-1720 - User Registration Membership Plugin

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user…

PLUGIN User Registration Membership

CVE-2024-1720

MEDIUM CVSS 4.7 2024-03-07
Threat Entry Updated 2025-01-21

CVE-2024-1761 - Wp Chat App Plugin

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'buttonColor' and 'phoneNumber'. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Chat App

CVE-2024-1761

MEDIUM CVSS 6.4 2024-03-07
Threat Entry Updated 2025-03-11

CVE-2024-1989 - Sassy Social Share Plugin

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share' shortcode in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escaping on user supplied attributes such as 'url'. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sassy Social Share

CVE-2024-1989

MEDIUM CVSS 6.4 2024-03-06
Threat Entry Updated 2025-03-11

CVE-2024-1771 - Total Plugin

The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the total_order_sections() function in all versions up to, and including, 2.1.59. This makes it possible for authenticated attackers, with subscriber-level access and above, to repeat sections on the homepage.

PLUGIN Total

CVE-2024-1771

MEDIUM CVSS 5.3 2024-03-06
Threat Entry Updated 2025-02-04

CVE-2024-1760 - Simply Schedule Appointments Plugin

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.6.20. This is due to missing or incorrect nonce validation on the ssa_factory_reset() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Simply Schedule Appointments

CVE-2024-1760

MEDIUM CVSS 4.3 2024-03-06
Threat Entry Updated 2025-01-08

CVE-2024-1782 - Blue Triad Ezanalytics Plugin

The Blue Triad EZAnalytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'bt_webid' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Blue Triad Ezanalytics

CVE-2024-1782

MEDIUM CVSS 6.1 2024-03-05
Threat Entry Updated 2024-12-23

CVE-2024-1769 - Jm Twitter Cards Plugin

The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 12 via the meta description data. This makes it possible for unauthenticated attackers to view password protected post content when viewing the page source.

PLUGIN Jm Twitter Cards

CVE-2024-1769

MEDIUM CVSS 5.3 2024-03-05
Threat Entry Updated 2025-01-08

CVE-2024-1731 - Auto Refresh Single Page Plugin

The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization of untrusted input from the arsp_options post meta option. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or…

PLUGIN Auto Refresh Single Page

CVE-2024-1731

HIGH CVSS 8.8 2024-03-05
Threat Entry Updated 2025-04-01

CVE-2024-1381 - Page Builder Sandwich Plugin

The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber access and higher, to extract sensitive user or configuration data.

PLUGIN Page Builder Sandwich

CVE-2024-1381

MEDIUM CVSS 6.5 2024-03-05
Threat Entry Updated 2025-01-08

CVE-2024-1285 - Page Builder Sandwich Plugin

The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'gambit_builder_save_content' function in all versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber access and above, to insert arbitrary content into existing posts.

PLUGIN Page Builder Sandwich

CVE-2024-1285

MEDIUM CVSS 6.5 2024-03-05
Threat Entry Updated 2025-01-08

CVE-2024-1478 - Maintenance Mode Plugin

The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.0 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content via API thus bypassing the content protection provided by the plugin.

PLUGIN Maintenance Mode

CVE-2024-1478

MEDIUM CVSS 5.3 2024-03-05
Threat Entry Updated 2025-01-08

CVE-2024-1178 - Sportspress Plugin

The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings_save() function in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to update the permalink structure for the clubs

PLUGIN Sportspress

CVE-2024-1178

MEDIUM CVSS 5.3 2024-03-05
Threat Entry Updated 2025-01-08

CVE-2024-1095 - Build Control Block Pattern Plugin

The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the settings_export() function in all versions up to, and including, 1.3.5.4. This makes it possible for unauthenticated attackers to export the plugin's settings.

PLUGIN Build Control Block Pattern

CVE-2024-1095

MEDIUM CVSS 5.3 2024-03-05
Threat Entry Updated 2025-03-11

CVE-2024-0825 - Vimeography Plugin

The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.2 via deserialization of untrusted input via the vimeography_duplicate_gallery_serialized in the duplicate_gallery function. This makes it possible for authenticated attackers attackers, with contributor access or higher, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve…

PLUGIN Vimeography

CVE-2024-0825

HIGH CVSS 8.8 2024-03-05
Threat Entry Updated 2025-03-24

CVE-2024-0698 - Easy Appointments Plugin

The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Appointments

CVE-2024-0698

MEDIUM CVSS 6.4 2024-03-05
Threat Entry Updated 2024-12-23

CVE-2024-1093 - Change Memory Limit Plugin

The Change Memory Limit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_logic() function hooked via admin_init in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to update the memory limit.

PLUGIN Change Memory Limit

CVE-2024-1093

MEDIUM CVSS 5.3 2024-03-05
Threat Entry Updated 2025-03-11

CVE-2024-1088 - Password Protected Store For Woocommerce Plugin

The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including post titles and content.

PLUGIN Password Protected Store For Woocommerce

CVE-2024-1088

MEDIUM CVSS 5.3 2024-03-05
Threat Entry Updated 2025-06-27

CVE-2024-1316 - Event Tickets And Registration Plugin

The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).

PLUGIN Event Tickets And Registration

CVE-2024-1316

MEDIUM CVSS 6.5 2024-03-04
Scroll to top