Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,189
Critical995
High3,341
Medium11,575
Reset
Showing 11821-11840 of 16189 records
Threat Entry Updated 2024-12-31

CVE-2024-1317 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via the ‘search_key’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Rss Aggregator By Feedzy

CVE-2024-1317

HIGH CVSS 8.8 2024-02-29
Threat Entry Updated 2024-12-31

CVE-2024-1318 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'feedzy_wizard_step_process' and 'import_status' functions in all versions up to, and including, 4.4.2. This makes it possible for authenticated attackers, with Contributor access and above, who are normally restricted to only being able to create posts rather than pages, to draft and publish posts with arbitrary content.

PLUGIN Rss Aggregator By Feedzy

CVE-2024-1318

MEDIUM CVSS 6.5 2024-02-29
Threat Entry Updated 2025-02-28

CVE-2024-1322 - Directorist Plugin

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes it possible for unauthenticated attackers to recreate default pages and enable or disable monetization and change map provider.

PLUGIN Directorist

CVE-2024-1322

MEDIUM CVSS 5.3 2024-02-29
Threat Entry Updated 2025-02-28

CVE-2024-1294 - Sunshine Photo Cart Plugin

The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.24 via the 'invoice'. This makes it possible for unauthenticated attackers to extract sensitive data including customer email and physical addresses.

PLUGIN Sunshine Photo Cart

CVE-2024-1294

MEDIUM CVSS 5.3 2024-02-29
Threat Entry Updated 2024-12-31

CVE-2024-1335 - Imagerecycle Pdf Image Compression Plugin

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the disableOptimization function. This makes it possible for unauthenticated attackers to disable the image optimization setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Imagerecycle Pdf Image Compression

CVE-2024-1335

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2024-12-31

CVE-2024-1334 - Imagerecycle Pdf Image Compression Plugin

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the enableOptimization function. This makes it possible for unauthenticated attackers to enable image optimization via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Imagerecycle Pdf Image Compression

CVE-2024-1334

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-03-04

CVE-2024-1282 - Email Encoder Plugin

The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Email Encoder

CVE-2024-1282

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-03-04

CVE-2024-1277 - Ocean Extra Plugin

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom fields in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ocean Extra

CVE-2024-1277

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-1276 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Content Ticker arrow attribute in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2024-1276

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-03-11

CVE-2024-1288 - Schema & Structured Data for WP & AMP Plugin

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saswp_reviews_form_render' function in all versions up to, and including, 1.26. This makes it possible for authenticated attackers, with contributor access and above, to modify the plugin's stored reCaptcha site and secret keys, potentially breaking the reCaptcha functionality.

PLUGIN Schema & Structured Data for WP & AMP

CVE-2024-1288

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-08-15

CVE-2024-1242 - Premium Addons For Elementor Plugin

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 4.10.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Premium Addons For Elementor

CVE-2024-1242

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-1236 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Filterable Controls label icon parameter in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2024-1236

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-01-15

CVE-2024-1235 - Addons For Elementor Plugin

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom class field in all versions up to, and including, 8.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Addons For Elementor

CVE-2024-1235

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-01-19

CVE-2024-1218 - Contact Form Builder Plugin

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with contributor access and higher, to obtain access to or modify forms or entries.

PLUGIN Contact Form Builder

CVE-2024-1218

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-02-27

CVE-2024-1206 - Wp Recipe Maker Plugin

The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up to, and including, 9.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Recipe Maker

CVE-2024-1206

HIGH CVSS 8.8 2024-02-29
Threat Entry Updated 2025-01-19

CVE-2024-1217 - Contact Form Builder Plugin

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with subscriber access or higher, to deactivate any active plugins.

PLUGIN Contact Form Builder

CVE-2024-1217

HIGH CVSS 7.6 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-1172 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2024-1172

MEDIUM CVSS 5.4 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-1171 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery Widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2024-1171

MEDIUM CVSS 5.4 2024-02-29
Threat Entry Updated 2025-01-15

CVE-2024-1130 - Nex Forms Plugin

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the set_read() function in all versions up to, and including, 8.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to mark records as read.

PLUGIN Nex Forms

CVE-2024-1130

MEDIUM CVSS 5.3 2024-02-29
Threat Entry Updated 2025-01-15

CVE-2024-1133 - Tutor Lms Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of restricted Q&A content due to a missing capability check when interacting with questions in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with subscriber access or higher, to interact with questions in courses in which they are not enrolled including private courses.

PLUGIN Tutor Lms

CVE-2024-1133

MEDIUM CVSS 4.3 2024-02-29
Scroll to top