Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,189
Critical995
High3,341
Medium11,575
Reset
Showing 11861-11880 of 16189 records
Threat Entry Updated 2025-01-27

CVE-2024-0620 - Password Protect Wordpress Plugin

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts.

PLUGIN Password Protect Wordpress

CVE-2024-0620

MEDIUM CVSS 5.3 2024-02-29
Threat Entry Updated 2025-01-27

CVE-2024-0616 - Passster Plugin

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other metadata including passwords of password-protected posts and pages.

PLUGIN Passster

CVE-2024-0616

MEDIUM CVSS 5.3 2024-02-29
Threat Entry Updated 2025-03-04

CVE-2024-0621 - Simple Share Buttons Adder Plugin

The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Simple Share Buttons Adder

CVE-2024-0621

MEDIUM CVSS 4.4 2024-02-29
Threat Entry Updated 2025-02-13

CVE-2024-0604 - Foogallery Plugin

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Foogallery

CVE-2024-0604

MEDIUM CVSS 4.4 2024-02-29
Threat Entry Updated 2025-03-04

CVE-2024-0590 - Clarity Plugin

The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing nonce validation on the edit_clarity_project_id() function. This makes it possible for unauthenticated attackers to change the project id and add malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Clarity

CVE-2024-0590

MEDIUM CVSS 6.1 2024-02-29
Threat Entry Updated 2025-02-27

CVE-2024-0602 - Yet Another Related Posts Plugin

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Yet Another Related Posts

CVE-2024-0602

MEDIUM CVSS 4.4 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0516 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible for unauthenticated attackers to update certain metadata.

PLUGIN Royal Elementor Addons

CVE-2024-0516

MEDIUM CVSS 5.3 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0515 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes it possible for unauthenticated attackers to remove items from user compare lists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Royal Elementor Addons

CVE-2024-0515

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0514 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_compare function. This makes it possible for unauthenticated attackers to add items to user compare lists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Royal Elementor Addons

CVE-2024-0514

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-01-27

CVE-2024-0506 - Website Builder Plugin

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Website Builder

CVE-2024-0506

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0513 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_wishlist function. This makes it possible for unauthenticated attackers to remove items from user wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Royal Elementor Addons

CVE-2024-0513

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0512 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_wishlist function. This makes it possible for unauthenticated attackers to add items to user wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Royal Elementor Addons

CVE-2024-0512

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0442 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and including, 1.3.87 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Royal Elementor Addons

CVE-2024-0442

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2024-12-27

CVE-2024-0438 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Happy Addons For Elementor

CVE-2024-0438

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-02-05

CVE-2024-0379 - Custom Twitter Feeds Plugin

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the ctf_auto_save_tokens function. This makes it possible for unauthenticated attackers to update the site's twitter API token and secret via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Custom Twitter Feeds

CVE-2024-0379

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-04-01

CVE-2023-6923 - Matomo Plugin

The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the idsite parameter in all versions up to, and including, 4.15.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Matomo

CVE-2023-6923

MEDIUM CVSS 6.1 2024-02-29
Threat Entry Updated 2025-02-27

CVE-2023-6806 - Starbox Plugin

The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Starbox

CVE-2023-6806

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-02-25

CVE-2023-6565 - Infinitewp Client Plugin

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.

PLUGIN Infinitewp Client

CVE-2023-6565

MEDIUM CVSS 5.9 2024-02-29
Threat Entry Updated 2025-01-27

CVE-2024-1808 - Shortcodes Ultimate Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_qrcode' shortcode in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shortcodes Ultimate

CVE-2024-1808

MEDIUM CVSS 6.4 2024-02-28
Scroll to top