Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,189
Critical995
High3,341
Medium11,575
Reset
Showing 11881-11900 of 16189 records
Threat Entry Updated 2025-02-11

CVE-2024-1860 - Anti Hacker Plugin

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the antihacker_add_whitelist() function in all versions up to, and including, 4.51. This makes it possible for unauthenticated attackers to add their IP Address to the whitelist circumventing protection

PLUGIN Anti Hacker

CVE-2024-1860

MEDIUM CVSS 6.5 2024-02-28
Threat Entry Updated 2025-01-27

CVE-2024-1861 - Anti Hacker Plugin

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the antihacker_truncate_scan_table() function in all versions up to, and including, 4.52. This makes it possible for authenticated attackers, with subscriber-level access and above, to truncate the scan table.

PLUGIN Anti Hacker

CVE-2024-1861

MEDIUM CVSS 4.3 2024-02-28
Threat Entry Updated 2025-03-21

CVE-2024-1719 - Paypal Stripe Add On Plugin

The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.3 and in Contact Form 7 – PayPal & Stripe Add-on all versions up to, and including 2.1. This is due to missing or incorrect nonce validation on the 'wpecpp_stripe_connect_completion' function. This makes it possible for unauthenticated attackers to modify the plugins settings and chance the stripe connection via a forged request granted they can trick a site administrator into performing an action such as clicking…

PLUGIN Paypal Stripe Add On

CVE-2024-1719

MEDIUM CVSS 4.3 2024-02-28
Threat Entry Updated 2025-01-28

CVE-2024-1514 - Wp Ecommerce Plugin

The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Ecommerce

CVE-2024-1514

CRITICAL CVSS 9.8 2024-02-28
Threat Entry Updated 2025-02-28

CVE-2024-1566 - Redirects Plugin

The Redirects plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to change redirects created with this plugin. This could lead to undesired redirection to phishing sites or malicious web pages.

PLUGIN Redirects

CVE-2024-1566

MEDIUM CVSS 6.5 2024-02-28
Threat Entry Updated 2025-03-04

CVE-2024-1791 - Codemirror Blocks Plugin

The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Codemirror Blocks

CVE-2024-1791

MEDIUM CVSS 6.4 2024-02-28
Threat Entry Updated 2025-03-04

CVE-2024-1954 - Oliver Pos Plugin

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1.8. This is due to missing or incorrect nonce validation in the includes/class-pos-bridge-install.php file. This makes it possible for unauthenticated attackers to perform several unauthorized actions like deactivating the plugin, disconnecting the subscription, syncing the status and more via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Oliver Pos

CVE-2024-1954

MEDIUM CVSS 6.3 2024-02-28
Threat Entry Updated 2025-02-11

CVE-2024-1516 - Wp Ecommerce Plugin

The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all versions up to, and including, 3.15.1. This makes it possible for unauthenticated attackers to create arbitrary posts with arbitrary content.

PLUGIN Wp Ecommerce

CVE-2024-1516

MEDIUM CVSS 5.3 2024-02-28
Threat Entry Updated 2025-02-07

CVE-2024-0786 - Conversios Io Plugin

The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ee_syncProductCategory function using the parameters conditionData, valueData, productArray, exclude and include in all versions up to, and including, 6.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber access or higher, to append additional SQL queries into already existing queries that can be…

PLUGIN Conversios Io

CVE-2024-0786

HIGH CVSS 8.8 2024-02-28
Threat Entry Updated 2025-03-06

CVE-2024-1476 - under_construction_\/_maintenance_mode Plugin

The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 via the REST API. This makes it possible for unauthenticated attackers to obtain the contents of posts and pages when maintenance mode is active thus bypassing the protection provided by the plugin.

PLUGIN under_construction_\/_maintenance_mode

CVE-2024-1476

MEDIUM CVSS 5.3 2024-02-28
Threat Entry Updated 2025-02-11

CVE-2024-1368 - Page Duplicator Plugin

The Page Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_dat_page() function in all versions up to, and including, 0.1.1. This makes it possible for unauthenticated attackers to duplicate arbitrary posts and pages.

PLUGIN Page Duplicator

CVE-2024-1368

MEDIUM CVSS 5.3 2024-02-28
Threat Entry Updated 2025-02-07

CVE-2024-1136 - Coming Soon Page Maintenance Mode Plugin

The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an improperly implemented URL check in the wpsm_coming_soon_redirect function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to view a site with maintenance mode or coming-soon mode enabled to view the site's content.

PLUGIN Coming Soon Page Maintenance Mode

CVE-2024-1136

MEDIUM CVSS 5.3 2024-02-28
Threat Entry Updated 2025-02-07

CVE-2024-0975 - Wordpress Access Control Plugin

The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Make Website Members Only" feature (when unset) and view restricted page and post content.

PLUGIN Wordpress Access Control

CVE-2024-0975

MEDIUM CVSS 5.3 2024-02-28
Threat Entry Updated 2025-01-08

CVE-2024-0768 - Envo S Elementor Templates Widgets For Woocommerce Plugin

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4.4. This is due to missing or incorrect nonce validation on the ajax_theme_activation function. This makes it possible for unauthenticated attackers to activate arbitrary installed themes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Envo S Elementor Templates Widgets For Woocommerce

CVE-2024-0768

MEDIUM CVSS 4.3 2024-02-28
Threat Entry Updated 2025-02-07

CVE-2024-0682 - Pagerestrict Plugin

The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.

PLUGIN Pagerestrict

CVE-2024-0682

MEDIUM CVSS 5.3 2024-02-28
Threat Entry Updated 2025-02-07

CVE-2024-0680 - Wp Private Content Plus Plugin

The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.6. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.

PLUGIN Wp Private Content Plus

CVE-2024-0680

MEDIUM CVSS 5.3 2024-02-28
Threat Entry Updated 2025-01-08

CVE-2024-0767 - Envo S Elementor Templates Widgets For Woocommerce Plugin

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on the ajax_plugin_activation function. This makes it possible for unauthenticated attackers to activate arbitrary installed plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Envo S Elementor Templates Widgets For Woocommerce

CVE-2024-0767

MEDIUM CVSS 4.3 2024-02-28
Threat Entry Updated 2025-01-08

CVE-2024-0766 - Envo S Elementor Templates Widgets For Woocommerce Plugin

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the templates_ajax_request function in all versions up to, and including, 1.4.4. This makes it possible for subscribers and higher to create templates.

PLUGIN Envo S Elementor Templates Widgets For Woocommerce

CVE-2024-0766

MEDIUM CVSS 4.3 2024-02-28
Threat Entry Updated 2025-02-10

CVE-2024-0433 - Gestpay For Woocommerce Plugin

The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20221130. This is due to missing or incorrect nonce validation on the 'ajax_unset_default_card' function. This makes it possible for unauthenticated attackers to remove the default status of a card token for a user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Gestpay For Woocommerce

CVE-2024-0433

MEDIUM CVSS 4.3 2024-02-28
Threat Entry Updated 2025-02-10

CVE-2024-0432 - Gestpay For Woocommerce Plugin

The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20221130. This is due to missing or incorrect nonce validation on the 'ajax_delete_card' function. This makes it possible for unauthenticated attackers to delete the default card token for a user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Gestpay For Woocommerce

CVE-2024-0432

MEDIUM CVSS 4.3 2024-02-28
Scroll to top