Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 11941-11960 of 16202 records
Threat Entry Updated 2025-01-16

CVE-2024-1323 - Orbit Fox Plugin

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type Grid Widget Title in all versions up to, and including, 2.10.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Orbit Fox

CVE-2024-1323

MEDIUM CVSS 6.4 2024-02-27
Threat Entry Updated 2025-02-27

CVE-2024-1758 - Superfaktura Woocommerce Plugin

The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.40.3 via the wc_sf_url_check function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Superfaktura Woocommerce

CVE-2024-1758

MEDIUM CVSS 5.4 2024-02-26
Threat Entry Updated 2025-02-27

CVE-2024-1710 - Addon Library Plugin

The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the onAjaxAction function action in all versions up to, and including, 1.3.76. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several unauthorized actions including uploading arbitrary files.

PLUGIN Addon Library

CVE-2024-1710

HIGH CVSS 8.8 2024-02-26
Threat Entry Updated 2025-01-16

CVE-2024-1165 - Brizy Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files to arbitrary locations on the server

PLUGIN Brizy

CVE-2024-1165

MEDIUM CVSS 4.3 2024-02-26
Threat Entry Updated 2025-02-05

CVE-2023-5775 - Backwpup Plugin

The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated attackers, with administrator-level access, to retrieve the password from the password input field in the UI or from the options table where the password is stored.

PLUGIN Backwpup

CVE-2023-5775

LOW CVSS 2.2 2024-02-26
Threat Entry Updated 2025-02-05

CVE-2024-1810 - Archivist Plugin

The Archivist – Custom Archive Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode_attributes' parameter in all versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Archivist

CVE-2024-1810

MEDIUM CVSS 6.1 2024-02-24
Threat Entry Updated 2025-01-15

CVE-2024-1362 - Colibri Page Builder Plugin

The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the cp_shortcode_refresh() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Colibri Page Builder

CVE-2024-1362

MEDIUM CVSS 4.3 2024-02-23
Threat Entry Updated 2025-01-15

CVE-2024-1361 - Colibri Page Builder Plugin

The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the apiCall() function. This makes it possible for unauthenticated attackers to call a limited set of functions that can be used to import images, delete posts, or save theme data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Colibri Page Builder

CVE-2024-1361

MEDIUM CVSS 4.3 2024-02-23
Threat Entry Updated 2025-02-05

CVE-2024-1360 - Colibri Plugin

The Colibri WP theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.94. This is due to missing or incorrect nonce validation on the colibriwp_install_plugin() function. This makes it possible for unauthenticated attackers to install recommended plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Colibri

CVE-2024-1360

MEDIUM CVSS 4.3 2024-02-23
Threat Entry Updated 2025-06-17

CVE-2023-4826 - Socialdriver Plugin

The SocialDriver WordPress theme before version 2024 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties resulting in a cross-site scripting (XSS) attack.

PLUGIN Socialdriver

CVE-2023-4826

MEDIUM CVSS 6.1 2024-02-23
Threat Entry Updated 2025-01-28

CVE-2024-1590 - Pagelayer Plugin

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Pagelayer

CVE-2024-1590

MEDIUM CVSS 4.6 2024-02-23
Threat Entry Updated 2025-01-16

CVE-2024-1779 - Admin Side Data Storage For Contact Form 7 Plugin

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_status() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to alter the message read status of messages.

PLUGIN Admin Side Data Storage For Contact Form 7

CVE-2024-1779

MEDIUM CVSS 5.3 2024-02-23
Threat Entry Updated 2025-01-16

CVE-2024-1776 - Admin Side Data Storage For Contact Form 7 Plugin

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up to, and including, 1.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Admin Side Data Storage For Contact Form 7

CVE-2024-1776

HIGH CVSS 7.2 2024-02-23
Threat Entry Updated 2025-01-16

CVE-2024-1778 - Admin Side Data Storage For Contact Form 7 Plugin

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_bookmark() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to alter bookmark statuses.

PLUGIN Admin Side Data Storage For Contact Form 7

CVE-2024-1778

MEDIUM CVSS 4.3 2024-02-23
Threat Entry Updated 2025-01-16

CVE-2024-1777 - Admin Side Data Storage For Contact Form 7 Plugin

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the settings update function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Admin Side Data Storage For Contact Form 7

CVE-2024-1777

MEDIUM CVSS 4.3 2024-02-23
Threat Entry Updated 2025-02-05

CVE-2024-0903 - Userfeedback Plugin

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_submitted' 'link' value in all versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in the feedback submission page that will execute when a user clicks the link, while also pressing the command key.

PLUGIN Userfeedback

CVE-2024-0903

MEDIUM CVSS 5.4 2024-02-22
Threat Entry Updated 2025-02-07

CVE-2024-1053 - Event Tickets Plugin

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to email the attendees list to themselves.

PLUGIN Event Tickets

CVE-2024-1053

MEDIUM CVSS 4.3 2024-02-22
Threat Entry Updated 2024-11-21

CVE-2024-24837 - WooCommerce Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joomla to WordPress.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.44.3; FG Drupal to WordPress: from n/a through 3.67.0; FG Joomla to WordPress: from n/a through 4.15.0.

PLUGIN WooCommerce

CVE-2024-24837

MEDIUM CVSS 4.3 2024-02-21
Threat Entry Updated 2025-02-04

CVE-2024-1081 - 3d Flipbook Plugin

The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bookmark feature in all versions up to, and including, 1.15.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN 3d Flipbook

CVE-2024-1081

MEDIUM CVSS 6.4 2024-02-21
Threat Entry Updated 2025-01-31

CVE-2024-0593 - Simple Job Board Plugin

The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.

PLUGIN Simple Job Board

CVE-2024-0593

MEDIUM CVSS 5.3 2024-02-21
Scroll to top