Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 11981-12000 of 16202 records
Threat Entry Updated 2024-11-21

CVE-2023-6591 - Before 20 Plugin

The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 20

CVE-2023-6591

MEDIUM CVSS 4.8 2024-02-12
Threat Entry Updated 2025-05-07

CVE-2024-0248 - Before 2 Plugin

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.

PLUGIN Before 2

CVE-2024-0248

MEDIUM CVSS 4.3 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2023-6501 - Splashscreen Plugin

The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Splashscreen

CVE-2023-6501

MEDIUM CVSS 4.3 2024-02-12
Threat Entry Updated 2025-05-06

CVE-2023-6036 - Before 3 Plugin

The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

PLUGIN Before 3

CVE-2023-6036

CRITICAL CVSS 9.8 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-24887 - Contest Gallery Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress.This issue affects Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress: from n/a through 21.2.8.4.

PLUGIN Contest Gallery

CVE-2024-24887

MEDIUM CVSS 5.4 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-24926 - Brooklyn Plugin

Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.

PLUGIN Brooklyn

CVE-2024-24926

HIGH CVSS 7.5 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-24796 - Event Manager And Tickets Selling For Woocommerce Plugin

Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a through 4.1.1.

PLUGIN Event Manager And Tickets Selling For Woocommerce

CVE-2024-24796

HIGH CVSS 8.2 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2023-47526 - Chartify Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team Chartify – WordPress Chart Plugin allows Stored XSS.This issue affects Chartify – WordPress Chart Plugin: from n/a through 2.0.6.

PLUGIN Chartify

CVE-2023-47526

MEDIUM CVSS 5.9 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-24927 - Brooklyn Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme allows Reflected XSS.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.

PLUGIN Brooklyn

CVE-2024-24927

HIGH CVSS 7.1 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-23517 - Scheduling Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Start Booking Scheduling Plugin – Online Booking for WordPress allows Stored XSS.This issue affects Scheduling Plugin – Online Booking for WordPress: from n/a through 3.5.10.

PLUGIN Scheduling

CVE-2024-23517

MEDIUM CVSS 6.5 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2023-51404 - My Agile Privacy Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyAgilePrivacy My Agile Privacy – The only GDPR solution for WordPress that you can truly trust allows Stored XSS.This issue affects My Agile Privacy – The only GDPR solution for WordPress that you can truly trust: from n/a through 2.1.7.

PLUGIN My Agile Privacy

CVE-2023-51404

MEDIUM CVSS 6.5 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-24801 - Owl Carousel Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt OWL Carousel – WordPress Owl Carousel Slider allows Stored XSS.This issue affects OWL Carousel – WordPress Owl Carousel Slider: from n/a through 1.4.0.

PLUGIN Owl Carousel

CVE-2024-24801

MEDIUM CVSS 6.5 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-24713 - Auto Listings Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Auto Listings Auto Listings – Car Listings & Car Dealership Plugin for WordPress allows Stored XSS.This issue affects Auto Listings – Car Listings & Car Dealership Plugin for WordPress: from n/a through 2.6.5.

PLUGIN Auto Listings

CVE-2024-24713

MEDIUM CVSS 6.5 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-24712 - Social Login Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress allows Stored XSS.This issue affects Heateor Social Login WordPress: from n/a through 1.1.30.

PLUGIN Social Login

CVE-2024-24712

MEDIUM CVSS 6.5 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-0596 - Awesome Support Plugin

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to view password protected and draft posts.

PLUGIN Awesome Support

CVE-2024-0596

MEDIUM CVSS 5.3 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-0595 - Awesome Support Plugin

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve user data such as emails.

PLUGIN Awesome Support

CVE-2024-0595

MEDIUM CVSS 4.3 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-0594 - Awesome Support Plugin

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Awesome Support

CVE-2024-0594

HIGH CVSS 8.8 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-0842 - Backuply Plugin

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.5. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in the server running out of resources.

PLUGIN Backuply

CVE-2024-0842

HIGH CVSS 7.5 2024-02-09
Threat Entry Updated 2024-11-21

CVE-2024-1122 - Eventin Plugin

The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible for unauthenticated attackers to export event data.

PLUGIN Eventin

CVE-2024-1122

MEDIUM CVSS 5.3 2024-02-09
Threat Entry Updated 2024-11-21

CVE-2024-0657 - Internal Link Juicer Plugin

The Internal Link Juicer: SEO Auto Linker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as 'ilj_settings_field_links_per_page' in all versions up to, and including, 2.23.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Internal Link Juicer

CVE-2024-0657

MEDIUM CVSS 4.4 2024-02-09
Scroll to top