Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12001-12020 of 16202 records
Threat Entry Updated 2024-12-17

CVE-2024-24881 - Wp Sms Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc allows Reflected XSS.This issue affects WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc: from n/a through 6.5.2.

PLUGIN Wp Sms

CVE-2024-24881

HIGH CVSS 7.1 2024-02-08
Threat Entry Updated 2024-11-21

CVE-2024-1207 - Booking Calendar Plugin

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Booking Calendar

CVE-2024-1207

CRITICAL CVSS 9.8 2024-02-08
Threat Entry Updated 2024-11-21

CVE-2024-0965 - Simple Page Access Restriction Plugin

The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content.

PLUGIN Simple Page Access Restriction

CVE-2024-0965

MEDIUM CVSS 5.3 2024-02-08
Threat Entry Updated 2024-11-21

CVE-2024-0511 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This makes it possible for unauthenticated attackers to post metadata via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Royal Elementor Addons

CVE-2024-0511

MEDIUM CVSS 4.3 2024-02-08
Threat Entry Updated 2024-11-21

CVE-2023-5665 - Payment Forms For Paystack Plugin

The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32130 is likely a duplicate of this issue.

PLUGIN Payment Forms For Paystack

CVE-2023-5665

MEDIUM CVSS 6.4 2024-02-08
Threat Entry Updated 2024-11-21

CVE-2024-1118 - Podlove Subscribe Button Plugin

The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-button shortcode in all versions up to, and including, 1.3.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Podlove Subscribe Button

CVE-2024-1118

HIGH CVSS 8.8 2024-02-07
Threat Entry Updated 2025-05-15

CVE-2024-1110 - Podlove Podcast Publisher Plugin

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init() function in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to import the plugin's settings.

PLUGIN Podlove Podcast Publisher

CVE-2024-1110

MEDIUM CVSS 5.3 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-1109 - Podlove Podcast Publisher Plugin

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_download() and init() functions in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to export the plugin's tracking data and podcast information.

PLUGIN Podlove Podcast Publisher

CVE-2024-1109

MEDIUM CVSS 5.3 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-1079 - Quiz Maker Plugin

The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. This makes it possible for unauthenticated attackers to fetch arbitrary quiz results which can contain PII.

PLUGIN Quiz Maker

CVE-2024-1079

MEDIUM CVSS 5.3 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-1078 - Quiz Maker Plugin

The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary quizzes.

PLUGIN Quiz Maker

CVE-2024-1078

MEDIUM CVSS 4.3 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-0977 - Timeline Widget For Elementor Plugin

The Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image URLs in the plugin's timeline widget in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, changes the slideshow type, and then changes it back to an image.

PLUGIN Timeline Widget For Elementor

CVE-2024-0977

MEDIUM CVSS 4.4 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-1055 - Powerpack Addons For Elementor Plugin

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's buttons in all versions up to, and including, 2.7.14 due to insufficient input sanitization and output escaping on user supplied URL values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Powerpack Addons For Elementor

CVE-2024-1055

MEDIUM CVSS 5.4 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-1037 - All In One Security Plugin

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN All In One Security

CVE-2024-1037

MEDIUM CVSS 6.1 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-0628 - Wp Rss Aggregator Plugin

The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Wp Rss Aggregator

CVE-2024-0628

LOW CVSS 3.8 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-0256 - Starbox Plugin

The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Starbox

CVE-2024-0256

MEDIUM CVSS 6.4 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-1210 - Learndash Plugin

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.

PLUGIN Learndash

CVE-2024-1210

MEDIUM CVSS 5.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-1209 - Learndash Plugin

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.

PLUGIN Learndash

CVE-2024-1209

MEDIUM CVSS 5.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-1072 - Website Builder By Seedprod Plugin

The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprod_lite_new_lpage function in all versions up to, and including, 6.15.21. This makes it possible for unauthenticated attackers to change the contents of coming-soon, maintenance pages, login and 404 pages set up with the plugin. Version 6.15.22 addresses this issue but introduces a bug affecting admin pages. We suggest upgrading to 6.15.23.

PLUGIN Website Builder By Seedprod

CVE-2024-1072

HIGH CVSS 8.2 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-1208 - Learndash Plugin

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.

PLUGIN Learndash

CVE-2024-1208

MEDIUM CVSS 5.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-1177 - Wp Club Manager Plugin

The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings_save() function in all versions up to, and including, 2.2.10. This makes it possible for unauthenticated attackers to update the permalink structure for the clubs

PLUGIN Wp Club Manager

CVE-2024-1177

MEDIUM CVSS 5.3 2024-02-05
Scroll to top