Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12021-12040 of 16202 records
Threat Entry Updated 2024-11-21

CVE-2024-1121 - Advanced Forms For Acf Plugin

The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_json_file() function in all versions up to, and including, 1.9.3.2. This makes it possible for unauthenticated attackers to export form settings.

PLUGIN Advanced Forms For Acf

CVE-2024-1121

MEDIUM CVSS 5.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-1092 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers, with contributor access or higher, to create, edit or delete feed categories created by them.

PLUGIN Rss Aggregator By Feedzy

CVE-2024-1092

MEDIUM CVSS 4.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-1075 - Minimal Coming Soon Maintenance Mode Plugin

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance mode and view pages that should be hidden.

PLUGIN Minimal Coming Soon Maintenance Mode

CVE-2024-1075

LOW CVSS 3.7 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0869 - Instant Images One Click Unsplash Uploads Plugin

The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs to the plugin on the instant-images/license REST API endpoint in all versions up to, and including, 6.1.0. This makes it possible for authors and higher to update arbitrary options.

PLUGIN Instant Images One Click Unsplash Uploads

CVE-2024-0869

HIGH CVSS 8.8 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-1046 - Profilepress Plugin

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'reg-number-field' shortcode in all versions up to, and including, 4.14.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Profilepress

CVE-2024-1046

MEDIUM CVSS 6.4 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0961 - Siteorigin Widgets Bundle Plugin

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the code editor in all versions up to, and including, 1.58.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Siteorigin Widgets Bundle

CVE-2024-0961

MEDIUM CVSS 6.4 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0954 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing context via the 'data-eael-wrapper-link' wrapper in all versions up to, and including, 5.9.7 due to insufficient input sanitization and output escaping on user supplied protocols. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2024-0954

MEDIUM CVSS 6.4 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0969 - Armember Plugin

The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Default Restriction" feature and view restricted post content.

PLUGIN Armember

CVE-2024-0969

MEDIUM CVSS 5.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0859 - Affiliates Manager Plugin

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.34. This is due to missing or incorrect nonce validation on the process_bulk_action function in ListAffiliatesTable.php. This makes it possible for unauthenticated attackers to delete affiliates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Affiliates Manager

CVE-2024-0859

MEDIUM CVSS 4.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0834 - Elementor Addon Elements Plugin

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_to parameter in all versions up to, and including, 1.12.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elementor Addon Elements

CVE-2024-0834

MEDIUM CVSS 6.4 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0823 - Exclusive Addons For Elementor Plugin

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' url in carousels in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Exclusive Addons For Elementor

CVE-2024-0823

MEDIUM CVSS 5.4 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0835 - Royal Elementor Kit Plugin

The Royal Elementor Kit theme for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the dismissed_handler function in all versions up to, and including, 1.0.116. This makes it possible for authenticated attackers, with subscriber access or higher, to update arbitrary transients. Note, that these transients can only be updated to true and not arbitrary values.

PLUGIN Royal Elementor Kit

CVE-2024-0835

MEDIUM CVSS 4.3 2024-02-05
Threat Entry Updated 2025-05-15

CVE-2024-0797 - Woot Plugin

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 1.0.6.1. This makes it possible for subscribers and higher to execute functions intended for admin use.

PLUGIN Woot

CVE-2024-0797

MEDIUM CVSS 4.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0796 - Woot Plugin

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6.1. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This makes it possible for unauthenticated attackers to invoke those functions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Woot

CVE-2024-0796

MEDIUM CVSS 4.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0791 - Wolf Wordpress Posts Bulk Editor And Products Manager Professional Plugin

The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on the wpbe_create_new_term, wpbe_update_tax_term, and wpbe_delete_tax_term functions in all versions up to, and including, 1.0.8.1. This makes it possible for authenticated attackers, with subscriber access or higher, to create, delete or modify taxonomy terms.

PLUGIN Wolf Wordpress Posts Bulk Editor And Products Manager Professional

CVE-2024-0791

MEDIUM CVSS 4.3 2024-02-05
Threat Entry Updated 2025-03-18

CVE-2024-0709 - Cryptocurrency Widgets Plugin

The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Cryptocurrency Widgets

CVE-2024-0709

CRITICAL CVSS 9.8 2024-02-05
Threat Entry Updated 2025-03-24

CVE-2024-0761 - File Manager Plugin

The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data including site backups in configurations where the .htaccess file in the directory does not block access.

PLUGIN File Manager

CVE-2024-0761

HIGH CVSS 8.1 2024-02-05
Threat Entry Updated 2025-05-15

CVE-2024-0699 - Ai Engine Plugin

The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_image_from_url' function in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Editor access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Ai Engine

CVE-2024-0699

MEDIUM CVSS 6.6 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0691 - Filebird Plugin

The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all versions up to, and including, 5.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. It may also be possible to socially engineer an administrator into uploading a malicious folder import.

PLUGIN Filebird

CVE-2024-0691

MEDIUM CVSS 5.5 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0790 - Wolf Wordpress Posts Bulk Editor And Products Manager Professional Plugin

The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8.1. This is due to missing or incorrect nonce validation on the wpbe_create_new_term, wpbe_update_tax_term, and wpbe_delete_tax_term functions. This makes it possible for unauthenticated attackers to create, modify and delete taxonomy terms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Furthermore, the functions wpbe_save_options, wpbe_bulk_delete_posts_count, wpbe_bulk_delete_posts, and wpbe_save_meta are vulnerable to Cross-Site…

PLUGIN Wolf Wordpress Posts Bulk Editor And Products Manager Professional

CVE-2024-0790

MEDIUM CVSS 5.4 2024-02-05
Scroll to top