Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 741-760 of 1249 records
Threat Entry Updated 2025-01-22

CVE-2024-12919 - Membership Content Restriction Paid Member Subscriptions Plugin

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the user-controlled value supplied via the 'pms_payment_id' parameter to authenticate users without any further identity validation. This makes it possible for unauthenticated attackers with knowledge of a valid payment ID to log in as any user who has made a purchase on the targeted site.

PLUGIN Membership Content Restriction Paid Member Subscriptions

CVE-2024-12919

CRITICAL CVSS 9.8 2025-01-14
Threat Entry Updated 2025-02-25

CVE-2024-12877 - Givewp Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files on the server that makes remote code execution possible. Please note this was only partially patched in 3.19.3, a fully sufficient patch was not released until 3.19.4. However, another…

PLUGIN Givewp

CVE-2024-12877

CRITICAL CVSS 9.8 2025-01-11
Threat Entry Updated 2025-06-27

CVE-2024-10215 - Wpbookit Plugin

The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.

PLUGIN Wpbookit

CVE-2024-10215

CRITICAL CVSS 9.8 2025-01-09
Threat Entry Updated 2025-06-05

CVE-2024-11642 - Post Grid Master Plugin

The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.4.12 via the 'locate_template' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other…

PLUGIN Post Grid Master

CVE-2024-11642

CRITICAL CVSS 9.8 2025-01-09
Threat Entry Updated 2025-08-12

CVE-2024-11350 - Adforest Plugin

The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password through the adforest_reset_password() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Adforest

CVE-2024-11350

CRITICAL CVSS 9.8 2025-01-08
Threat Entry Updated 2025-03-13

CVE-2024-11635 - Wordpress File Upload Plugin

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.

PLUGIN Wordpress File Upload

CVE-2024-11635

CRITICAL CVSS 9.8 2025-01-08
Threat Entry Updated 2025-04-17

CVE-2024-11613 - Wordpress File Upload Plugin

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined directory path. This makes it possible for unauthenticated attackers to execute code on the server.

PLUGIN Wordpress File Upload

CVE-2024-11613

CRITICAL CVSS 9.8 2025-01-08
Threat Entry Updated 2025-05-14

CVE-2024-8855 - Wordpress Auction Plugin

The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks

PLUGIN Wordpress Auction

CVE-2024-8855

CRITICAL CVSS 9.8 2025-01-07
Threat Entry Updated 2025-01-07

CVE-2024-12470 - Sakolawp Lite Plugin

The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an administrative user.

PLUGIN Sakolawp Lite

CVE-2024-12470

CRITICAL CVSS 9.8 2025-01-07
Threat Entry Updated 2025-01-07

CVE-2024-12264 - Payu India Plugin

The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /wp-json/payu/v1/generate-user-token and /wp-json/payu/v1/get-shipping-cost REST API endpoints not properly verifying a user's identity prior to setting the users ID and auth cookies. This makes it possible for unauthenticated attackers to create new administrative user accounts.

PLUGIN Payu India

CVE-2024-12264

CRITICAL CVSS 9.8 2025-01-07
Threat Entry Updated 2025-01-07

CVE-2024-12252 - Seo Beginner Auto Post Plugin

The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to overwrite the seo-beginner-auto-post.php file which can be leveraged to achieve remote code execution.

PLUGIN Seo Beginner Auto Post

CVE-2024-12252

CRITICAL CVSS 9.8 2025-01-07
Threat Entry Updated 2025-01-07

CVE-2024-12402 - Tc Ecommerce Plugin

The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.4. This is due to the plugin not properly validating a user's identity prior to updating their password through the update_user_profile() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Tc Ecommerce

CVE-2024-12402

CRITICAL CVSS 9.8 2025-01-07
Threat Entry Updated 2025-01-04

CVE-2024-12583 - Integration Dynamics Plugin

The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

PLUGIN Integration Dynamics

CVE-2024-12583

CRITICAL CVSS 9.9 2025-01-04
Threat Entry Updated 2025-05-17

CVE-2024-11972 - Hunk Companion Plugin

The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.

PLUGIN Hunk Companion

CVE-2024-11972

CRITICAL CVSS 9.8 2024-12-31
Threat Entry Updated 2024-12-25

CVE-2024-11281 - Woocommerce Point Of Sale Plugin

The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0. This is due to insufficient validation on the 'logged_in_user_id' value when option values are empty and the ability for attackers to change the email of arbitrary user accounts. This makes it possible for unauthenticated attackers to change the email of arbitrary user accounts, including administrators, and reset their password to gain access to the account.

PLUGIN Woocommerce Point Of Sale

CVE-2024-11281

CRITICAL CVSS 9.8 2024-12-25
Threat Entry Updated 2025-08-12

CVE-2024-11349 - Adforest Plugin

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the sb_login_user_with_otp_fun() function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.

PLUGIN Adforest

CVE-2024-11349

CRITICAL CVSS 9.8 2024-12-21
Threat Entry Updated 2024-12-20

CVE-2024-12571 - Store Locator Plugin

The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Store Locator

CVE-2024-12571

CRITICAL CVSS 9.8 2024-12-20
Threat Entry Updated 2024-12-19

CVE-2024-12626 - Custom Integrations In Wordpress Plugin

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. When used in conjunction with the plugin's import and code action feature, this vulnerability…

PLUGIN Custom Integrations In Wordpress

CVE-2024-12626

CRITICAL CVSS 9.6 2024-12-19
Threat Entry Updated 2024-12-18

CVE-2024-12287 - Biagiotti Membership Plugin

The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, such as administrators, granted they have access to an email.

PLUGIN Biagiotti Membership

CVE-2024-12287

CRITICAL CVSS 9.8 2024-12-18
Threat Entry Updated 2024-12-13

CVE-2024-9290 - Clone Migrate For Wordpress Plugin

The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Clone Migrate For Wordpress

CVE-2024-9290

CRITICAL CVSS 9.8 2024-12-13
Scroll to top