Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 761-780 of 1249 records
Threat Entry Updated 2024-12-12

CVE-2024-10124 - Vayu Blocks Plugin

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. This vulnerability was partially patched in version 1.1.1.

PLUGIN Vayu Blocks

CVE-2024-10124

CRITICAL CVSS 9.8 2024-12-12
Threat Entry Updated 2024-12-12

CVE-2024-11015 - Sign In With Google Plugin

The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to the 'authenticate_user' user function not implementing sufficient null value checks when setting the access token and user information. This makes it possible for unauthenticated attackers to log in as the first user who has signed in using Google OAuth, which could be the site administrator.

PLUGIN Sign In With Google

CVE-2024-11015

CRITICAL CVSS 9.8 2024-12-12
Threat Entry Updated 2024-12-08

CVE-2024-12209 - Wp Health Plugin

The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Wp Health

CVE-2024-12209

CRITICAL CVSS 9.8 2024-12-08
Threat Entry Updated 2024-12-06

CVE-2024-51615 - WordPress Auction Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Owen Cutajar & Hyder Jaffari WordPress Auction Plugin allows SQL Injection.This issue affects WordPress Auction Plugin: from n/a through 3.7.

PLUGIN WordPress Auction Plugin

CVE-2024-51615

CRITICAL CVSS 9.3 2024-12-06
Threat Entry Updated 2024-12-06

CVE-2024-12155 - Sv100 Companion Plugin

The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the settings_import() function in all versions up to, and including, 2.0.02. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

PLUGIN Sv100 Companion

CVE-2024-12155

CRITICAL CVSS 9.8 2024-12-06
Threat Entry Updated 2024-11-28

CVE-2024-8672 - Widget Options Plugin

The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 via the display logic functionality that extends several page builders. This is due to the plugin allowing users to supply input that will be passed through eval() without any filtering or capability checks. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server. Special note: We suggested the vendor implement an allowlist of…

PLUGIN Widget Options

CVE-2024-8672

CRITICAL CVSS 9.9 2024-11-28
Threat Entry Updated 2025-04-11

CVE-2024-11103 - Contest Gallery Plugin

The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Contest Gallery

CVE-2024-11103

CRITICAL CVSS 9.8 2024-11-28
Threat Entry Updated 2024-11-28

CVE-2024-11082 - Tumult Hype Animations Plugin

The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hypeanimations_panel() function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Tumult Hype Animations

CVE-2024-11082

CRITICAL CVSS 9.9 2024-11-28
Threat Entry Updated 2024-11-28

CVE-2024-11925 - Jobsearch Wp Job Board Plugin

The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated attackers to log in as any user, including site administrators if the users email is known.

PLUGIN Jobsearch Wp Job Board

CVE-2024-11925

CRITICAL CVSS 9.8 2024-11-28
Threat Entry Updated 2025-06-05

CVE-2024-11024 - Apppresser Plugin

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to the plugin not properly validating a user's password reset code prior to updating their password. This makes it possible for unauthenticated attackers, with knowledge of a user's email address, to reset the user's password and gain access to their account.

PLUGIN Apppresser

CVE-2024-11024

CRITICAL CVSS 9.8 2024-11-26
Threat Entry Updated 2025-07-12

CVE-2024-10542 - Anti Spam Plugin

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

PLUGIN Anti Spam

CVE-2024-10542

CRITICAL CVSS 9.8 2024-11-26
Threat Entry Updated 2024-11-26

CVE-2024-9942 - Wordpress Gym Management System Plugin

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wordpress Gym Management System

CVE-2024-9942

CRITICAL CVSS 9.8 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-9659 - School Management System Plugin

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN School Management System

CVE-2024-9659

CRITICAL CVSS 9.8 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-9511 - Fluent Smtp Plugin

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.82 via deserialization of untrusted input in the 'formatResult' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary…

PLUGIN Fluent Smtp

CVE-2024-9511

CRITICAL CVSS 9.8 2024-11-23
Threat Entry Updated 2024-12-06

CVE-2024-10961 - Oa Social Login Plugin

The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

PLUGIN Oa Social Login

CVE-2024-10961

CRITICAL CVSS 9.8 2024-11-23
Threat Entry Updated 2024-11-20

CVE-2024-52431 - Wordpress Video Robot Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pressaholic WordPress Video Robot - The Ultimate Video Importer allows SQL Injection.This issue affects WordPress Video Robot - The Ultimate Video Importer: from n/a through 1.20.0.

PLUGIN Wordpress Video Robot

CVE-2024-52431

CRITICAL CVSS 9.3 2024-11-18
Threat Entry Updated 2024-11-18

CVE-2024-52408 - Push Notifications for WordPress by PushAssist Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Team PushAssist Push Notifications for WordPress by PushAssist allows Upload a Web Shell to a Web Server.This issue affects Push Notifications for WordPress by PushAssist: from n/a through 3.0.8.

PLUGIN Push Notifications for WordPress by PushAssist

CVE-2024-52408

CRITICAL CVSS 9.9 2024-11-16
Threat Entry Updated 2025-07-09

CVE-2024-8856 - Backup And Staging By Wp Time Capsule Plugin

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Backup And Staging By Wp Time Capsule

CVE-2024-8856

CRITICAL CVSS 9.8 2024-11-16
Threat Entry Updated 2026-01-23

CVE-2024-10924 - Really Simple Security Plugin

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

PLUGIN Really Simple Security

CVE-2024-10924

CRITICAL CVSS 9.8 2024-11-15
Threat Entry Updated 2024-11-15

CVE-2024-52370 - Hive Support – WordPress Help Desk Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support – WordPress Help Desk allows Upload a Web Shell to a Web Server.This issue affects Hive Support – WordPress Help Desk: from n/a through 1.1.1.

PLUGIN Hive Support – WordPress Help Desk

CVE-2024-52370

CRITICAL CVSS 9.9 2024-11-14
Scroll to top