Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 801-820 of 1249 records
Threat Entry Updated 2024-11-08

CVE-2024-9307 - Mfolio Plugin

The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file or upload arbitrary EXE files on the affected site's server which may make remote code execution possible if the attacker can also gain access to run the .exe file, or trick a site visitor into downloading…

PLUGIN Mfolio

CVE-2024-9307

CRITICAL CVSS 9.9 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10687 - Contest Gallery Plugin

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and including, 24.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Contest Gallery

CVE-2024-10687

CRITICAL CVSS 9.8 2024-11-05
Threat Entry Updated 2024-11-01

CVE-2024-10392 - Complete Ai Pack Plugin

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and including, 1.8.89. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Complete Ai Pack

CVE-2024-10392

CRITICAL CVSS 9.8 2024-10-31
Threat Entry Updated 2024-11-01

CVE-2024-8512 - W3speedster Wp Plugin

The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 via the 'script' parameter of the hookBeforeStartOptimization() function. This is due to the plugin passing user supplied input to eval(). This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

PLUGIN W3speedster Wp

CVE-2024-8512

CRITICAL CVSS 9.1 2024-10-30
Threat Entry Updated 2024-11-07

CVE-2024-9989 - Crypto Tool Plugin

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.15. This is due a to limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

PLUGIN Crypto Tool

CVE-2024-9989

CRITICAL CVSS 9.8 2024-10-29
Threat Entry Updated 2024-11-07

CVE-2024-9988 - Crypto Tool Plugin

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.15. This is due to missing validation on the user being supplied in the 'crypto_connect_ajax_process::register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

PLUGIN Crypto Tool

CVE-2024-9988

CRITICAL CVSS 9.8 2024-10-29
Threat Entry Updated 2024-11-08

CVE-2024-50496 - Ar Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Web and Print Design AR For WordPress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: from n/a through 6.2.

PLUGIN Ar

CVE-2024-50496

CRITICAL CVSS 10.0 2024-10-28
Threat Entry Updated 2024-10-28

CVE-2024-9501 - Wp Social Plugin

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

PLUGIN Wp Social

CVE-2024-9501

CRITICAL CVSS 9.8 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9933 - Watchtowerhq Plugin

The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.6. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login' function. This makes it possible for unauthenticated attackers to log in to the WatchTowerHQ client administrator user.

PLUGIN Watchtowerhq

CVE-2024-9933

CRITICAL CVSS 9.8 2024-10-26
Threat Entry Updated 2026-01-23

CVE-2024-9932 - Wux Blog Editor Plugin

The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wux Blog Editor

CVE-2024-9932

CRITICAL CVSS 9.8 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9931 - Wux Blog Editor Plugin

The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to log in to the first administrator user.

PLUGIN Wux Blog Editor

CVE-2024-9931

CRITICAL CVSS 9.8 2024-10-26
Threat Entry Updated 2024-10-28

CVE-2024-9930 - Sb Core Plugin

The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2.3.2. This is due to missing validation on the user being supplied in the 'verify_email' action. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator. The vulnerability is in the Account extension.

PLUGIN Sb Core

CVE-2024-9930

CRITICAL CVSS 9.8 2024-10-26
Threat Entry Updated 2024-11-06

CVE-2024-9488 - Wpdiscuz Plugin

The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

PLUGIN Wpdiscuz

CVE-2024-9488

CRITICAL CVSS 9.8 2024-10-25
Threat Entry Updated 2024-10-18

CVE-2024-9263 - Wp Timetics Ai Powered Appointment Booking Calendar And Online Scheduling Plugin

The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to reset the emails and passwords of arbitrary user accounts, including administrators, which makes account takeover and privilege escalation possible.

PLUGIN Wp Timetics Ai Powered Appointment Booking Calendar And Online Scheduling

CVE-2024-9263

CRITICAL CVSS 9.8 2024-10-17
Threat Entry Updated 2024-10-18

CVE-2024-9863 - Miniorange Firebase Sms Otp Verification Plugin

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form is disabled.

PLUGIN Miniorange Firebase Sms Otp Verification

CVE-2024-9863

CRITICAL CVSS 9.8 2024-10-17
Threat Entry Updated 2025-01-28

CVE-2024-9862 - Otp Verification With Firebase Plugin

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources, and the user current password check is missing. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.

PLUGIN Otp Verification With Firebase

CVE-2024-9862

CRITICAL CVSS 9.8 2024-10-17
Threat Entry Updated 2024-10-16

CVE-2024-9893 - Nextend Facebook Connect Plugin

The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

PLUGIN Nextend Facebook Connect

CVE-2024-9893

CRITICAL CVSS 9.8 2024-10-16
Threat Entry Updated 2024-10-16

CVE-2024-49260 - WordPress Gallery Plugin – Limb Image Gallery

Unrestricted Upload of File with Dangerous Type vulnerability in Limb WordPress Gallery Plugin – Limb Image Gallery allows Code Injection.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through 1.5.7.

PLUGIN WordPress Gallery Plugin – Limb Image Gallery

CVE-2024-49260

CRITICAL CVSS 9.9 2024-10-16
Scroll to top