Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 821-840 of 1249 records
Threat Entry Updated 2026-04-08

CVE-2021-4449 - Zoomsounds Plugin

The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE-2021-4457 is a duplicate of this.

PLUGIN Zoomsounds

CVE-2021-4449

CRITICAL CVSS 9.8 2024-10-16
Threat Entry Updated 2024-10-16

CVE-2021-4443 - QuadMenu – Mega Menu Plugin

The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. This makes it possible for unauthenticated attackers to create arbitrary PHP files that can be used to execute malicious code.

PLUGIN QuadMenu – Mega Menu

CVE-2021-4443

CRITICAL CVSS 9.8 2024-10-16
Threat Entry Updated 2025-02-27

CVE-2024-9634 - Givewp Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 via deserialization of untrusted input from the give_company_name parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.

PLUGIN Givewp

CVE-2024-9634

CRITICAL CVSS 9.8 2024-10-16
Threat Entry Updated 2024-10-16

CVE-2024-9105 - Ultimateai Plugin

The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This is due to insufficient verification on the user being supplied in the 'ultimate_ai_register_or_login_with_google' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

PLUGIN Ultimateai

CVE-2024-9105

CRITICAL CVSS 9.8 2024-10-16
Threat Entry Updated 2025-03-12

CVE-2024-9047 - Wordpress File Upload Plugin

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the targeted WordPress installation to be using PHP 7.4 or earlier.

PLUGIN Wordpress File Upload

CVE-2024-9047

CRITICAL CVSS 9.8 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9707 - Hunk Companion Plugin

The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

PLUGIN Hunk Companion

CVE-2024-9707

CRITICAL CVSS 9.8 2024-10-11
Threat Entry Updated 2024-10-15

CVE-2024-9234 - Gutenkit Blocks Addon Plugin

The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API endpoint) in all versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins, or utilize the functionality to upload arbitrary files spoofed like plugins.

PLUGIN Gutenkit Blocks Addon

CVE-2024-9234

CRITICAL CVSS 9.8 2024-10-11
Threat Entry Updated 2024-11-15

CVE-2024-9822 - Pedalo Connector Plugin

The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user, who is usually the administrator, or if it does not exist, then to the first administrator.

PLUGIN Pedalo Connector

CVE-2024-9822

CRITICAL CVSS 9.8 2024-10-11
Threat Entry Updated 2024-10-15

CVE-2024-9796 - Wp Advanced Search Plugin

The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

PLUGIN Wp Advanced Search

CVE-2024-9796

CRITICAL CVSS 9.8 2024-10-10
Threat Entry Updated 2024-10-15

CVE-2024-9518 - Userplus Plugin

The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' functions. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' parameter during a registration.

PLUGIN Userplus

CVE-2024-9518

CRITICAL CVSS 9.8 2024-10-10
Threat Entry Updated 2025-02-20

CVE-2024-8943 - Latepoint Plugin

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being supplied during the booking customer step. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. Note that logging in as a WordPress user is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. The vulnerability…

PLUGIN Latepoint

CVE-2024-8943

CRITICAL CVSS 9.8 2024-10-08
Threat Entry Updated 2025-02-20

CVE-2024-8911 - Latepoint Plugin

The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts. Note that changing a WordPress user's password is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. Without this setting enabled, only…

PLUGIN Latepoint

CVE-2024-8911

CRITICAL CVSS 9.8 2024-10-08
Threat Entry Updated 2024-10-07

CVE-2024-9289 - Affiliate Pro Plugin

The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible for unauthenticated attackers to log in as any user, including administrators, granted they have access to the administrator's email.

PLUGIN Affiliate Pro

CVE-2024-9289

CRITICAL CVSS 9.8 2024-10-01
Threat Entry Updated 2024-10-07

CVE-2024-9265 - Echo Rss Feed Post Generator Plugin

The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through the echo_check_post_header_sent() function. This makes it possible for unauthenticated attackers to register as an administrator.

PLUGIN Echo Rss Feed Post Generator

CVE-2024-9265

CRITICAL CVSS 9.8 2024-10-01
Threat Entry Updated 2024-10-04

CVE-2024-9108 - Wechat Social Login Plugin

The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wechat Social Login

CVE-2024-9108

CRITICAL CVSS 9.8 2024-10-01
Threat Entry Updated 2024-10-04

CVE-2024-9106 - Wechat Social Login Plugin

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.

PLUGIN Wechat Social Login

CVE-2024-9106

CRITICAL CVSS 9.8 2024-10-01
Threat Entry Updated 2024-10-01

CVE-2024-8353 - Givewp Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files and achieve remote code execution. This is essentially the same vulnerability as CVE-2024-5932, however, it was discovered the the presence of stripslashes_deep on user_info allows the is_serialized check…

PLUGIN Givewp

CVE-2024-8353

CRITICAL CVSS 10.0 2024-09-28
Threat Entry Updated 2024-10-02

CVE-2024-7772 - Jupiter X Core Plugin

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in all versions up to, and including, 4.6.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Jupiter X Core

CVE-2024-7772

CRITICAL CVSS 9.8 2024-09-26
Threat Entry Updated 2024-10-02

CVE-2024-8275 - The Events Calendar Plugin

The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection.

PLUGIN The Events Calendar

CVE-2024-8275

CRITICAL CVSS 9.8 2024-09-25
Threat Entry Updated 2024-10-02

CVE-2024-8514 - Google Website Translator Plugin

The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via deserialization of untrusted input from the 'prisna_import' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or…

PLUGIN Google Website Translator

CVE-2024-8514

CRITICAL CVSS 9.1 2024-09-25
Scroll to top