Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 861-880 of 1249 records
Threat Entry Updated 2025-05-16

CVE-2024-3673 - Web Directory Free Plugin

The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.

PLUGIN Web Directory Free

CVE-2024-3673

CRITICAL CVSS 9.1 2024-08-30
Threat Entry Updated 2024-09-13

CVE-2024-7856 - Mp3 Audio Player For Music Radio Podcast Plugin

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files which can make remote code execution possible when wp-config.php is deleted.

PLUGIN Mp3 Audio Player For Music Radio Podcast

CVE-2024-7856

CRITICAL CVSS 9.1 2024-08-29
Threat Entry Updated 2025-03-13

CVE-2024-7857 - Media Library Folders Plugin

The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter of the 'mlf_change_sort_type' AJAX action in all versions up to, and including, 8.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Media Library Folders

CVE-2024-7857

CRITICAL CVSS 9.8 2024-08-29
Threat Entry Updated 2024-09-27

CVE-2024-7568 - Favicon Generator Plugin

The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the output_sub_admin_page_0 function. This makes it possible for unauthenticated attackers to delete arbitrary files on the server via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The plugin author deleted the functionality of the plugin to patch this issue and close the plugin, we recommend seeking an alternative to…

PLUGIN Favicon Generator

CVE-2024-7568

CRITICAL CVSS 9.6 2024-08-24
Threat Entry Updated 2024-09-27

CVE-2024-6386 - Wpml Plugin

The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via the Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

PLUGIN Wpml

CVE-2024-6386

CRITICAL CVSS 9.9 2024-08-21
Threat Entry Updated 2024-09-27

CVE-2024-7854 - Woo Inquiry Plugin

The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to insufficient escaping on the user supplied parameter 'dbid' and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Woo Inquiry

CVE-2024-7854

CRITICAL CVSS 10.0 2024-08-21
Threat Entry Updated 2025-05-27

CVE-2024-6847 - Chatbot With Chatgpt Plugin

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.

PLUGIN Chatbot With Chatgpt

CVE-2024-6847

CRITICAL CVSS 9.8 2024-08-20
Threat Entry Updated 2024-08-26

CVE-2024-7777 - Contact Form Builder Plugin

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functions in versions 2.0 to 2.13.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to read and delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PLUGIN Contact Form Builder

CVE-2024-7777

CRITICAL CVSS 9.0 2024-08-20
Threat Entry Updated 2024-08-26

CVE-2024-5932 - Givewp Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.

PLUGIN Givewp

CVE-2024-5932

CRITICAL CVSS 10.0 2024-08-20
Threat Entry Updated 2025-05-27

CVE-2024-6330 - Geo My Wp Plugin

The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.

PLUGIN Geo My Wp

CVE-2024-6330

CRITICAL CVSS 9.8 2024-08-19
Threat Entry Updated 2025-05-27

CVE-2024-6459 - News Element Elementor Blog Magazine Plugin

The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

PLUGIN News Element Elementor Blog Magazine

CVE-2024-6459

CRITICAL CVSS 9.8 2024-08-17
Threat Entry Updated 2024-08-19

CVE-2024-6500 - Inpost For Woocommerce Plugin

The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as 1.4.4 (for InPost PL). This makes it possible for unauthenticated attackers to read and delete arbitrary files on Windows servers. On Linux servers, only files within the WordPress install will be deleted, but all files can be read.

PLUGIN Inpost For Woocommerce

CVE-2024-6500

CRITICAL CVSS 10.0 2024-08-17
Threat Entry Updated 2025-05-27

CVE-2024-6460 - Grow Plugin

The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

PLUGIN Grow

CVE-2024-6460

CRITICAL CVSS 9.8 2024-08-16
Threat Entry Updated 2024-08-13

CVE-2024-7094 - Js Support Ticket Plugin

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the style.php file, along with missing capability checks. This makes it possible for unauthenticated attackers to execute code on the server. This issue was partially patched in 2.8.6 when the code injection issue was resolved, and fully…

PLUGIN Js Support Ticket

CVE-2024-7094

CRITICAL CVSS 9.8 2024-08-13
Threat Entry Updated 2025-02-07

CVE-2024-7503 - Woocommerce Social Login Plugin

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the userID. This requires the email module to be enabled.

PLUGIN Woocommerce Social Login

CVE-2024-7503

CRITICAL CVSS 9.8 2024-08-12
Threat Entry Updated 2024-08-08

CVE-2024-7350 - Bookingpress Appointment Booking Plugin

The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to authentication bypass in versions 1.1.6 to 1.1.7. This is due to the plugin not properly verifying a user's identity prior to logging them in when completing a booking. This makes it possible for unauthenticated attackers to log in as registered users, including administrators, if they have access to that user's email. This is only exploitable when the 'Auto login user after successful booking' setting is enabled.

PLUGIN Bookingpress Appointment Booking

CVE-2024-7350

CRITICAL CVSS 9.8 2024-08-08
Threat Entry Updated 2024-08-05

CVE-2024-7257 - Woocommerce Extra Product Options Plugin

The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Woocommerce Extra Product Options

CVE-2024-7257

CRITICAL CVSS 9.8 2024-08-03
Threat Entry Updated 2025-05-28

CVE-2024-5975 - Cz Loan Management Plugin

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN Cz Loan Management

CVE-2024-5975

CRITICAL CVSS 9.1 2024-07-30
Threat Entry Updated 2025-08-20

CVE-2024-5765 - Wpstickybar Plugin

The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN Wpstickybar

CVE-2024-5765

CRITICAL CVSS 9.8 2024-07-30
Threat Entry Updated 2025-05-30

CVE-2024-6366 - User Profile Builder Plugin

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

PLUGIN User Profile Builder

CVE-2024-6366

CRITICAL CVSS 9.1 2024-07-29
Scroll to top