Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 881-900 of 1249 records
Threat Entry Updated 2025-02-11

CVE-2024-6636 - Woocommerce Social Login Plugin

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator while registering for an account.

PLUGIN Woocommerce Social Login

CVE-2024-6636

CRITICAL CVSS 9.8 2024-07-20
Threat Entry Updated 2024-11-21

CVE-2024-6205 - Payplus Payment Gateway Plugin

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.

PLUGIN Payplus Payment Gateway

CVE-2024-6205

CRITICAL CVSS 9.8 2024-07-19
Threat Entry Updated 2024-11-21

CVE-2024-6164 - Before 2 Plugin

The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

PLUGIN Before 2

CVE-2024-6164

CRITICAL CVSS 9.8 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-6220 - Keydatas Plugin

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Keydatas

CVE-2024-6220

CRITICAL CVSS 9.8 2024-07-17
Threat Entry Updated 2025-03-13

CVE-2024-6457 - Husky Products Filter Professional For Woocommerce Plugin

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ‘woof_author’ parameter in all versions up to, and including, 1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Husky Products Filter Professional For Woocommerce

CVE-2024-6457

CRITICAL CVSS 9.8 2024-07-16
Threat Entry Updated 2025-05-13

CVE-2024-5450 - Bug Library Plugin

The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload PHP files

PLUGIN Bug Library

CVE-2024-5450

CRITICAL CVSS 9.1 2024-07-13
Threat Entry Updated 2025-05-21

CVE-2024-6328 - Mstore Api Plugin

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of the 'firebase_sms_login' and 'firebase_sms_login_v2' functions. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email address or phone number. Additionally, if a new email address is supplied, a new user account is…

PLUGIN Mstore Api

CVE-2024-6328

CRITICAL CVSS 9.8 2024-07-12
Threat Entry Updated 2024-11-21

CVE-2024-6624 - Json Api User Plugin

The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.

PLUGIN Json Api User

CVE-2024-6624

CRITICAL CVSS 9.8 2024-07-11
Threat Entry Updated 2024-11-21

CVE-2024-6397 - Instawp Connect Plugin

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username, and to perform a variety of other administrative tasks. NOTE: This vulnerability was partially fixed in 0.1.0.44, but was still exploitable via Cross-Site Request Forgery.

PLUGIN Instawp Connect

CVE-2024-6397

CRITICAL CVSS 9.8 2024-07-11
Threat Entry Updated 2024-11-21

CVE-2024-3604 - Openstreetmap Plugin

The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the 'osm_map_v3' shortcode in all versions up to, and including, 6.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Openstreetmap

CVE-2024-3604

CRITICAL CVSS 9.9 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-6314 - Iq Testimonials Plugin

The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process_image_upload' function in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This can only be exploited if the 'gd' php extension is not loaded on the server.

PLUGIN Iq Testimonials

CVE-2024-6314

CRITICAL CVSS 9.8 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-6313 - Forms Gutenberg Plugin

The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' function in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Forms Gutenberg

CVE-2024-6313

CRITICAL CVSS 9.8 2024-07-09
Threat Entry Updated 2025-05-21

CVE-2024-5488 - Before 7 Plugin

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.

PLUGIN Before 7

CVE-2024-5488

CRITICAL CVSS 9.8 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-6365 - Woo Product Tables Plugin

The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' function. This is due to missing authorization and lack of sanitization of appended data in the languages/customTitle.php file. This makes it possible for unauthenticated attackers to execute code on the server.

PLUGIN Woo Product Tables

CVE-2024-6365

CRITICAL CVSS 9.8 2024-07-09
Threat Entry Updated 2024-11-21

CVE-2024-6172 - Email Subscribers Newsletters Plugin

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Email Subscribers Newsletters

CVE-2024-6172

CRITICAL CVSS 9.8 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-6265 - Userswp Plugin

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Userswp

CVE-2024-6265

CRITICAL CVSS 9.8 2024-06-29
Threat Entry Updated 2025-12-15

CVE-2024-6028 - Quiz Maker Plugin

The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Quiz Maker

CVE-2024-6028

CRITICAL CVSS 9.8 2024-06-25
Threat Entry Updated 2024-11-21

CVE-2024-6297 - Blaze Widget Plugin

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.

PLUGIN Blaze Widget

CVE-2024-6297

CRITICAL CVSS 10.0 2024-06-25
Threat Entry Updated 2024-11-21

CVE-2024-6027 - Product Filter Plugin

The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘conditions’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Product Filter

CVE-2024-6027

CRITICAL CVSS 9.8 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-5756 - Icegram Express Plugin

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Icegram Express

CVE-2024-5756

CRITICAL CVSS 9.8 2024-06-21
Scroll to top