Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 901-920 of 1249 records
Threat Entry Updated 2025-05-09

CVE-2024-4098 - Shariff Wrapper Plugin

The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 via the shariff3uu_fetch_sharecounts function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Shariff Wrapper

CVE-2024-4098

CRITICAL CVSS 9.8 2024-06-20
Threat Entry Updated 2024-11-21

CVE-2024-5432 - Lifeline Donation Plugin

The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficient verification on the user being supplied during the checkout through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

PLUGIN Lifeline Donation

CVE-2024-5432

CRITICAL CVSS 9.8 2024-06-20
Threat Entry Updated 2024-11-21

CVE-2024-4742 - Youzify Plugin

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Youzify

CVE-2024-4742

CRITICAL CVSS 9.8 2024-06-20
Threat Entry Updated 2024-11-21

CVE-2024-3605 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Hotel Booking

CVE-2024-3605

CRITICAL CVSS 10.0 2024-06-20
Threat Entry Updated 2025-12-05

CVE-2024-5853 - Sirv Plugin

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_file_by_chanks AJAX action in all versions up to, and including, 7.2.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Sirv

CVE-2024-5853

CRITICAL CVSS 9.9 2024-06-19
Threat Entry Updated 2025-04-11

CVE-2024-3229 - Salon Booking System Plugin

The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_ImportAssistants function along with missing authorization checks in all versions up to, and including, 10.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Salon Booking System

CVE-2024-3229

CRITICAL CVSS 9.8 2024-06-19
Threat Entry Updated 2024-11-21

CVE-2024-5021 - Nimble Portfolio Plugin

The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.1 via the 'file_get_contents' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Nimble Portfolio

CVE-2024-5021

CRITICAL CVSS 9.3 2024-06-19
Threat Entry Updated 2024-11-21

CVE-2024-4258 - Video Gallery Plugin

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.13 via the settings parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Video Gallery

CVE-2024-4258

CRITICAL CVSS 9.8 2024-06-15
Threat Entry Updated 2024-11-21

CVE-2024-3105 - Insert Php Plugin

The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server.

PLUGIN Insert Php

CVE-2024-3105

CRITICAL CVSS 9.9 2024-06-15
Threat Entry Updated 2025-02-07

CVE-2024-5871 - Woocommerce Social Login Plugin

The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Woocommerce Social Login

CVE-2024-5871

CRITICAL CVSS 9.8 2024-06-15
Threat Entry Updated 2025-02-20

CVE-2024-2472 - Latepoint Plugin

The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's cabinets, including the ability to view PII such as email addresses and to change their LatePoint user password, which may or may not be associated with a WordPress account.

PLUGIN Latepoint

CVE-2024-2472

CRITICAL CVSS 9.1 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-4936 - Canto Plugin

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. This required allow_url_include to be enabled on the target site in order to exploit.

PLUGIN Canto

CVE-2024-4936

CRITICAL CVSS 9.8 2024-06-14
Threat Entry Updated 2024-11-21

CVE-2024-4371 - Codesigner Plugin

The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.1 via deserialization of untrusted input from the recently_viewed_products cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive…

PLUGIN Codesigner

CVE-2024-4371

CRITICAL CVSS 9.0 2024-06-13
Threat Entry Updated 2025-03-25

CVE-2024-3552 - Web Directory Free Plugin

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.

PLUGIN Web Directory Free

CVE-2024-3552

CRITICAL CVSS 9.8 2024-06-13
Threat Entry Updated 2026-02-25

CVE-2024-3922 - Dokan Plugin

The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Dokan

CVE-2024-3922

CRITICAL CVSS 10.0 2024-06-13
Threat Entry Updated 2024-11-21

CVE-2024-4898 - Instawp Connect Plugin

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers to connect the site to InstaWP API, edit arbitrary site options and create administrator accounts.

PLUGIN Instawp Connect

CVE-2024-4898

CRITICAL CVSS 9.8 2024-06-12
Threat Entry Updated 2025-06-05

CVE-2024-3549 - Blog2social Plugin

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Blog2social

CVE-2024-3549

CRITICAL CVSS 9.9 2024-06-11
Threat Entry Updated 2025-05-01

CVE-2024-4620 - Arforms Premium Wordpress Form Builder Plugin

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form

PLUGIN Arforms Premium Wordpress Form Builder

CVE-2024-4620

CRITICAL CVSS 9.8 2024-06-07
Threat Entry Updated 2024-11-21

CVE-2024-3592 - Quiz And Survey Master Plugin

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Quiz And Survey Master

CVE-2024-3592

CRITICAL CVSS 9.9 2024-06-07
Scroll to top