Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 941-960 of 1249 records
Threat Entry Updated 2024-11-21

CVE-2024-4560 - Chatbot Chatgpt Plugin

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers, with to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Chatbot Chatgpt

CVE-2024-4560

CRITICAL CVSS 9.8 2024-05-14
Threat Entry Updated 2025-01-15

CVE-2024-4434 - Learnpress Plugin

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Learnpress

CVE-2024-4434

CRITICAL CVSS 9.8 2024-05-14
Threat Entry Updated 2024-11-21

CVE-2024-4413 - Motopress Hotel Booking Lite Plugin

The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Motopress Hotel Booking Lite

CVE-2024-4413

CRITICAL CVSS 9.8 2024-05-14
Threat Entry Updated 2024-11-21

CVE-2024-3806 - Porto Theme

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

THEME Porto

CVE-2024-3806

CRITICAL CVSS 9.8 2024-05-14
Threat Entry Updated 2024-11-21

CVE-2024-3070 - Last Viewed Posts By Wpbeginner Plugin

The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input from the LastViewedPosts Cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Last Viewed Posts By Wpbeginner

CVE-2024-3070

CRITICAL CVSS 9.8 2024-05-14
Threat Entry Updated 2024-11-21

CVE-2024-4393 - Social Connect Plugin

The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. This is due to insufficient verification on the OpenID server being supplied during the social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

PLUGIN Social Connect

CVE-2024-4393

CRITICAL CVSS 9.8 2024-05-08
Threat Entry Updated 2024-11-21

CVE-2024-4346 - Startklar Elmentor Forms Extwidgets Plugin

The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.7.13. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.

PLUGIN Startklar Elmentor Forms Extwidgets

CVE-2024-4346

CRITICAL CVSS 9.1 2024-05-07
Threat Entry Updated 2024-11-21

CVE-2024-4345 - Startklar Elmentor Forms Extwidgets Plugin

The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process' function in the 'startklarDropZoneUploadProcess' class in versions up to, and including, 1.7.13. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Startklar Elmentor Forms Extwidgets

CVE-2024-4345

CRITICAL CVSS 9.8 2024-05-07
Threat Entry Updated 2024-11-21

CVE-2024-4186 - Edwiser Bridge Plugin

The Build App Online plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. This is due to the 'eb_user_email_verification_key' default value is empty, and the not empty check is missing in the 'eb_user_email_verify' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This can only be exploited if the 'Email Verification' setting is enabled.

PLUGIN Edwiser Bridge

CVE-2024-4186

CRITICAL CVSS 9.8 2024-05-07
Threat Entry Updated 2025-06-05

CVE-2024-3729 - Frontend Admin Plugin

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to manipulate the user processing forms, which can be used to add and edit administrator user for privilege escalation, or to automatically log in users for authentication bypass, or manipulate the post processing form that can be used to inject arbitrary web scripts. This can only be exploited if the 'openssl' php extension is not…

PLUGIN Frontend Admin

CVE-2024-3729

CRITICAL CVSS 9.8 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-2876 - Woocommerce Plugin

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including, 5.7.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Woocommerce

CVE-2024-2876

CRITICAL CVSS 9.8 2024-05-02
Threat Entry Updated 2025-02-06

CVE-2024-2667 - Instawp Connect Plugin

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This makes it possible for unauthenticated attackers to upload arbitrary files.

PLUGIN Instawp Connect

CVE-2024-2667

CRITICAL CVSS 9.8 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-3342 - Timetable And Event Schedule By Motopress Plugin

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all versions up to, and including, 2.4.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Timetable And Event Schedule By Motopress

CVE-2024-3342

CRITICAL CVSS 9.9 2024-04-27
Threat Entry Updated 2025-02-07

CVE-2024-3962 - Product Addons Fields For Woocommerce Plugin

The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ppom_upload_file function in all versions up to, and including, 32.0.18. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires the PPOM Pro plugin to be installed along with a WooCommerce product that contains a file upload field to retrieve the correct nonce.

PLUGIN Product Addons Fields For Woocommerce

CVE-2024-3962

CRITICAL CVSS 9.8 2024-04-26
Threat Entry Updated 2025-01-17

CVE-2024-3136 - Masterstudy Lms Plugin

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Masterstudy Lms

CVE-2024-3136

CRITICAL CVSS 9.8 2024-04-09
Threat Entry Updated 2024-11-21

CVE-2024-2804 - Network Summary Plugin

The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up to, and including, 2.0.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Network Summary

CVE-2024-2804

CRITICAL CVSS 9.8 2024-04-09
Threat Entry Updated 2025-01-31

CVE-2024-1813 - Simple Job Board Plugin

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code when a submitted job application is viewed.

PLUGIN Simple Job Board

CVE-2024-1813

CRITICAL CVSS 9.8 2024-04-09
Threat Entry Updated 2025-03-17

CVE-2024-2879 - Layerslider Plugin

The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Layerslider

CVE-2024-2879

CRITICAL CVSS 9.8 2024-04-03
Scroll to top