Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 961-980 of 1249 records
Threat Entry Updated 2024-11-21

CVE-2024-2086 - Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files into Your WordPress Site Plugin

The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers to modify plugin settings as well as allowing full read/write/delete access to the Google Drive associated with the plugin.

PLUGIN Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files into Your WordPress Site

CVE-2024-2086

CRITICAL CVSS 10.0 2024-03-30
Threat Entry Updated 2025-02-13

CVE-2024-2411 - Masterstudy Lms Plugin

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Masterstudy Lms

CVE-2024-2411

CRITICAL CVSS 9.8 2024-03-29
Threat Entry Updated 2025-02-13

CVE-2024-2409 - Masterstudy Lms Plugin

The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() function called by the 'wp_ajax_nopriv_stm_lms_register' AJAX action. This makes it possible for unauthenticated attackers to register a user with administrator-level privileges when MasterStudy LMS Pro is installed and the LMS Forms Editor add-on is enabled.

PLUGIN Masterstudy Lms

CVE-2024-2409

CRITICAL CVSS 9.8 2024-03-29
Threat Entry Updated 2024-11-21

CVE-2024-1711 - Create By Mediavine Plugin

The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Create By Mediavine

CVE-2024-1711

CRITICAL CVSS 9.8 2024-03-20
Threat Entry Updated 2024-11-21

CVE-2024-2172 - Malware Scanner Plugin

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This makes it possible for unauthenticated attackers to escalate their privileges to that of an administrator.

PLUGIN Malware Scanner

CVE-2024-2172

CRITICAL CVSS 9.8 2024-03-13
Threat Entry Updated 2025-03-05

CVE-2024-1071 - Ultimate Member Plugin

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ultimate Member

CVE-2024-1071

CRITICAL CVSS 9.8 2024-03-13
Threat Entry Updated 2025-01-21

CVE-2023-6825 - File Manager Plugin

The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file…

PLUGIN File Manager

CVE-2023-6825

CRITICAL CVSS 9.9 2024-03-13
Threat Entry Updated 2025-01-16

CVE-2024-1981 - Migration Backup Staging Plugin

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Migration Backup Staging

CVE-2024-1981

CRITICAL CVSS 9.8 2024-02-29
Threat Entry Updated 2025-01-28

CVE-2024-1514 - Wp Ecommerce Plugin

The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Ecommerce

CVE-2024-1514

CRITICAL CVSS 9.8 2024-02-28
Threat Entry Updated 2025-03-10

CVE-2024-1698 - Notificationx Plugin

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Notificationx

CVE-2024-1698

CRITICAL CVSS 9.8 2024-02-27
Threat Entry Updated 2024-12-18

CVE-2024-1512 - Masterstudy Lms Plugin

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Masterstudy Lms

CVE-2024-1512

CRITICAL CVSS 9.8 2024-02-17
Threat Entry Updated 2025-02-26

CVE-2024-0610 - Piraeus Bank Woocommerce Payment Gateway Plugin

The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'MerchantReference' parameter in all versions up to, and including, 1.6.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Piraeus Bank Woocommerce Payment Gateway

CVE-2024-0610

CRITICAL CVSS 9.8 2024-02-17
Threat Entry Updated 2025-05-06

CVE-2023-6036 - Before 3 Plugin

The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

PLUGIN Before 3

CVE-2023-6036

CRITICAL CVSS 9.8 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-1207 - Booking Calendar Plugin

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Booking Calendar

CVE-2024-1207

CRITICAL CVSS 9.8 2024-02-08
Threat Entry Updated 2025-03-18

CVE-2024-0709 - Cryptocurrency Widgets Plugin

The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Cryptocurrency Widgets

CVE-2024-0709

CRITICAL CVSS 9.8 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0221 - Photo Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.19 via the rename_item function. This makes it possible for authenticated attackers to rename arbitrary files on the server. This can lead to site takeovers if the wp-config.php file of a site can be renamed. By default this can be exploited by administrators only. In the premium version of the plugin, administrators can give gallery management permissions to lower level users, which might make this exploitable…

PLUGIN Photo Gallery

CVE-2024-0221

CRITICAL CVSS 9.1 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2023-6989 - Shield Security Plugin

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

PLUGIN Shield Security

CVE-2023-6989

CRITICAL CVSS 9.8 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2023-6933 - Better Search Replace Plugin

The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Better Search Replace

CVE-2023-6933

CRITICAL CVSS 9.8 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2021-4436 - 3dprint Lite Plugin

The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.

PLUGIN 3dprint Lite

CVE-2021-4436

CRITICAL CVSS 9.8 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-0705 - Stripe Payment Plugin For Woocommerce

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Stripe Payment Plugin For Woocommerce

CVE-2024-0705

CRITICAL CVSS 9.8 2024-01-19
Scroll to top