Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,045
Critical0
High3,045
Medium0
Reset
Showing 2041-2060 of 3045 records
Threat Entry Updated 2024-11-21

CVE-2024-1945 - Arforms Form Builder Plugin

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'arflite_remove_preview_data' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with subscriber access and above, to delete arbitrary site options, resulting in loss of availability.

PLUGIN Arforms Form Builder

CVE-2024-1945

HIGH CVSS 7.1 2024-05-02
Threat Entry Updated 2025-03-05

CVE-2024-1797 - Wp Ulike Plugin

The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the 'wp_ulike_counter' and 'wp_ulike' shortcodes in all versions up to, and including, 4.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Ulike

CVE-2024-1797

HIGH CVSS 8.8 2024-05-02
Threat Entry Updated 2025-01-08

CVE-2024-1567 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on the affected site's server which may make cross-site scripting or remote code execution possible.

PLUGIN Royal Elementor Addons

CVE-2024-1567

HIGH CVSS 8.2 2024-05-02
Threat Entry Updated 2025-01-30

CVE-2024-1173 - Wp Erp Plugin

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.13.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with accounting manager or admin access, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Erp

CVE-2024-1173

HIGH CVSS 7.2 2024-05-02
Threat Entry Updated 2025-05-22

CVE-2023-7064 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.15.2 via deserialization of untrusted input from the vulnerable 'id' parameter in the 'auxin_template_control_importer' function. This makes it possible for authenticated attackers able to upload a separate PHAR payload as an image file to inject a PHP Object, though the action itself is available to subscribers. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or…

PLUGIN Auxin Elements

CVE-2023-7064

HIGH CVSS 7.5 2024-05-02
Threat Entry Updated 2025-02-06

CVE-2023-6961 - Wp Meta Seo Plugin

The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Referer’ header in all versions up to, and including, 4.5.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Meta Seo

CVE-2023-6961

HIGH CVSS 7.2 2024-05-02
Threat Entry Updated 2025-01-28

CVE-2023-6214 - Ht Mega For Elementor Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order data including products and customer PII.

PLUGIN Ht Mega For Elementor

CVE-2023-6214

HIGH CVSS 7.5 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-3476 - Side Menu Lite Plugin

The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

PLUGIN Side Menu Lite

CVE-2024-3476

HIGH CVSS 8.8 2024-05-02
Threat Entry Updated 2025-03-25

CVE-2024-3474 - Wow Skype Buttons Plugin

The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

PLUGIN Wow Skype Buttons

CVE-2024-3474

HIGH CVSS 8.8 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-3475 - Sticky Buttons Plugin

The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

PLUGIN Sticky Buttons

CVE-2024-3475

HIGH CVSS 7.5 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-2663 - Zd Youtube Flv Player Plugin

The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.6 via the $_GET['image'] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Zd Youtube Flv Player

CVE-2024-2663

HIGH CVSS 8.3 2024-04-30
Threat Entry Updated 2024-11-21

CVE-2024-4185 - Customer Email Verification For Woocommerce Plugin

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification, and if both the "Login the user automatically after the account is verified" and "Verify account for current users" options are checked, then it potentially makes it possible for attackers to bypass authentication for other users.

PLUGIN Customer Email Verification For Woocommerce

CVE-2024-4185

HIGH CVSS 8.1 2024-04-30
Threat Entry Updated 2025-06-05

CVE-2024-1895 - Event Monster Plugin

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.4 via deserialization via shortcode of untrusted input from a custom meta value. This makes it possible for authenticated attackers, with contributor access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary…

PLUGIN Event Monster

CVE-2024-1895

HIGH CVSS 7.5 2024-04-30
Threat Entry Updated 2025-05-08

CVE-2024-2505 - Enabling Unauthorized Users To Modify Critical Gamipress Plugin

The GamiPress WordPress plugin before 6.8.9's access control mechanism fails to properly restrict access to its settings, permitting Authors to manipulate requests and extend access to lower privileged users, like Subscribers, despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical GamiPress WordPress plugin before 6.8.9 configurations.

PLUGIN Enabling Unauthorized Users To Modify Critical Gamipress

CVE-2024-2505

HIGH CVSS 8.1 2024-04-29
Threat Entry Updated 2024-11-21

CVE-2024-1789 - Wp Smtp Plugin

The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Smtp

CVE-2024-1789

HIGH CVSS 7.2 2024-04-26
Threat Entry Updated 2025-06-10

CVE-2024-3075 - Mm Email2image Plugin

The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Mm Email2image

CVE-2024-3075

HIGH CVSS 8.1 2024-04-26
Threat Entry Updated 2024-11-21

CVE-2024-3293 - rtMedia for WordPress, BuddyPress and bbPress Plugin

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtmedia_gallery shortcode in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN rtMedia for WordPress, BuddyPress and bbPress

CVE-2024-3293

HIGH CVSS 8.8 2024-04-23
Threat Entry Updated 2024-11-21

CVE-2024-32694 - Allows Reflected Xss Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interactive media 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin allows Reflected XSS.This issue affects 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin: from n/a through 3.62.

PLUGIN Allows Reflected Xss

CVE-2024-32694

HIGH CVSS 7.1 2024-04-22
Threat Entry Updated 2025-05-28

CVE-2024-3600 - Poll Maker Plugin

The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJAX action in addition to insufficient escaping and sanitization in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to create quizzes and inject malicious web scripts into them that execute when a user visits the page.

PLUGIN Poll Maker

CVE-2024-3600

HIGH CVSS 7.2 2024-04-19
Threat Entry Updated 2024-11-21

CVE-2024-32585 - WooCommerce Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendWP Import Content in WordPress & WooCommerce with Excel allows Reflected XSS.This issue affects Import Content in WordPress & WooCommerce with Excel: from n/a through 4.2.

PLUGIN WooCommerce

CVE-2024-32585

HIGH CVSS 7.1 2024-04-18
Scroll to top