Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,044
Critical0
High3,044
Medium0
Reset
Showing 1401-1420 of 3044 records
Threat Entry Updated 2025-02-14

CVE-2025-23428 - QMean – WordPress Did You Mean Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound QMean – WordPress Did You Mean allows Reflected XSS. This issue affects QMean – WordPress Did You Mean: from n/a through 2.0.

PLUGIN QMean – WordPress Did You Mean

CVE-2025-23428

HIGH CVSS 7.1 2025-02-14
Threat Entry Updated 2025-02-18

CVE-2024-13606 - Js Help Desk Plugin

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/jssupportticketdata directory which can contain file attachments included in support tickets.

PLUGIN Js Help Desk

CVE-2024-13606

HIGH CVSS 7.5 2025-02-13
Threat Entry Updated 2025-02-24

CVE-2024-13346 - Avada Plugin

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Avada

CVE-2024-13346

HIGH CVSS 7.3 2025-02-13
Threat Entry Updated 2025-04-14

CVE-2024-13345 - Avada Builder Plugin

The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Avada Builder

CVE-2024-13345

HIGH CVSS 7.3 2025-02-13
Threat Entry Updated 2025-02-24

CVE-2024-13770 - Puzzles Plugin

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.4 via deserialization of untrusted input 'view_more_posts' AJAX action. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional…

PLUGIN Puzzles

CVE-2024-13770

HIGH CVSS 8.1 2025-02-13
Threat Entry Updated 2025-02-25

CVE-2024-13532 - Small Package Quotes Plugin

The Small Package Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Small Package Quotes

CVE-2024-13532

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-20

CVE-2025-0511 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 2.11.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Welcart E Commerce

CVE-2025-0511

HIGH CVSS 7.2 2025-02-12
Threat Entry Updated 2025-02-20

CVE-2024-12386 - Wp Abstracts Plugin

The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.3. This is due to missing nonce validation on multiple functions. This makes it possible for unauthenticated attackers to delete arbitrary accounts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Abstracts

CVE-2024-12386

HIGH CVSS 8.1 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13480 - Ltl Freight Quotes Plugin

The LTL Freight Quotes – For Customers of FedEx Freight plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ltl Freight Quotes

CVE-2024-13480

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13477 - Ltl Freight Quotes Plugin

The LTL Freight Quotes – Unishippers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 2.5.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ltl Freight Quotes

CVE-2024-13477

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-20

CVE-2024-13531 - Shipengine Shipping Quotes Plugin

The ShipEngine Shipping Quotes plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Shipengine Shipping Quotes

CVE-2024-13531

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-18

CVE-2024-13528 - Customer Email Verification For Woocommerce Plugin

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with a placeholder email. This makes it possible for authenticated attackers, with Contributor-level access and above, to generate a verification link for any unverified user and log into the account. The 'Fine tune placement' option must be enabled in the plugin settings in order to exploit the vulnerability.

PLUGIN Customer Email Verification For Woocommerce

CVE-2024-13528

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13490 - Ltl Freight Quotes Plugin

The LTL Freight Quotes – XPO Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ltl Freight Quotes

CVE-2024-13490

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13475 - Small Package Quotes Plugin

The Small Package Quotes – UPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 4.5.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Small Package Quotes

CVE-2024-13475

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-03-11

CVE-2024-13473 - Ltl Freight Quotes Plugin

The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameter in all versions up to, and including, 5.0.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ltl Freight Quotes

CVE-2024-13473

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-20

CVE-2024-12296 - Superio Plugin

The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'import_page_options' function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

PLUGIN Superio

CVE-2024-12296

HIGH CVSS 8.8 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13435 - Ebook Downloader Plugin

The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ebook Downloader

CVE-2024-13435

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-12315 - Export All Posts Products Orders Refunds Users Plugin

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/smack_uci_uploads/exports/ directory which can contain information like exported user data.

PLUGIN Export All Posts Products Orders Refunds Users

CVE-2024-12315

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-12

CVE-2024-13714 - Ia Image Bank And Custom Image Creation Plugin

The All-Images.ai – IA Image Bank and Custom Image creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_get_image_by_url' function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Ia Image Bank And Custom Image Creation

CVE-2024-13714

HIGH CVSS 8.8 2025-02-12
Threat Entry Updated 2025-02-24

CVE-2024-13600 - Majestic Support Plugin

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the 'majesticsupportdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/majesticsupportdata directory which can contain file attachments included in support tickets.

PLUGIN Majestic Support

CVE-2024-13600

HIGH CVSS 7.5 2025-02-12
Scroll to top