Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,044
Critical0
High3,044
Medium0
Reset
Showing 1481-1500 of 3044 records
Threat Entry Updated 2025-02-05

CVE-2024-13408 - Post Grid Plugin

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 via the 'theme' attribute of the `pgcu` shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php…

PLUGIN Post Grid

CVE-2024-13408

HIGH CVSS 7.5 2025-01-24
Threat Entry Updated 2025-02-04

CVE-2024-13234 - Product Table Plugin

The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in all versions up to, and including, 2.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Product Table

CVE-2024-13234

HIGH CVSS 7.5 2025-01-23
Threat Entry Updated 2025-02-04

CVE-2024-13593 - Meeting Map Plugin

The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.0 via the 'bmlt_meeting_map' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Meeting Map

CVE-2024-13593

HIGH CVSS 7.5 2025-01-23
Threat Entry Updated 2025-01-22

CVE-2025-23867 - WordPress File Search Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WordPress File Search allows Reflected XSS. This issue affects WordPress File Search: from n/a through 1.2.

PLUGIN WordPress File Search

CVE-2025-23867

HIGH CVSS 7.1 2025-01-22
Threat Entry Updated 2025-01-22

CVE-2025-23535 - REAL WordPress Sidebar Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in clickandsell REAL WordPress Sidebar allows Stored XSS. This issue affects REAL WordPress Sidebar: from n/a through 0.1.

PLUGIN REAL WordPress Sidebar

CVE-2025-23535

HIGH CVSS 7.1 2025-01-22
Threat Entry Updated 2025-03-24

CVE-2024-13496 - Gamipress Plugin

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NOTE: This vulnerability was previously published as being fixed…

PLUGIN Gamipress

CVE-2024-13496

HIGH CVSS 7.5 2025-01-22
Threat Entry Updated 2025-01-24

CVE-2024-13499 - Gamipress Plugin

The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_do_shortcode() function in all versions up to, and including, 7.2.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Gamipress

CVE-2024-13499

HIGH CVSS 7.3 2025-01-22
Threat Entry Updated 2025-01-24

CVE-2024-13495 - Gamipress Plugin

The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via the gamipress_ajax_get_logs() function in all versions up to, and including, 7.2.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Gamipress

CVE-2024-13495

HIGH CVSS 7.3 2025-01-22
Threat Entry Updated 2025-01-24

CVE-2025-0429 - Aipower Plugin

The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_ai_forms() function. This allows authenticated attackers, with administrative privileges, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Aipower

CVE-2025-0429

HIGH CVSS 7.2 2025-01-22
Threat Entry Updated 2025-01-24

CVE-2025-0428 - Aipower Plugin

The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_prompts function. This allows authenticated attackers, with administrative privileges, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Aipower

CVE-2025-0428

HIGH CVSS 7.2 2025-01-22
Threat Entry Updated 2025-01-21

CVE-2025-22735 - WordPress Tag Cloud Plugin – Tag Groups

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TaxoPress WordPress Tag Cloud Plugin – Tag Groups allows Reflected XSS. This issue affects WordPress Tag Cloud Plugin – Tag Groups: from n/a through 2.0.4.

PLUGIN WordPress Tag Cloud Plugin – Tag Groups

CVE-2025-22735

HIGH CVSS 7.1 2025-01-21
Threat Entry Updated 2025-01-21

CVE-2024-49333 - WordPress Core

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows SQL Injection. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5.

CORE WordPress Core

CVE-2024-49333

HIGH CVSS 8.5 2025-01-21
Threat Entry Updated 2025-01-21

CVE-2024-49303 - WordPress Core

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows SQL Injection. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5.

CORE WordPress Core

CVE-2024-49303

HIGH CVSS 8.5 2025-01-21
Threat Entry Updated 2025-01-21

CVE-2024-49300 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows Reflected XSS. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5.

CORE WordPress Core

CVE-2024-49300

HIGH CVSS 7.1 2025-01-21
Threat Entry Updated 2025-02-05

CVE-2024-10936 - String Locator Plugin

The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. An administrator must perform a search and…

PLUGIN String Locator

CVE-2024-10936

HIGH CVSS 8.8 2025-01-21
Threat Entry Updated 2025-01-18

CVE-2024-13184 - Wp Extended Plugin

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including, 3.0.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Extended

CVE-2024-13184

HIGH CVSS 7.5 2025-01-18
Threat Entry Updated 2025-02-25

CVE-2025-0308 - Ultimate Member Plugin

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ultimate Member

CVE-2025-0308

HIGH CVSS 7.5 2025-01-18
Threat Entry Updated 2025-01-17

CVE-2024-13377 - Gravity Forms Plugin

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gravity Forms

CVE-2024-13377

HIGH CVSS 7.2 2025-01-17
Threat Entry Updated 2025-06-05

CVE-2024-13333 - Advanced File Manager Plugin

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above and upload permissions granted by an administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. The function can be exploited only if the "Display .htaccess?" setting is enabled.

PLUGIN Advanced File Manager

CVE-2024-13333

HIGH CVSS 7.5 2025-01-17
Threat Entry Updated 2025-01-16

CVE-2025-23913 - WordPress Google Map Professional Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pankajpragma, rahulpragma WordPress Google Map Professional allows SQL Injection.This issue affects WordPress Google Map Professional: from n/a through 1.0.

PLUGIN WordPress Google Map Professional

CVE-2025-23913

HIGH CVSS 8.5 2025-01-16
Scroll to top