Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,044
Critical0
High3,044
Medium0
Reset
Showing 1601-1620 of 3044 records
Threat Entry Updated 2024-12-04

CVE-2024-11643 - Allaccessible Plugin

The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'AllAccessible_save_settings' function in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

PLUGIN Allaccessible

CVE-2024-11643

HIGH CVSS 8.8 2024-12-04
Threat Entry Updated 2024-12-04

CVE-2024-11952 - Classic Addons Wpbakery Page Builder Addons Plugin

The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all versions up to, and including, 3.0 via the 'style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file…

PLUGIN Classic Addons Wpbakery Page Builder Addons

CVE-2024-11952

HIGH CVSS 7.5 2024-12-04
Threat Entry Updated 2024-12-04

CVE-2024-10567 - Ti Woocommerce Wishlist Plugin

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limited options updates.

PLUGIN Ti Woocommerce Wishlist

CVE-2024-10567

HIGH CVSS 7.5 2024-12-04
Threat Entry Updated 2024-12-04

CVE-2024-11293 - Content Restriction Social Sites Login Plugin

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.9. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for…

PLUGIN Content Restriction Social Sites Login

CVE-2024-11293

HIGH CVSS 8.1 2024-12-04
Threat Entry Updated 2024-12-04

CVE-2024-10587 - Funnelforms Free Plugin

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.7.4.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete…

PLUGIN Funnelforms Free

CVE-2024-10587

HIGH CVSS 8.8 2024-12-04
Threat Entry Updated 2024-12-04

CVE-2024-10952 - The Authors List Plugin

The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN The Authors List

CVE-2024-10952

HIGH CVSS 7.3 2024-12-04
Threat Entry Updated 2025-06-05

CVE-2024-11391 - Advanced File Manager Plugin

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Advanced File Manager

CVE-2024-11391

HIGH CVSS 7.5 2024-12-03
Threat Entry Updated 2024-12-02

CVE-2024-52461 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kinsta WordPress Hosting Infinite Slider allows Reflected XSS.This issue affects Infinite Slider: from n/a through 2.0.1.

CORE WordPress Core

CVE-2024-52461

HIGH CVSS 7.1 2024-12-02
Threat Entry Updated 2024-12-02

CVE-2024-12015 - WordPress Core

The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.

CORE WordPress Core

CVE-2024-12015

HIGH CVSS 7.7 2024-12-02
Threat Entry Updated 2025-02-10

CVE-2024-52481 - Jobify Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Astoundify Jobify - Job Board WordPress Theme allows Relative Path Traversal.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.

PLUGIN Jobify

CVE-2024-52481

HIGH CVSS 7.5 2024-11-28
Threat Entry Updated 2025-02-26

CVE-2024-8066 - Filester Plugin

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Filester

CVE-2024-8066

HIGH CVSS 7.5 2024-11-28
Threat Entry Updated 2026-01-23

CVE-2024-9669 - Filester Plugin

The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via the 'fm_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the server, allowing the execution of any code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The vulnerability was…

PLUGIN Filester

CVE-2024-9669

HIGH CVSS 7.2 2024-11-28
Threat Entry Updated 2025-05-22

CVE-2024-9461 - Total Upkeep Plugin

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

PLUGIN Total Upkeep

CVE-2024-9461

HIGH CVSS 7.2 2024-11-26
Threat Entry Updated 2024-11-26

CVE-2024-9504 - Appointment Booking System Plugin

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Appointment Booking System

CVE-2024-9504

HIGH CVSS 7.2 2024-11-26
Threat Entry Updated 2025-07-12

CVE-2024-10781 - Spam Protection Antispam Firewall Plugin

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

PLUGIN Spam Protection Antispam Firewall

CVE-2024-10781

HIGH CVSS 8.1 2024-11-26
Threat Entry Updated 2024-11-26

CVE-2024-10570 - Security Malware Firewall Plugin

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 2.145, as well as insufficient input sanitization and validation. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Security Malware Firewall

CVE-2024-10570

HIGH CVSS 7.5 2024-11-26
Threat Entry Updated 2024-11-26

CVE-2024-10729 - Appointment Plugin For Woocommerce

The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_google_calendar_data' function in versions up to, and including, 6.9.0. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily.

PLUGIN Appointment Plugin For Woocommerce

CVE-2024-10729

HIGH CVSS 8.8 2024-11-26
Threat Entry Updated 2024-11-23

CVE-2024-11034 - Get A Quote Button For Woocommerce Plugin

The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation plugin for WordPress is vulnerable to arbitrary shortcode execution via fire_contact_form AJAX action in all versions up to, and including, 1.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Get A Quote Button For Woocommerce

CVE-2024-11034

HIGH CVSS 7.3 2024-11-23
Threat Entry Updated 2024-11-26

CVE-2024-9941 - Wordpress Gym Management System Plugin

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new user accounts with the administrator role.

PLUGIN Wordpress Gym Management System

CVE-2024-9941

HIGH CVSS 8.8 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-9660 - School Management System Plugin

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_load_documets_new() and mj_smgt_load_documets() functions in all versions up to, and including, 91.5.0. This makes it possible for authenticated attackers, with Student-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN School Management System

CVE-2024-9660

HIGH CVSS 8.8 2024-11-23
Scroll to top