Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 3961-3980 of 10866 records
Threat Entry Updated 2025-03-06

CVE-2025-0801 - Ratemyagent Plugin

The RateMyAgent Official plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing or incorrect nonce validation on the 'rma-settings-wizard'. This makes it possible for unauthenticated attackers to update the plugin's API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ratemyagent

CVE-2025-0801

MEDIUM CVSS 4.3 2025-02-28
Threat Entry Updated 2025-03-06

CVE-2024-13796 - Post Grid Plugin

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.6 via the /wp-json/post-grid/v2/get_users REST API This makes it possible for unauthenticated attackers to extract sensitive data including including emails and other user data.

PLUGIN Post Grid

CVE-2024-13796

MEDIUM CVSS 5.3 2025-02-28
Threat Entry Updated 2025-02-28

CVE-2025-1681 - Car Dealer Automotive WordPress Theme – Responsive

The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to change or delete arbitrary css and js files.

THEME Car Dealer Automotive WordPress Theme – Responsive

CVE-2025-1681

MEDIUM CVSS 5.4 2025-02-28
Threat Entry Updated 2025-05-24

CVE-2024-13402 - Buddyboss Platform Plugin

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Buddyboss Platform

CVE-2024-13402

MEDIUM CVSS 6.4 2025-02-27
Threat Entry Updated 2025-03-25

CVE-2024-13217 - Jeg Elementor Kit Plugin

The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.

PLUGIN Jeg Elementor Kit

CVE-2024-13217

MEDIUM CVSS 4.3 2025-02-27
Threat Entry Updated 2025-03-11

CVE-2025-1450 - Floating Chat Widget Plugin

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-hover’ parameter in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Floating Chat Widget

CVE-2025-1450

MEDIUM CVSS 6.4 2025-02-27
Threat Entry Updated 2025-03-11

CVE-2024-13734 - Card Elements For Elementor Plugin

The Card Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Profile Card widget in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Card Elements For Elementor

CVE-2024-13734

MEDIUM CVSS 6.4 2025-02-27
Threat Entry Updated 2025-03-11

CVE-2025-1690 - Stripe Checkout Plugin

The ThemeMakers Stripe Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stripe' shortcode in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Stripe Checkout

CVE-2025-1690

MEDIUM CVSS 6.4 2025-02-27
Threat Entry Updated 2025-03-11

CVE-2025-1689 - Paypal Checkout Plugin

The ThemeMakers PayPal Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Paypal Checkout

CVE-2025-1689

MEDIUM CVSS 6.4 2025-02-27
Threat Entry Updated 2025-03-11

CVE-2024-13907 - Total Upkeep Plugin

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.16.8 via the 'download' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Total Upkeep

CVE-2024-13907

MEDIUM CVSS 4.9 2025-02-27
Threat Entry Updated 2025-03-11

CVE-2024-6261 - Image Photo Gallery Final Tiles Grid Plugin

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'FinalTilesGallery' shortcode in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Image Photo Gallery Final Tiles Grid

CVE-2024-6261

MEDIUM CVSS 6.4 2025-02-27
Threat Entry Updated 2025-03-11

CVE-2025-0469 - Forminator Forms Plugin

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider template data in all versions up to, and including, 1.39.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Forminator Forms

CVE-2025-0469

MEDIUM CVSS 6.4 2025-02-27
Threat Entry Updated 2025-03-12

CVE-2024-13905 - Onestore Sites Plugin

The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.1.1 via the class-export.php file. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Onestore Sites

CVE-2024-13905

MEDIUM CVSS 5.3 2025-02-27
Threat Entry Updated 2025-03-21

CVE-2024-13647 - Sakolawp Plugin

The School Management System – SakolaWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on the 'save_exam_setting' and 'delete_exam_setting' actions. This makes it possible for unauthenticated attackers to update exam settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Sakolawp

CVE-2024-13647

MEDIUM CVSS 4.3 2025-02-27
Threat Entry Updated 2025-03-24

CVE-2025-1517 - Sina Extension For Elementor Plugin

The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text, Countdown Widget, and Login Form shortcodes in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sina Extension For Elementor

CVE-2025-1517

MEDIUM CVSS 6.4 2025-02-26
Threat Entry Updated 2025-02-26

CVE-2024-6810 - Quiz Organizer Plugin

The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Quiz Organizer

CVE-2024-6810

MEDIUM CVSS 4.4 2025-02-26
Threat Entry Updated 2025-04-10

CVE-2024-13803 - Essential Blocks Plugin

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-marker’ parameter in all versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Blocks

CVE-2024-13803

MEDIUM CVSS 6.4 2025-02-26
Threat Entry Updated 2025-05-20

CVE-2024-13678 - R3w Instafeed Plugin

The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN R3w Instafeed

CVE-2024-13678

MEDIUM CVSS 6.1 2025-02-26
Threat Entry Updated 2026-01-09

CVE-2024-13669 - Calendapp Plugin

The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Calendapp

CVE-2024-13669

MEDIUM CVSS 6.1 2025-02-26
Threat Entry Updated 2025-05-20

CVE-2024-13634 - Post Sync Plugin

The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Post Sync

CVE-2024-13634

MEDIUM CVSS 6.1 2025-02-26
Scroll to top