Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 4461-4480 of 10866 records
Threat Entry Updated 2025-08-12

CVE-2024-13323 - Wp Booking Calendar Plugin

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Booking Calendar

CVE-2024-13323

MEDIUM CVSS 6.4 2025-01-14
Threat Entry Updated 2025-06-05

CVE-2024-11396 - Event Monster Plugin

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.

PLUGIN Event Monster

CVE-2024-11396

MEDIUM CVSS 5.3 2025-01-14
Threat Entry Updated 2025-05-08

CVE-2024-12568 - Email Subscribers By Icegram Express Plugin

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workflow settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Email Subscribers By Icegram Express

CVE-2024-12568

MEDIUM CVSS 4.8 2025-01-13
Threat Entry Updated 2025-05-08

CVE-2024-12567 - Email Subscribers By Icegram Express Plugin

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Email Subscribers By Icegram Express

CVE-2024-12567

MEDIUM CVSS 4.8 2025-01-13
Threat Entry Updated 2025-05-08

CVE-2024-12566 - Email Subscribers By Icegram Express Plugin

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Email Subscribers By Icegram Express

CVE-2024-12566

MEDIUM CVSS 4.8 2025-01-13
Threat Entry Updated 2025-05-08

CVE-2024-11636 - Email Subscribers By Icegram Express Plugin

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Text Block options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Email Subscribers By Icegram Express

CVE-2024-11636

MEDIUM CVSS 4.8 2025-01-13
Threat Entry Updated 2025-01-11

CVE-2024-12527 - Perfect Portal Widgets Plugin

The Perfect Portal Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'perfect_portal_intake_form' shortcode in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Perfect Portal Widgets

CVE-2024-12527

MEDIUM CVSS 6.4 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-12520 - Dominion Domain Checker Wpbakery Addon Plugin

The Dominion – Domain Checker for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dominion_shortcodes_domain_search_6' shortcode in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Dominion Domain Checker Wpbakery Addon

CVE-2024-12520

MEDIUM CVSS 6.4 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-12519 - Tcbd Auto Refresher Plugin

The TCBD Auto Refresher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd_auto_refresh' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tcbd Auto Refresher

CVE-2024-12519

MEDIUM CVSS 6.4 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-12412 - Booking And Rental Manager For Woocommerce Plugin

The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘active_tab’ parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Booking And Rental Manager For Woocommerce

CVE-2024-12412

MEDIUM CVSS 6.1 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-12407 - Push Notification For Post And Buddypress Plugin

The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pushnotificationid' parameter in all versions up to, and including, 2.06 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Push Notification For Post And Buddypress

CVE-2024-12407

MEDIUM CVSS 6.1 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-11892 - Accordion Slider Lite Plugin

The Accordion Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordion_slider' shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Accordion Slider Lite

CVE-2024-11892

MEDIUM CVSS 6.4 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-11874 - Grid Accordion Lite Plugin

The Grid Accordion Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'grid_accordion' shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Grid Accordion Lite

CVE-2024-11874

MEDIUM CVSS 6.4 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-11758 - Wp Spid Italia Plugin

The WP SPID Italia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Spid Italia

CVE-2024-11758

MEDIUM CVSS 6.4 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-12116 - Unlimited Theme Addons Plugin

The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.1 via the 'uta-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.

PLUGIN Unlimited Theme Addons

CVE-2024-12116

MEDIUM CVSS 4.3 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-11915 - Rrdevs For Elementor Plugin

The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.0 via the Popup block due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts that they should not have access to.

PLUGIN Rrdevs For Elementor

CVE-2024-11915

MEDIUM CVSS 4.3 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-11386 - Gatormail Smart Forms Plugin

The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsmartform' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gatormail Smart Forms

CVE-2024-11386

MEDIUM CVSS 6.4 2025-01-11
Threat Entry Updated 2025-05-17

CVE-2024-12587 - Contact Form Master Plugin

The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Contact Form Master

CVE-2024-12587

MEDIUM CVSS 6.1 2025-01-11
Threat Entry Updated 2025-02-07

CVE-2024-12304 - Gutenberg Blocks With Ai Plugin

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via button block link in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Blocks With Ai

CVE-2024-12304

MEDIUM CVSS 6.4 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-12505 - Trackserver Plugin

The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Trackserver

CVE-2024-12505

MEDIUM CVSS 6.4 2025-01-11
Scroll to top