Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 4481-4500 of 10866 records
Threat Entry Updated 2025-06-05

CVE-2024-12472 - Post Duplicator Plugin

The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to by duplicating the post.

PLUGIN Post Duplicator

CVE-2024-12472

MEDIUM CVSS 5.3 2025-01-11
Threat Entry Updated 2025-01-11

CVE-2024-12204 - Woocommerce Popups Plugin

The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in the class-cx-rest.php file in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create 100% off coupons, delete posts, delete leads, and update coupon statuses.

PLUGIN Woocommerce Popups

CVE-2024-12204

MEDIUM CVSS 5.4 2025-01-11
Threat Entry Updated 2025-06-05

CVE-2024-11327 - Clickwhale Plugin

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Clickwhale

CVE-2024-11327

MEDIUM CVSS 6.1 2025-01-11
Threat Entry Updated 2025-02-25

CVE-2024-13318 - Essential Wp Real Estate Plugin

The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts.

PLUGIN Essential Wp Real Estate

CVE-2024-13318

MEDIUM CVSS 5.3 2025-01-10
Threat Entry Updated 2025-01-16

CVE-2024-13183 - Orbit Fox Plugin

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Orbit Fox

CVE-2024-13183

MEDIUM CVSS 6.4 2025-01-10
Threat Entry Updated 2025-01-16

CVE-2025-0311 - Orbit Fox Plugin

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Orbit Fox

CVE-2025-0311

MEDIUM CVSS 6.4 2025-01-10
Threat Entry Updated 2025-01-10

CVE-2024-12606 - Ai Scribe The Chatgpt Powered Seo Content Creation Wizard Plugin

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the engine_request_data() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin settings.

PLUGIN Ai Scribe The Chatgpt Powered Seo Content Creation Wizard

CVE-2024-12606

MEDIUM CVSS 4.3 2025-01-10
Threat Entry Updated 2025-01-10

CVE-2024-12473 - Ai Scribe The Chatgpt Powered Seo Content Creation Wizard Plugin

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to SQL Injection via the 'template_id' parameter of the 'article_builder_generate_data' shortcode in all versions up to, and including, 2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to…

PLUGIN Ai Scribe The Chatgpt Powered Seo Content Creation Wizard

CVE-2024-12473

MEDIUM CVSS 6.5 2025-01-10
Threat Entry Updated 2025-01-09

CVE-2025-22813 - Conversational Forms for ChatBot Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ChatBot for WordPress - WPBot Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.4.2.

PLUGIN Conversational Forms for ChatBot

CVE-2025-22813

MEDIUM CVSS 6.5 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2025-22802 - Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail allows Stored XSS.This issue affects Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail: from n/a through 2.1.4.

PLUGIN Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail

CVE-2025-22802

MEDIUM CVSS 6.5 2025-01-09
Threat Entry Updated 2025-06-05

CVE-2024-6155 - Greenshift Animation And Page Builder Blocks Plugin

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross Site Scripting in all versions up to, and including, 9.0.0 due to a missing capability check in the greenshift_download_file_localy function, along with no SSRF protection and sanitization on uploaded SVG files. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application that can also be leveraged to download malicious SVG files containing Cross-Site Scripting…

PLUGIN Greenshift Animation And Page Builder Blocks

CVE-2024-6155

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-5769 - Mimo Woocommerce Order Tracking Plugin

The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add, update, and delete shipper tracking settings.

PLUGIN Mimo Woocommerce Order Tracking

CVE-2024-5769

MEDIUM CVSS 4.3 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12819 - Searchie Plugin

The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortcode in all versions up to, and including, 1.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Searchie

CVE-2024-12819

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12621 - Yumpu Epaper Publishing Plugin

The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' shortcode in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Yumpu Epaper Publishing

CVE-2024-12621

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12618 - Newsletter2go Plugin

The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'resetStyles' AJAX action in all versions up to, and including, 4.0.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset styles.

PLUGIN Newsletter2go

CVE-2024-12618

MEDIUM CVSS 4.3 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12515 - Masjidal Plugin

The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Masjidal

CVE-2024-12515

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12514 - 3dvieweronline Wp Plugin

The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' shortcode in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN 3dvieweronline Wp

CVE-2024-12514

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12616 - Wp Bitly Plugin

The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 2.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update and retrieve plugin settings.

PLUGIN Wp Bitly

CVE-2024-12616

MEDIUM CVSS 4.3 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12605 - Ai Scribe The Chatgpt Powered Seo Content Creation Wizard Plugin

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the "al_scribe_content_data" actions. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ai Scribe The Chatgpt Powered Seo Content Creation Wizard

CVE-2024-12605

MEDIUM CVSS 4.3 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12496 - Linear Plugin

The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissions' shortcode in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Linear

CVE-2024-12496

MEDIUM CVSS 6.4 2025-01-09
Scroll to top