Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 5101-5120 of 10866 records
Threat Entry Updated 2025-07-12

CVE-2024-11188 - Formidable Forms Plugin

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Formidable Forms

CVE-2024-11188

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11426 - Autolisticle Automatically Update Numbered List Articles Plugin

The AutoListicle: Automatically Update Numbered List Articles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-list-number' shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Autolisticle Automatically Update Numbered List Articles

CVE-2024-11426

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11408 - Slotti Ajanvaraus Plugin

The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti' shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slotti Ajanvaraus

CVE-2024-11408

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11387 - Easy Liveblogs Plugin

The Easy Liveblogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elb_liveblog' shortcode in all versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Liveblogs

CVE-2024-11387

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11332 - Sign Hipaa Documents Plugin

The HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hipaatizer' shortcode in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sign Hipaa Documents

CVE-2024-11332

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11361 - Pdf Invoicing For Woocommerce Plugin

The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Pdf Invoicing For Woocommerce

CVE-2024-11361

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-10880 - Jobboardwp Plugin

The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Jobboardwp

CVE-2024-10880

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2025-02-11

CVE-2024-10606 - Wp Travel Engine Plugin

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpte_onboard_save_function_callback() function in all versions up to, and including, 6.2.1. This makes it possible for authenticated attackers, with contributor-level access and above, to modify several settings that could have an impact such as lost revenue and page updates.

PLUGIN Wp Travel Engine

CVE-2024-10606

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-9223 - Wpdash Notes Plugin

The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_ajax_post_it_list_comment' function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view comments on any post, including private and password protected posts, and pending and draft posts if they were previously published. The vulnerability was partially patched in version 1.3.5.

PLUGIN Wpdash Notes

CVE-2024-9223

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-10886 - Tribute Testimonial Gridslider Plugin

The Tribute Testimonials – WordPress Testimonial Grid/Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tribute_testimonials_slider' shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tribute Testimonial Gridslider

CVE-2024-10886

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-10874 - Quotes Llama Plugin

The Quotes llama plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quotes-llama' shortcode in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Quotes Llama

CVE-2024-10874

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11463 - Debounce Email Validator Plugin

The DeBounce Email Validator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'from', 'to', and 'key' parameters in all versions up to, and including, 5.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Debounce Email Validator

CVE-2024-11463

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11362 - Peachpay For Woocommerce Plugin

The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.112.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Peachpay For Woocommerce

CVE-2024-11362

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-10869 - Stop Brute Force Attacks Plugin

The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Stop Brute Force Attacks

CVE-2024-10869

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2025-07-15

CVE-2024-10116 - Twitter Follow Button Plugin

The Twitter Follow Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'username' parameter in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Twitter Follow Button

CVE-2024-10116

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-10813 - Woo Product Table Plugin

The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1 via the var_dump_table parameter. This makes it possible for unauthenticated attackers var data.

PLUGIN Woo Product Table

CVE-2024-10813

MEDIUM CVSS 5.3 2024-11-23
Threat Entry Updated 2025-01-23

CVE-2024-10868 - Enter Addons Plugin

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.9 via the Advanced Tabs widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.

PLUGIN Enter Addons

CVE-2024-10868

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2025-02-07

CVE-2024-10537 - Wp User Manager Plugin

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_user_meta_key() function in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate user meta keys.

PLUGIN Wp User Manager

CVE-2024-10537

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2025-02-07

CVE-2024-10216 - Wp User Manager Plugin

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add or remove a Carbon Fields custom sidebar if the Carbon Fields (carbon-fields) plugin is installed.

PLUGIN Wp User Manager

CVE-2024-10216

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2025-06-09

CVE-2024-9422 - Gmw Premium Settings Plugin

The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

PLUGIN Gmw Premium Settings

CVE-2024-9422

MEDIUM CVSS 6.6 2024-11-22
Scroll to top