Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 5521-5540 of 10866 records
Threat Entry Updated 2024-10-17

CVE-2024-9944 - Woocommerce Plugin

The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views order form submissions.

PLUGIN Woocommerce

CVE-2024-9944

MEDIUM CVSS 5.3 2024-10-15
Threat Entry Updated 2024-10-19

CVE-2024-9820 - Wp 2fa With Telegram Plugin

The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.

PLUGIN Wp 2fa With Telegram

CVE-2024-9820

MEDIUM CVSS 6.5 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-6757 - Website Builder Plugin

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.

PLUGIN Website Builder

CVE-2024-6757

MEDIUM CVSS 4.3 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-9546 - Wpide Plugin

The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution results. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Wpide

CVE-2024-9546

MEDIUM CVSS 5.3 2024-10-15
Threat Entry Updated 2025-01-16

CVE-2024-8902 - Elementor Addon Elements Plugin

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function in modules/data-table/widgets/data-table.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

PLUGIN Elementor Addon Elements

CVE-2024-8902

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9696 - Rescue Shortcodes Plugin

The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' shortcode in all versions up to, and including, 2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rescue Shortcodes

CVE-2024-9696

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2025-08-09

CVE-2024-9595 - Tablepress Plugin

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tablepress

CVE-2024-9595

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-8915 - Category Icon Plugin

The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Category Icon

CVE-2024-8915

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-8760 - Page Builder Gutenberg Blocks Plugin

The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes it possible for unauthenticated attackers to embed untrusted style information into comments resulting in a possibility of data exfiltration such as admin nonces with limited impact. These nonces could be used to perform CSRF attacks within a limited time window. The presence of other plugins may make additional nonces available, which may pose a risk in plugins that don't perform capability checks to protect AJAX…

PLUGIN Page Builder Gutenberg Blocks

CVE-2024-8760

MEDIUM CVSS 5.3 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9704 - Social Sharing Plugin

The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Social Sharing

CVE-2024-9704

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9756 - Order Attachments For Woocommerce Plugin

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload limited file types.

PLUGIN Order Attachments For Woocommerce

CVE-2024-9756

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9824 - Image Gallery Plugin

The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'ip_delete_post' and 'ip_update_post_title' functions in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts and update post titles.

PLUGIN Image Gallery

CVE-2024-9824

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9656 - Mynx Page Builder Plugin

The Mynx Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Mynx Page Builder

CVE-2024-9656

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9670 - 2d Tag Cloud Widget By Sujin Plugin

The 2D Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 6.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN 2d Tag Cloud Widget By Sujin

CVE-2024-9670

MEDIUM CVSS 6.1 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9776 - Imagepress Plugin

The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Imagepress

CVE-2024-9776

MEDIUM CVSS 4.4 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9778 - Imagepress Plugin

The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the 'imagepress_admin_page' function. This makes it possible for unauthenticated attackers to update plugin settings, including redirection URLs, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Imagepress

CVE-2024-9778

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-16

CVE-2024-7489 - Mailchimp Wp Plugin

The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form color parameters in all versions up to, and including, 2.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mailchimp Wp

CVE-2024-7489

MEDIUM CVSS 4.4 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9187 - Read More Plugin

The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteRm() function in all versions up to, and including, 1.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete read more buttons.

PLUGIN Read More

CVE-2024-9187

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9860 - Bridge Core Plugin

The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level permissions or above, to delete or change plugin settings, import demo data, and install limited plugins.

PLUGIN Bridge Core

CVE-2024-9860

MEDIUM CVSS 6.5 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9592 - Paypal Gift Certificate Plugin

The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the 'wpppgc_plugin_options' function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious JavaScript via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Paypal Gift Certificate

CVE-2024-9592

MEDIUM CVSS 6.1 2024-10-12
Scroll to top