Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 6121-6140 of 10866 records
Threat Entry Updated 2025-02-04

CVE-2024-6491 - Getwid Plugin

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to set the MailChimp API key.

PLUGIN Getwid

CVE-2024-6491

MEDIUM CVSS 4.3 2024-07-20
Threat Entry Updated 2025-02-04

CVE-2024-6489 - Getwid Plugin

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_google_api_key function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to set the MailChimp API key.

PLUGIN Getwid

CVE-2024-6489

MEDIUM CVSS 5.3 2024-07-20
Threat Entry Updated 2024-11-21

CVE-2024-3934 - Mercado Pago Payments For Woocommerce Plugin

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.1 via the mercadopagoDownloadLog function. This makes it possible for authenticated attackers, with subscriber-level access and above, to download and read the contents of arbitrary files on the server, which can contain sensitive information. The arbitrary file download was patched in 7.5.1, while the missing authorization was corrected in version 7.6.2.

PLUGIN Mercado Pago Payments For Woocommerce

CVE-2024-3934

MEDIUM CVSS 6.5 2024-07-20
Threat Entry Updated 2025-07-10

CVE-2024-2337 - Easy Testimonials Plugin

The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_grid ' shortcode in all versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Testimonials

CVE-2024-2337

MEDIUM CVSS 6.4 2024-07-20
Threat Entry Updated 2024-11-21

CVE-2024-6560 - Addonify Quick View Plugin

The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.16. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Addonify Quick View

CVE-2024-6560

MEDIUM CVSS 5.3 2024-07-20
Threat Entry Updated 2024-11-21

CVE-2024-5804 - Cf7 Conditional Fields Plugin

The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.13. This is due to missing or incorrect nonce validation on the wpcf7cf_admin_init function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Cf7 Conditional Fields

CVE-2024-5804

MEDIUM CVSS 4.3 2024-07-20
Threat Entry Updated 2024-11-21

CVE-2024-5977 - Givewp Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with GiveWP Worker-level access and above, to delete and update arbitrary posts.

PLUGIN Givewp

CVE-2024-5977

MEDIUM CVSS 5.4 2024-07-19
Threat Entry Updated 2024-11-21

CVE-2024-6799 - Yith Essential Kit For Woocommerce Plugin

The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_module', 'deactivate_module', and 'install_module' functions in all versions up to, and including, 2.34.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install, activate, and deactivate plugins from a pre-defined list of available YITH plugins.

PLUGIN Yith Essential Kit For Woocommerce

CVE-2024-6799

MEDIUM CVSS 4.3 2024-07-19
Threat Entry Updated 2025-05-16

CVE-2024-5604 - Before 2 Plugin

The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2024-5604

MEDIUM CVSS 5.9 2024-07-19
Threat Entry Updated 2025-05-16

CVE-2023-7268 - Before 2 Plugin

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets

PLUGIN Before 2

CVE-2023-7268

MEDIUM CVSS 6.5 2024-07-19
Threat Entry Updated 2024-11-21

CVE-2024-5997 - Custom Posts Or Users Plugin

The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_user and duplicate_post functions in all versions up to, and including, 0.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create duplicates of users and posts/pages.

PLUGIN Custom Posts Or Users

CVE-2024-5997

MEDIUM CVSS 4.3 2024-07-18
Threat Entry Updated 2025-01-16

CVE-2024-6455 - Elements Kit Elementor Addons Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, pending and private items.

PLUGIN Elements Kit Elementor Addons

CVE-2024-6455

MEDIUM CVSS 5.3 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-5555 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘social-link-title’ parameter in all versions up to, and including, 5.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-5555

MEDIUM CVSS 6.4 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-5554 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘onclick_event’ parameter in all versions up to, and including, 5.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-5554

MEDIUM CVSS 6.4 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2023-6708 - Svg Support Plugin

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping, even when the 'Sanitize SVG while uploading' feature is enabled. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that successful exploitation of this vulnerability requires the administrator to allow author-level users to upload SVG files.

PLUGIN Svg Support

CVE-2023-6708

MEDIUM CVSS 5.4 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-6705 - Reglevel Plugin

The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Reglevel

CVE-2024-6705

MEDIUM CVSS 5.5 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-6175 - Booking Ultra Pro Plugin

The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions in all versions up to, and including, 1.1.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify and delete. multiple plugin options and data such as payments, pricing, booking information, business hours, calendars, profile information, and email templates.

PLUGIN Booking Ultra Pro

CVE-2024-6175

MEDIUM CVSS 5.4 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-6599 - Meks Video Importer Plugin

The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capability check on the ajax_save_settings function in all versions up to, and including, 1.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's API keys

PLUGIN Meks Video Importer

CVE-2024-6599

MEDIUM CVSS 4.3 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-5964 - Zenon Lite Theme

The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Zenon Lite

CVE-2024-5964

MEDIUM CVSS 6.4 2024-07-18
Threat Entry Updated 2025-02-10

CVE-2024-39682 - Cooked Plugin

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary HTML in pages that will be shown whenever a user accesses a compromised page. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

PLUGIN Cooked

CVE-2024-39682

MEDIUM CVSS 6.4 2024-07-18
Scroll to top