Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 6301-6320 of 10866 records
Threat Entry Updated 2024-11-21

CVE-2024-5419 - Void Contact Form 7 Widget For Elementor Page Builder Plugin

The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cf7_redirect_page' attribute within the plugin's Void Contact From 7 widget in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Void Contact Form 7 Widget For Elementor Page Builder

CVE-2024-5419

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-12-26

CVE-2024-5938 - Boot Store Plugin

The Boot Store theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Boot Store

CVE-2024-5938

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-39310 - Basil Recipe Theme

The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` parameter in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. Because the of the default WordPress validation, it is not possible to insert the payload directly but if the Cooked plugin is installed, it is possible to create a recipe post…

THEME Basil Recipe

CVE-2024-39310

MEDIUM CVSS 5.4 2024-07-01
Threat Entry Updated 2025-05-01

CVE-2024-4934 - Before 9 Plugin

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 9

CVE-2024-4934

MEDIUM CVSS 5.5 2024-07-01
Threat Entry Updated 2025-05-01

CVE-2024-6130 - Form Maker By 10web Plugin

The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Form Maker By 10web

CVE-2024-6130

MEDIUM CVSS 4.8 2024-07-01
Threat Entry Updated 2024-11-21

CVE-2023-4017 - Goya Theme

The Goya theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attra-color’, 'attra-size', and 'product-cata' parameters in versions up to, and including, 1.0.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Goya

CVE-2023-4017

MEDIUM CVSS 6.1 2024-06-29
Threat Entry Updated 2025-02-07

CVE-2024-5819 - Gutenberg Blocks With Ai Plugin

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data attributes in all versions up to, and including, 3.2.45 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Blocks With Ai

CVE-2024-5819

MEDIUM CVSS 6.4 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-6363 - Stock Ticker Plugin

The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortcode in all versions up to, and including, 3.24.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Stock Ticker

CVE-2024-6363

MEDIUM CVSS 6.4 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-5790 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Happy Addons For Elementor

CVE-2024-5790

MEDIUM CVSS 6.4 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-5666 - Extensions For Elementor Plugin

The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the EE Button widget in all versions up to, and including, 2.0.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Extensions For Elementor

CVE-2024-5666

MEDIUM CVSS 6.4 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-5889 - Events Manager Plugin

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Events Manager

CVE-2024-5889

MEDIUM CVSS 6.1 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-5942 - Page And Post Clone Plugin

The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'content_clone' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to clone and read private posts.

PLUGIN Page And Post Clone

CVE-2024-5942

MEDIUM CVSS 4.3 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-5192 - Funnel Builder Plugin

The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mimes’ parameter in all versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Funnel Builder

CVE-2024-5192

MEDIUM CVSS 6.4 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-6405 - Floating Social Buttons Plugin

The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the floating_social_buttons_option() function. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Floating Social Buttons

CVE-2024-6405

MEDIUM CVSS 6.1 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-5925 - Theron Lite Theme

The Theron Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Theron Lite

CVE-2024-5925

MEDIUM CVSS 6.4 2024-06-28
Threat Entry Updated 2024-11-21

CVE-2024-5922 - Scylla Lite Theme

The Scylla lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Scylla Lite

CVE-2024-5922

MEDIUM CVSS 6.4 2024-06-28
Threat Entry Updated 2024-11-21

CVE-2024-5662 - Ultimate Post Kit Plugin

The Ultimate Post Kit Addons For Elementor – (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the Social Count (Static) widget in all versions up to, and including, 3.11.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Post Kit

CVE-2024-5662

MEDIUM CVSS 6.4 2024-06-28
Threat Entry Updated 2024-11-21

CVE-2024-5424 - Simply Gallery Block Plugin

The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘galleryID’ and 'className' parameters in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simply Gallery Block

CVE-2024-5424

MEDIUM CVSS 6.4 2024-06-28
Threat Entry Updated 2025-07-01

CVE-2024-6288 - Enhanced E Commerce For Woocommerce Store Plugin

The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tiktok_user_id’ parameter in all versions up to, and including, 7.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Enhanced E Commerce For Woocommerce Store

CVE-2024-6288

MEDIUM CVSS 4.7 2024-06-28
Threat Entry Updated 2024-11-21

CVE-2024-5796 - Infinite Theme

The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘project_url’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Infinite

CVE-2024-5796

MEDIUM CVSS 6.4 2024-06-28
Scroll to top