Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 6641-6660 of 10866 records
Threat Entry Updated 2025-01-15

CVE-2024-4205 - Premium Addons For Elementor Plugin

The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content() function in all versions up to, and including, 4.10.31. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve Elementor template data.

PLUGIN Premium Addons For Elementor

CVE-2024-4205

MEDIUM CVSS 4.3 2024-05-31
Threat Entry Updated 2025-03-24

CVE-2024-5418 - Dethemekit For Elementor

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide widget in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Dethemekit For Elementor

CVE-2024-5418

MEDIUM CVSS 6.4 2024-05-31
Threat Entry Updated 2024-11-21

CVE-2024-3583 - Simple Like Page Plugin

The Simple Like Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Like Page

CVE-2024-3583

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-4668 - Gum Elementor Addon Plugin

The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Price Table and Post Slider widgets in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gum Elementor Addon

CVE-2024-4668

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2025-02-12

CVE-2024-4422 - Comparison Slider Plugin

The Comparison Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider title parameter in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Comparison Slider

CVE-2024-4422

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2025-02-12

CVE-2024-4427 - Comparison Slider Plugin

The Comparison Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 1.0.5. This makes it possible for authenticated attackers, with subscriber access or above, to change plugin settings and perform other actions such deleting sliders.

PLUGIN Comparison Slider

CVE-2024-4427

MEDIUM CVSS 4.3 2024-05-30
Threat Entry Updated 2025-02-12

CVE-2024-4426 - Comparison Slider Plugin

The Comparison Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on several functions hooked to AJAX actions. This makes it possible for unauthenticated attackers to change slider titles, delete sliders and modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Comparison Slider

CVE-2024-4426

MEDIUM CVSS 4.3 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-2089 - Remote Content Shortcode Plugin

The Remote Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'remote_content' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Remote Content Shortcode

CVE-2024-2089

MEDIUM CVSS 5.4 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-2657 - Font Farsi Plugin

The Font Farsi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Font Farsi

CVE-2024-2657

MEDIUM CVSS 4.4 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-4355 - Stopbadbots Plugin

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stopbadbots_get_ajax_data() function in all versions up to, and including, 10.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose visitor data.

PLUGIN Stopbadbots

CVE-2024-4355

MEDIUM CVSS 4.3 2024-05-30
Threat Entry Updated 2025-01-15

CVE-2024-5327 - Powerpack Addons For Elementor Plugin

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘pp_animated_gradient_bg_color’ parameter in all versions up to, and including, 2.7.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Powerpack Addons For Elementor

CVE-2024-5327

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2025-01-15

CVE-2024-5073 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Feed component in all versions up to, and including, 5.9.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2024-5073

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2025-01-29

CVE-2024-5341 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' attribute of the Heading Title widget in all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2024-5341

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-4218 - Affieasy Plugin

The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.7. This is due to plugin improperly releasing the tagged and patched version of the plugin - the vulnerable version is used as the core files, while the patched version was included in a 'trunk' folder. This makes it possible for unauthenticated attackers to perform a variety of actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Affieasy

CVE-2024-4218

MEDIUM CVSS 6.5 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-4356 - List Categories Plugin

The List categories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'categories' shortcode in all versions up to, and including, 0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN List Categories

CVE-2024-4356

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-3277 - Yumpu Epaper Publishing Plugin

The Yumpu ePaper publishing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in all versions up to, and including, 2.0.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload PDF files and publish them, as well as modify the API key.

PLUGIN Yumpu Epaper Publishing

CVE-2024-3277

MEDIUM CVSS 5.0 2024-05-30
Threat Entry Updated 2025-02-12

CVE-2024-3946 - Wp To Do Plugin

The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Wp To Do

CVE-2024-3946

MEDIUM CVSS 4.4 2024-05-30
Threat Entry Updated 2025-02-12

CVE-2024-3947 - Wp To Do Plugin

The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.0. This is due to missing or incorrect nonce validation on the wptodo_settings() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp To Do

CVE-2024-3947

MEDIUM CVSS 4.3 2024-05-30
Threat Entry Updated 2025-02-12

CVE-2024-3945 - Wp To Do Plugin

The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.0. This is due to missing or incorrect nonce validation on the wptodo_manage() function. This makes it possible for unauthenticated attackers to add new todo items via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp To Do

CVE-2024-3945

MEDIUM CVSS 4.3 2024-05-30
Threat Entry Updated 2025-02-12

CVE-2024-3943 - Wp To Do Plugin

The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.0. This is due to missing or incorrect nonce validation on the wptodo_addcomment function. This makes it possible for unauthenticated attackers to add comments to to do items via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp To Do

CVE-2024-3943

MEDIUM CVSS 4.3 2024-05-30
Scroll to top