Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 6761-6780 of 10866 records
Threat Entry Updated 2024-11-21

CVE-2024-4710 - Ubermenu Plugin

The UberMenu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ubermenu-col, ubermenu_mobile_close_button, ubermenu_toggle, ubermenu-search shortcodes in all versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ubermenu

CVE-2024-4710

MEDIUM CVSS 6.4 2024-05-21
Threat Entry Updated 2025-01-07

CVE-2024-4470 - Master Slider Plugin

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide_info' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied 'tag_name' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Master Slider

CVE-2024-4470

MEDIUM CVSS 6.4 2024-05-21
Threat Entry Updated 2025-04-10

CVE-2024-4372 - Carousel Slider Plugin

The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

PLUGIN Carousel Slider

CVE-2024-4372

MEDIUM CVSS 5.4 2024-05-21
Threat Entry Updated 2025-05-21

CVE-2024-4289 - Sailthru Triggermail Plugin

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Sailthru Triggermail

CVE-2024-4289

MEDIUM CVSS 6.1 2024-05-21
Threat Entry Updated 2025-04-18

CVE-2024-4061 - Survey Maker Plugin

The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Survey Maker

CVE-2024-4061

MEDIUM CVSS 4.8 2024-05-21
Threat Entry Updated 2025-05-21

CVE-2024-2189 - Block By Wpzoom Plugin

The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Block By Wpzoom

CVE-2024-2189

MEDIUM CVSS 6.1 2024-05-21
Threat Entry Updated 2025-02-03

CVE-2024-4943 - Blocksy Plugin

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘has_field_link_rel’ parameter in all versions up to, and including, 2.0.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Blocksy

CVE-2024-4943

MEDIUM CVSS 6.4 2024-05-21
Threat Entry Updated 2024-11-21

CVE-2024-3155 - Combo Blocks Plugin

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Combo Blocks

CVE-2024-3155

MEDIUM CVSS 6.4 2024-05-21
Threat Entry Updated 2025-05-21

CVE-2024-3368 - All In One Seo Plugin

The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN All In One Seo

CVE-2024-3368

MEDIUM CVSS 6.1 2024-05-20
Threat Entry Updated 2025-01-07

CVE-2024-5088 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Happy Addons For Elementor

CVE-2024-5088

MEDIUM CVSS 6.4 2024-05-18
Threat Entry Updated 2024-11-21

CVE-2024-4432 - Piotnet Addons For Elementor Plugin

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Piotnet Addons For Elementor

CVE-2024-4432

MEDIUM CVSS 6.4 2024-05-18
Threat Entry Updated 2024-11-21

CVE-2024-4698 - Testimonial Carousel For Elementor Plugin

The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_line_text ' and 'slide_button_hover_animation' parameters in versions up to, and including, 10.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Testimonial Carousel For Elementor

CVE-2024-4698

MEDIUM CVSS 6.4 2024-05-18
Threat Entry Updated 2025-02-06

CVE-2024-2772 - Contact Form Plugin

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the Fluent Forms settings, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This can be chained with CVE-2024-2771 for a low-privileged user to inject malicious web…

PLUGIN Contact Form

CVE-2024-2772

MEDIUM CVSS 6.4 2024-05-18
Threat Entry Updated 2024-11-21

CVE-2024-4849 - Wordpress Automatic Plugin

The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘autoplay’ parameter in all versions up to, and including, 3.94.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wordpress Automatic

CVE-2024-4849

MEDIUM CVSS 6.4 2024-05-18
Threat Entry Updated 2024-11-21

CVE-2024-3811 - Salient Shortcodes Plugin

The Salient Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'icon' shortcode in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Salient Shortcodes

CVE-2024-3811

MEDIUM CVSS 6.4 2024-05-18
Threat Entry Updated 2025-01-30

CVE-2024-4891 - Essential Blocks Plugin

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 4.5.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Blocks

CVE-2024-4891

MEDIUM CVSS 6.4 2024-05-18
Threat Entry Updated 2025-03-21

CVE-2024-4374 - Dethemekit For Elementor

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Dethemekit For Elementor

CVE-2024-4374

MEDIUM CVSS 6.4 2024-05-18
Threat Entry Updated 2025-03-05

CVE-2024-3714 - Givewp Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode when used with a legacy form in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Givewp

CVE-2024-3714

MEDIUM CVSS 6.4 2024-05-18
Threat Entry Updated 2025-01-07

CVE-2024-4865 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Happy Addons For Elementor

CVE-2024-4865

MEDIUM CVSS 6.4 2024-05-18
Threat Entry Updated 2024-11-21

CVE-2024-4789 - Cost Calculator Builder Pro Plugin

Cost Calculator Builder Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.1.72, via the send_demo_webhook() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Cost Calculator Builder Pro

CVE-2024-4789

MEDIUM CVSS 6.4 2024-05-17
Scroll to top