Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 7021-7040 of 10866 records
Threat Entry Updated 2025-04-23

CVE-2024-2345 - Filebird Plugin

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the folder name parameter in all versions up to, and including, 5.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Filebird

CVE-2024-2345

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-06

CVE-2024-2328 - Real Media Library Plugin

The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image title and alt text in all versions up to, and including, 4.22.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Real Media Library

CVE-2024-2328

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-02-07

CVE-2024-2273 - Gutenberg Blocks With Ai Plugin

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.2.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Blocks With Ai

CVE-2024-2273

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-04-23

CVE-2024-2346 - Filebird Plugin

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via folder deletion due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author access or higher, to delete folders created by other users and make their file uploads visible.

PLUGIN Filebird

CVE-2024-2346

MEDIUM CVSS 5.4 2024-05-02
Threat Entry Updated 2025-03-13

CVE-2024-2324 - Fileorganizer Plugin

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg file upload in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. For the free version, this is limited to administrators. The pro version is also vulnerable and exploitable by administrators, but also offers the functionality to lower level users (as…

PLUGIN Fileorganizer

CVE-2024-2324

MEDIUM CVSS 4.4 2024-05-02
Threat Entry Updated 2025-01-28

CVE-2024-2085 - Ht Mega Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' value in several widgets all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ht Mega

CVE-2024-2085

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-01-28

CVE-2024-2084 - Ht Mega Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox widget in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ht Mega

CVE-2024-2084

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-2109 - Booster Extension Plugin

The Booster Extension plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.0 via the 'booster_extension_authorbox_shortcode_display' function. This makes it possible for unauthenticated attackers to extract sensitive data including user emails

PLUGIN Booster Extension

CVE-2024-2109

MEDIUM CVSS 5.3 2024-05-02
Threat Entry Updated 2025-03-21

CVE-2024-2043 - Eleforms Plugin

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when downloading form submissions in all versions up to, and including, 2.9.9.7. This makes it possible for unauthenticated attackers to view form submissions.

PLUGIN Eleforms

CVE-2024-2043

MEDIUM CVSS 5.3 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-1993 - Icon Widget Plugin

The Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Icon Widget

CVE-2024-1993

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-1959 - Social Warfare Plugin

The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialWarfare' shortcode in all versions up to, and including, 4.4.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Social Warfare

CVE-2024-1959

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-28

CVE-2024-1842 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1842

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-28

CVE-2024-1841 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1841

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-28

CVE-2024-1840 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1840

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-28

CVE-2024-1805 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1805

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-06-05

CVE-2024-1809 - Analytify Google Analytics Dashboard Plugin

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain certain sensitive information related to plugin settings.

PLUGIN Analytify Google Analytics Dashboard

CVE-2024-1809

MEDIUM CVSS 5.4 2024-05-02
Threat Entry Updated 2025-03-05

CVE-2024-1759 - Wp Ulike Plugin

The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Ulike

CVE-2024-1759

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-06-05

CVE-2024-1679 - Print Labels With Barcodes Plugin

The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template and javascript label fields in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Print Labels With Barcodes

CVE-2024-1679

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-06-05

CVE-2024-1677 - Print Labels With Barcodes Plugin

The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to an improper capability check on 42 separate AJAX functions in all versions up to, and including, 3.4.6. This makes it possible for authenticated attackers, with subscriber access and above, to fully control the plugin which includes the ability to modify plugin settings and profiles, and create, edit, retrieve, and delete templates and barcodes.

PLUGIN Print Labels With Barcodes

CVE-2024-1677

MEDIUM CVSS 6.3 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-1688 - Woo Total Sales Plugin

The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_orders_archive() function in all versions up to, and including, 3.1.4. This makes it possible for unauthenticated attackers to retrieve sales reports for the store.

PLUGIN Woo Total Sales

CVE-2024-1688

MEDIUM CVSS 5.3 2024-05-02
Scroll to top