Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 7721-7740 of 10866 records
Threat Entry Updated 2025-01-15

CVE-2024-0907 - Nex Forms Plugin

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the restore_records() function in all versions up to, and including, 8.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to restore records.

PLUGIN Nex Forms

CVE-2024-0907

MEDIUM CVSS 5.3 2024-02-29
Threat Entry Updated 2024-12-27

CVE-2024-0838 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Happy Addons For Elementor

CVE-2024-0838

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-01-27

CVE-2024-0792 - Shortcodes Ultimate Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping on RSS feed content. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shortcodes Ultimate

CVE-2024-0792

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-03-04

CVE-2024-0821 - Cost Of Goods For Woocommerce Plugin

The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'section' parameter in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Cost Of Goods For Woocommerce

CVE-2024-0821

MEDIUM CVSS 6.1 2024-02-29
Threat Entry Updated 2025-03-04

CVE-2024-0658 - Insert Php Code Snippet Plugin

The Insert PHP Code Snippet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user's name when accessing the insert-php-code-snippet-manage page in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Insert Php Code Snippet

CVE-2024-0658

MEDIUM CVSS 4.4 2024-02-29
Threat Entry Updated 2025-01-27

CVE-2024-0656 - Password Protected Plugin

The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Captcha Site Key in all versions up to, and including, 2.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Password Protected

CVE-2024-0656

MEDIUM CVSS 4.4 2024-02-29
Threat Entry Updated 2025-01-27

CVE-2024-0620 - Password Protect Wordpress Plugin

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts.

PLUGIN Password Protect Wordpress

CVE-2024-0620

MEDIUM CVSS 5.3 2024-02-29
Threat Entry Updated 2025-01-27

CVE-2024-0616 - Passster Plugin

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other metadata including passwords of password-protected posts and pages.

PLUGIN Passster

CVE-2024-0616

MEDIUM CVSS 5.3 2024-02-29
Threat Entry Updated 2025-03-04

CVE-2024-0621 - Simple Share Buttons Adder Plugin

The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Simple Share Buttons Adder

CVE-2024-0621

MEDIUM CVSS 4.4 2024-02-29
Threat Entry Updated 2025-02-13

CVE-2024-0604 - Foogallery Plugin

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Foogallery

CVE-2024-0604

MEDIUM CVSS 4.4 2024-02-29
Threat Entry Updated 2025-03-04

CVE-2024-0590 - Clarity Plugin

The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing nonce validation on the edit_clarity_project_id() function. This makes it possible for unauthenticated attackers to change the project id and add malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Clarity

CVE-2024-0590

MEDIUM CVSS 6.1 2024-02-29
Threat Entry Updated 2025-02-27

CVE-2024-0602 - Yet Another Related Posts Plugin

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Yet Another Related Posts

CVE-2024-0602

MEDIUM CVSS 4.4 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0516 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible for unauthenticated attackers to update certain metadata.

PLUGIN Royal Elementor Addons

CVE-2024-0516

MEDIUM CVSS 5.3 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0515 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes it possible for unauthenticated attackers to remove items from user compare lists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Royal Elementor Addons

CVE-2024-0515

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0514 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_compare function. This makes it possible for unauthenticated attackers to add items to user compare lists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Royal Elementor Addons

CVE-2024-0514

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-01-27

CVE-2024-0506 - Website Builder Plugin

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Website Builder

CVE-2024-0506

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0513 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_wishlist function. This makes it possible for unauthenticated attackers to remove items from user wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Royal Elementor Addons

CVE-2024-0513

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0512 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_wishlist function. This makes it possible for unauthenticated attackers to add items to user wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Royal Elementor Addons

CVE-2024-0512

MEDIUM CVSS 4.3 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-0442 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and including, 1.3.87 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Royal Elementor Addons

CVE-2024-0442

MEDIUM CVSS 6.4 2024-02-29
Threat Entry Updated 2024-12-27

CVE-2024-0438 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Happy Addons For Elementor

CVE-2024-0438

MEDIUM CVSS 6.4 2024-02-29
Scroll to top