Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10,866
Critical0
High0
Medium10,866
Reset
Showing 7941-7960 of 10866 records
Threat Entry Updated 2024-11-21

CVE-2024-0624 - Paid Memberships Pro Plugin

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible for unauthenticated attackers to update the order of levels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Paid Memberships Pro

CVE-2024-0624

MEDIUM CVSS 5.3 2024-01-25
Threat Entry Updated 2024-11-21

CVE-2024-0617 - Category Discount Woocommerce Plugin

The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpcd_save_discount() function in all versions up to, and including, 4.12. This makes it possible for unauthenticated attackers to modify product category discounts that could lead to loss of revenue.

PLUGIN Category Discount Woocommerce

CVE-2024-0617

MEDIUM CVSS 5.3 2024-01-25
Threat Entry Updated 2024-11-21

CVE-2024-0688 - Websub Plugin

The "WebSub (FKA. PubSubHubbub)" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Websub

CVE-2024-0688

MEDIUM CVSS 4.4 2024-01-25
Threat Entry Updated 2024-11-21

CVE-2023-6697 - Wp Go Maps Plugin

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Go Maps

CVE-2023-6697

MEDIUM CVSS 6.1 2024-01-24
Threat Entry Updated 2024-11-21

CVE-2024-0665 - Wp Customer Area Plugin

The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Customer Area

CVE-2024-0665

MEDIUM CVSS 6.1 2024-01-24
Threat Entry Updated 2024-11-21

CVE-2024-0703 - Sticky Buttons Plugin

The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sticky URLs in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Sticky Buttons

CVE-2024-0703

MEDIUM CVSS 4.4 2024-01-23
Threat Entry Updated 2024-11-21

CVE-2024-0587 - Accelerated Mobile Pages Plugin

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up to, and including, 1.0.92.1 due to insufficient input sanitization and output escaping on the executed JS file. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Accelerated Mobile Pages

CVE-2024-0587

MEDIUM CVSS 6.1 2024-01-23
Threat Entry Updated 2025-05-30

CVE-2023-7194 - Meris Wp Theme

The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

THEME Meris Wp Theme

CVE-2023-7194

MEDIUM CVSS 6.1 2024-01-22
Threat Entry Updated 2025-05-30

CVE-2023-7170 - Eventon Rsvp Plugin

The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Eventon Rsvp

CVE-2023-7170

MEDIUM CVSS 6.1 2024-01-22
Threat Entry Updated 2025-06-17

CVE-2023-6447 - Before 3 Plugin

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name.

PLUGIN Before 3

CVE-2023-6447

MEDIUM CVSS 5.3 2024-01-22
Threat Entry Updated 2025-05-30

CVE-2023-6626 - Product Enquiry For Woocommerce Plugin

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Product Enquiry For Woocommerce

CVE-2023-6626

MEDIUM CVSS 4.8 2024-01-22
Threat Entry Updated 2025-06-11

CVE-2023-6456 - Wp Review Slider Plugin

The WP Review Slider WordPress plugin before 13.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wp Review Slider

CVE-2023-6456

MEDIUM CVSS 4.8 2024-01-22
Threat Entry Updated 2024-11-21

CVE-2023-6290 - Before 7 Plugin

The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 7

CVE-2023-6290

MEDIUM CVSS 4.8 2024-01-22
Threat Entry Updated 2025-06-20

CVE-2023-6625 - Product Enquiry For Woocommerce Plugin

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack

PLUGIN Product Enquiry For Woocommerce

CVE-2023-6625

MEDIUM CVSS 4.3 2024-01-22
Threat Entry Updated 2025-05-30

CVE-2024-0679 - Colormag Plugin

The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate arbitrary plugins.

PLUGIN Colormag

CVE-2024-0679

MEDIUM CVSS 6.5 2024-01-20
Threat Entry Updated 2024-11-21

CVE-2024-0623 - Vk Block Patterns Plugin

The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.31.1.1. This is due to missing or incorrect nonce validation on the vbp_clear_patterns_cache() function. This makes it possible for unauthenticated attackers to clear the patterns cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Vk Block Patterns

CVE-2024-0623

MEDIUM CVSS 4.3 2024-01-20
Threat Entry Updated 2025-06-02

CVE-2024-0381 - Wp Recipe Maker Plugin

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and wprm-recipe-counter shortcodes in all versions up to, and including, 9.1.0. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Recipe Maker

CVE-2024-0381

MEDIUM CVSS 6.4 2024-01-18
Threat Entry Updated 2024-11-21

CVE-2023-6958 - Wp Recipe Maker Plugin

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Recipe Maker

CVE-2023-6958

MEDIUM CVSS 6.4 2024-01-18
Threat Entry Updated 2024-11-21

CVE-2023-6970 - Wp Recipe Maker Plugin

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Recipe Maker

CVE-2023-6970

MEDIUM CVSS 6.1 2024-01-18
Scroll to top