Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 6061-6080 of 15036 records
Threat Entry Updated 2025-05-26

CVE-2025-0692 - Simple Video Management System Plugin

The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Simple Video Management System

CVE-2025-0692

LOW CVSS 3.5 2025-02-13
Threat Entry Updated 2025-05-21

CVE-2024-13125 - Everest Forms Plugin

The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Everest Forms

CVE-2024-13125

LOW CVSS 3.5 2025-02-13
Threat Entry Updated 2025-05-21

CVE-2024-13121 - Restrict Content Plugin

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Restrict Content

CVE-2024-13121

LOW CVSS 3.5 2025-02-13
Threat Entry Updated 2025-05-23

CVE-2024-12586 - Chalet Montagne Com Tools Plugin

The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Chalet Montagne Com Tools

CVE-2024-12586

MEDIUM CVSS 6.1 2025-02-13
Threat Entry Updated 2025-05-21

CVE-2024-13120 - Restrict Content Plugin

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Restrict Content

CVE-2024-13120

MEDIUM CVSS 4.8 2025-02-13
Threat Entry Updated 2025-05-21

CVE-2024-13119 - Restrict Content Plugin

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Restrict Content

CVE-2024-13119

MEDIUM CVSS 4.8 2025-02-13
Threat Entry Updated 2025-02-24

CVE-2024-13770 - Puzzles Plugin

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.4 via deserialization of untrusted input 'view_more_posts' AJAX action. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional…

PLUGIN Puzzles

CVE-2024-13770

HIGH CVSS 8.1 2025-02-13
Threat Entry Updated 2025-02-24

CVE-2025-0837 - Puzzles Plugin

The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Puzzles

CVE-2025-0837

MEDIUM CVSS 6.4 2025-02-13
Threat Entry Updated 2025-02-24

CVE-2024-13227 - Seo Plugin

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank Math API in all versions up to, and including, 1.0.235 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Seo

CVE-2024-13227

MEDIUM CVSS 6.4 2025-02-13
Threat Entry Updated 2025-02-24

CVE-2024-13229 - Seo Plugin

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete any schema metadata assigned to any post.

PLUGIN Seo

CVE-2024-13229

MEDIUM CVSS 4.3 2025-02-13
Threat Entry Updated 2025-11-13

CVE-2024-10763 - Campress Plugin

The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

PLUGIN Campress

CVE-2024-10763

CRITICAL CVSS 9.8 2025-02-13
Threat Entry Updated 2025-02-25

CVE-2024-13644 - Dethemekit For Elementor

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Dethemekit For Elementor

CVE-2024-13644

MEDIUM CVSS 6.4 2025-02-13
Threat Entry Updated 2025-02-20

CVE-2024-10322 - Brizy Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Brizy

CVE-2024-10322

MEDIUM CVSS 6.4 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13532 - Small Package Quotes Plugin

The Small Package Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Small Package Quotes

CVE-2024-13532

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-20

CVE-2025-0511 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 2.11.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Welcart E Commerce

CVE-2025-0511

HIGH CVSS 7.2 2025-02-12
Threat Entry Updated 2025-02-20

CVE-2024-10960 - Brizy Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Brizy

CVE-2024-10960

CRITICAL CVSS 9.9 2025-02-12
Threat Entry Updated 2025-02-20

CVE-2024-12386 - Wp Abstracts Plugin

The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.3. This is due to missing nonce validation on multiple functions. This makes it possible for unauthenticated attackers to delete arbitrary accounts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Abstracts

CVE-2024-12386

HIGH CVSS 8.1 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13480 - Ltl Freight Quotes Plugin

The LTL Freight Quotes – For Customers of FedEx Freight plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ltl Freight Quotes

CVE-2024-13480

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13477 - Ltl Freight Quotes Plugin

The LTL Freight Quotes – Unishippers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 2.5.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ltl Freight Quotes

CVE-2024-13477

HIGH CVSS 7.5 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2025-0506 - Rise Blocks Plugin

The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the titleTag parameter in all versions up to, and including, 3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rise Blocks

CVE-2025-0506

MEDIUM CVSS 6.4 2025-02-12
Scroll to top