Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 6541-6560 of 15036 records
Threat Entry Updated 2025-01-09

CVE-2025-22813 - Conversational Forms for ChatBot Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ChatBot for WordPress - WPBot Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.4.2.

PLUGIN Conversational Forms for ChatBot

CVE-2025-22813

MEDIUM CVSS 6.5 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2025-22802 - Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail allows Stored XSS.This issue affects Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail: from n/a through 2.1.4.

PLUGIN Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail

CVE-2025-22802

MEDIUM CVSS 6.5 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2025-22295 - WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tripetto WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto allows Stored XSS.This issue affects WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto: from n/a through 8.0.5.

PLUGIN WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto

CVE-2025-22295

HIGH CVSS 7.1 2025-01-09
Threat Entry Updated 2025-06-05

CVE-2024-6155 - Greenshift Animation And Page Builder Blocks Plugin

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross Site Scripting in all versions up to, and including, 9.0.0 due to a missing capability check in the greenshift_download_file_localy function, along with no SSRF protection and sanitization on uploaded SVG files. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application that can also be leveraged to download malicious SVG files containing Cross-Site Scripting…

PLUGIN Greenshift Animation And Page Builder Blocks

CVE-2024-6155

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-5769 - Mimo Woocommerce Order Tracking Plugin

The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add, update, and delete shipper tracking settings.

PLUGIN Mimo Woocommerce Order Tracking

CVE-2024-5769

MEDIUM CVSS 4.3 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12848 - Skt Builder Plugin

The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the 'addLibraryByArchive' function in all versions up to, and including, 4.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files that make remote code execution possible.

PLUGIN Skt Builder

CVE-2024-12848

HIGH CVSS 8.8 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12819 - Searchie Plugin

The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortcode in all versions up to, and including, 1.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Searchie

CVE-2024-12819

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12621 - Yumpu Epaper Publishing Plugin

The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' shortcode in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Yumpu Epaper Publishing

CVE-2024-12621

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12618 - Newsletter2go Plugin

The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'resetStyles' AJAX action in all versions up to, and including, 4.0.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset styles.

PLUGIN Newsletter2go

CVE-2024-12618

MEDIUM CVSS 4.3 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12542 - Linkid Plugin

The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 0.1.2. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

PLUGIN Linkid

CVE-2024-12542

HIGH CVSS 8.6 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12515 - Masjidal Plugin

The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Masjidal

CVE-2024-12515

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12514 - 3dvieweronline Wp Plugin

The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' shortcode in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN 3dvieweronline Wp

CVE-2024-12514

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12616 - Wp Bitly Plugin

The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 2.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update and retrieve plugin settings.

PLUGIN Wp Bitly

CVE-2024-12616

MEDIUM CVSS 4.3 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12605 - Ai Scribe The Chatgpt Powered Seo Content Creation Wizard Plugin

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the "al_scribe_content_data" actions. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ai Scribe The Chatgpt Powered Seo Content Creation Wizard

CVE-2024-12605

MEDIUM CVSS 4.3 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12330 - Files Backup By Backup For Wp Plugin

The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.3 via publicly accessible back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including all information stored in the database.

PLUGIN Files Backup By Backup For Wp

CVE-2024-12330

HIGH CVSS 7.5 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12496 - Linear Plugin

The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissions' shortcode in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Linear

CVE-2024-12496

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12493 - Files Download Delay Plugin

The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' shortcode in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Files Download Delay

CVE-2024-12493

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12491 - Simply Rets Plugin

The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_search_form' shortcode in all versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simply Rets

CVE-2024-12491

MEDIUM CVSS 6.4 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12394 - Wp Action Network Plugin

The Action Network plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Action Network

CVE-2024-12394

MEDIUM CVSS 6.1 2025-01-09
Threat Entry Updated 2025-01-09

CVE-2024-12285 - Sema Api Plugin

The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versions up to, and including, 5.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Sema Api

CVE-2024-12285

MEDIUM CVSS 6.1 2025-01-09
Scroll to top