Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 7301-7320 of 15036 records
Threat Entry Updated 2025-07-12

CVE-2024-10873 - Element Kit For Elementor Plugin

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the _load_template function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Element Kit For Elementor

CVE-2024-10873

HIGH CVSS 8.8 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11408 - Slotti Ajanvaraus Plugin

The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti' shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slotti Ajanvaraus

CVE-2024-11408

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11387 - Easy Liveblogs Plugin

The Easy Liveblogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elb_liveblog' shortcode in all versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Liveblogs

CVE-2024-11387

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11332 - Sign Hipaa Documents Plugin

The HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hipaatizer' shortcode in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sign Hipaa Documents

CVE-2024-11332

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11361 - Pdf Invoicing For Woocommerce Plugin

The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Pdf Invoicing For Woocommerce

CVE-2024-11361

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-10880 - Jobboardwp Plugin

The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Jobboardwp

CVE-2024-10880

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2025-02-11

CVE-2024-10606 - Wp Travel Engine Plugin

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpte_onboard_save_function_callback() function in all versions up to, and including, 6.2.1. This makes it possible for authenticated attackers, with contributor-level access and above, to modify several settings that could have an impact such as lost revenue and page updates.

PLUGIN Wp Travel Engine

CVE-2024-10606

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-9223 - Wpdash Notes Plugin

The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_ajax_post_it_list_comment' function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view comments on any post, including private and password protected posts, and pending and draft posts if they were previously published. The vulnerability was partially patched in version 1.3.5.

PLUGIN Wpdash Notes

CVE-2024-9223

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2024-12-06

CVE-2024-10961 - Oa Social Login Plugin

The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

PLUGIN Oa Social Login

CVE-2024-10961

CRITICAL CVSS 9.8 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11415 - Wp Orphanage Extended Plugin

The WP-Orphanage Extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the wporphanageex_menu_settings() function. This makes it possible for unauthenticated attackers to escalate the privileges of all orphan accounts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Orphanage Extended

CVE-2024-11415

HIGH CVSS 8.8 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-10886 - Tribute Testimonial Gridslider Plugin

The Tribute Testimonials – WordPress Testimonial Grid/Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tribute_testimonials_slider' shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tribute Testimonial Gridslider

CVE-2024-10886

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-10874 - Quotes Llama Plugin

The Quotes llama plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quotes-llama' shortcode in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Quotes Llama

CVE-2024-10874

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11463 - Debounce Email Validator Plugin

The DeBounce Email Validator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'from', 'to', and 'key' parameters in all versions up to, and including, 5.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Debounce Email Validator

CVE-2024-11463

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11362 - Peachpay For Woocommerce Plugin

The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.112.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Peachpay For Woocommerce

CVE-2024-11362

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-10869 - Stop Brute Force Attacks Plugin

The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Stop Brute Force Attacks

CVE-2024-10869

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2025-07-15

CVE-2024-10116 - Twitter Follow Button Plugin

The Twitter Follow Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'username' parameter in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Twitter Follow Button

CVE-2024-10116

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-10813 - Woo Product Table Plugin

The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1 via the var_dump_table parameter. This makes it possible for unauthenticated attackers var data.

PLUGIN Woo Product Table

CVE-2024-10813

MEDIUM CVSS 5.3 2024-11-23
Threat Entry Updated 2025-01-23

CVE-2024-10868 - Enter Addons Plugin

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.9 via the Advanced Tabs widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.

PLUGIN Enter Addons

CVE-2024-10868

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2025-02-07

CVE-2024-10537 - Wp User Manager Plugin

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_user_meta_key() function in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate user meta keys.

PLUGIN Wp User Manager

CVE-2024-10537

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2025-02-07

CVE-2024-10216 - Wp User Manager Plugin

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add or remove a Carbon Fields custom sidebar if the Carbon Fields (carbon-fields) plugin is installed.

PLUGIN Wp User Manager

CVE-2024-10216

MEDIUM CVSS 4.3 2024-11-23
Scroll to top