Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 7581-7600 of 15036 records
Threat Entry Updated 2024-11-08

CVE-2024-9946 - Super Socializer Plugin

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they have access to the email and the user does not have an already-existing account for the service returning the token. An attacker cannot authenticate as an administrator…

PLUGIN Super Socializer

CVE-2024-9946

HIGH CVSS 8.1 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-6626 - Eleforms Plugin

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several functions in all versions up to, and including, 2.9.9.9. This makes it possible for unauthenticated attackers to view form submissions.

PLUGIN Eleforms

CVE-2024-6626

MEDIUM CVSS 5.3 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10543 - Tumult Hype Animations Plugin

The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hypeanimations_getcontent function in all versions up to, and including, 1.9.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve animation information.

PLUGIN Tumult Hype Animations

CVE-2024-10543

MEDIUM CVSS 4.3 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10020 - Social Login Plugin

The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they have access to the email and the user does not have an already-existing account for the service returning the token. An attacker cannot authenticate as an administrator by default, but these accounts are also…

PLUGIN Social Login

CVE-2024-10020

HIGH CVSS 8.1 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10535 - Video Gallery For Woocommerce Plugin

The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_unused_thumbnails() function in all versions up to, and including, 1.31. This makes it possible for unauthenticated attackers to delete thumbnails in the video-wc-gallery-thumb directory.

PLUGIN Video Gallery For Woocommerce

CVE-2024-10535

MEDIUM CVSS 5.3 2024-11-06
Threat Entry Updated 2025-05-17

CVE-2024-9934 - Wp Imagezoom Plugin

The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Wp Imagezoom

CVE-2024-9934

MEDIUM CVSS 6.1 2024-11-06
Threat Entry Updated 2025-04-11

CVE-2024-7879 - Before 4 Plugin

The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 4

CVE-2024-7879

MEDIUM CVSS 4.8 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10647 - Ws Form Plugin

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.244. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Ws Form

CVE-2024-10647

MEDIUM CVSS 6.1 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10028 - Everest Backup Plugin

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process. This makes it possible for unauthenticated attackers to obtain an archive file name and download the site's backup.

PLUGIN Everest Backup

CVE-2024-10028

HIGH CVSS 7.5 2024-11-06
Threat Entry Updated 2025-07-11

CVE-2024-10084 - Contact Form 7 Dynamic Text Extension Plugin

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract the titles and text contents of private and password-protected posts, they do not own.

PLUGIN Contact Form 7 Dynamic Text Extension

CVE-2024-10084

MEDIUM CVSS 4.3 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-10329 - Ultimate Bootstrap Elements For Elementor Plugin

The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the 'ube_get_page_templates' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the contents of templates that are private.

PLUGIN Ultimate Bootstrap Elements For Elementor

CVE-2024-10329

MEDIUM CVSS 4.3 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-10263 - Tickera Plugin

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Tickera

CVE-2024-10263

HIGH CVSS 7.3 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-9657 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip' parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-9657

MEDIUM CVSS 6.5 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-9867 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Open Map Widget' marker_content parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-9867

MEDIUM CVSS 5.4 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-9178 - Xt Floating Cart For Woocommerce Plugin

The XT Floating Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Xt Floating Cart For Woocommerce

CVE-2024-9178

MEDIUM CVSS 6.4 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-10319 - Xpro Addons For Elementor Plugin

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the render function in widgets/content-toggle/layout/frontend.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

PLUGIN Xpro Addons For Elementor

CVE-2024-10319

MEDIUM CVSS 4.3 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-9878 - Photo Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Photo Gallery

CVE-2024-9878

MEDIUM CVSS 4.4 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-7429 - Zotpress Plugin

The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Zotpress_process_accounts_AJAX function in all versions up to, and including, 7.3.12. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset the plugin's settings.

PLUGIN Zotpress

CVE-2024-7429

MEDIUM CVSS 4.3 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-10687 - Contest Gallery Plugin

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and including, 24.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Contest Gallery

CVE-2024-10687

CRITICAL CVSS 9.8 2024-11-05
Threat Entry Updated 2024-11-07

CVE-2024-9443 - Framework Plugin

The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Framework

CVE-2024-9443

MEDIUM CVSS 6.4 2024-11-05
Scroll to top