Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 7861-7880 of 15036 records
Threat Entry Updated 2024-11-08

CVE-2024-8541 - Discount Rules For Woocommerce Plugin

The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.6.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a site administrator into performing an action such as clicking on a link. Please note that this is only exploitable when the 'Leave a…

PLUGIN Discount Rules For Woocommerce

CVE-2024-8541

MEDIUM CVSS 4.7 2024-10-16
Threat Entry Updated 2024-10-17

CVE-2024-9895 - Smart Online Order For Clover Plugin

The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Smart Online Order For Clover

CVE-2024-9895

MEDIUM CVSS 6.4 2024-10-15
Threat Entry Updated 2024-10-15

CVE-2024-9837 - Auto Date Year Month Plugin

The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Auto Date Year Month

CVE-2024-9837

HIGH CVSS 7.3 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-9944 - Woocommerce Plugin

The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views order form submissions.

PLUGIN Woocommerce

CVE-2024-9944

MEDIUM CVSS 5.3 2024-10-15
Threat Entry Updated 2024-10-19

CVE-2024-9820 - Wp 2fa With Telegram Plugin

The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.

PLUGIN Wp 2fa With Telegram

CVE-2024-9820

MEDIUM CVSS 6.5 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-9687 - Wp 2fa With Telegram Plugin

The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient validation of the user-controlled key on the 'validate_tg' action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator.

PLUGIN Wp 2fa With Telegram

CVE-2024-9687

HIGH CVSS 8.8 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-6757 - Website Builder Plugin

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.

PLUGIN Website Builder

CVE-2024-6757

MEDIUM CVSS 4.3 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-9548 - Slimstat Analytics Plugin

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping when logging visitor requests. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slimstat Analytics

CVE-2024-9548

HIGH CVSS 7.2 2024-10-15
Threat Entry Updated 2024-10-17

CVE-2024-9546 - Wpide Plugin

The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution results. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Wpide

CVE-2024-9546

MEDIUM CVSS 5.3 2024-10-15
Threat Entry Updated 2025-01-16

CVE-2024-8902 - Elementor Addon Elements Plugin

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function in modules/data-table/widgets/data-table.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

PLUGIN Elementor Addon Elements

CVE-2024-8902

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-8757 - And Custom User Registration Form Builder Plugin

The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_user_id parameter in all versions up to, and including, 3.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be…

PLUGIN And Custom User Registration Form Builder

CVE-2024-8757

HIGH CVSS 7.2 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9696 - Rescue Shortcodes Plugin

The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' shortcode in all versions up to, and including, 2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rescue Shortcodes

CVE-2024-9696

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2025-08-09

CVE-2024-9595 - Tablepress Plugin

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tablepress

CVE-2024-9595

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-8915 - Category Icon Plugin

The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Category Icon

CVE-2024-8915

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-8760 - Page Builder Gutenberg Blocks Plugin

The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes it possible for unauthenticated attackers to embed untrusted style information into comments resulting in a possibility of data exfiltration such as admin nonces with limited impact. These nonces could be used to perform CSRF attacks within a limited time window. The presence of other plugins may make additional nonces available, which may pose a risk in plugins that don't perform capability checks to protect AJAX…

PLUGIN Page Builder Gutenberg Blocks

CVE-2024-8760

MEDIUM CVSS 5.3 2024-10-12
Threat Entry Updated 2025-03-12

CVE-2024-9047 - Wordpress File Upload Plugin

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the targeted WordPress installation to be using PHP 7.4 or earlier.

PLUGIN Wordpress File Upload

CVE-2024-9047

CRITICAL CVSS 9.8 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9704 - Social Sharing Plugin

The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Social Sharing

CVE-2024-9704

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9756 - Order Attachments For Woocommerce Plugin

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload limited file types.

PLUGIN Order Attachments For Woocommerce

CVE-2024-9756

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9824 - Image Gallery Plugin

The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'ip_delete_post' and 'ip_update_post_title' functions in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts and update post titles.

PLUGIN Image Gallery

CVE-2024-9824

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9656 - Mynx Page Builder Plugin

The Mynx Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Mynx Page Builder

CVE-2024-9656

MEDIUM CVSS 6.4 2024-10-12
Scroll to top