Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 8901-8920 of 15036 records
Threat Entry Updated 2024-11-21

CVE-2024-5504 - Rife Elementor Extensions Templates Plugin

The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute within the plugin's Writing Effect Headline widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rife Elementor Extensions Templates

CVE-2024-5504

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-3513 - Ultimate Blocks Plugin

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title tag parameter in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Blocks

CVE-2024-3513

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-5544 - Media Library Assistant Plugin

The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Media Library Assistant

CVE-2024-5544

MEDIUM CVSS 6.1 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-6172 - Email Subscribers Newsletters Plugin

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Email Subscribers Newsletters

CVE-2024-6172

CRITICAL CVSS 9.8 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-5219 - Easy Google Maps Plugin

The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Google Maps

CVE-2024-5219

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-5767 - Sitetweet Plugin

The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Sitetweet

CVE-2024-5767

HIGH CVSS 8.8 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-5606 - Before 9 Plugin

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role

PLUGIN Before 9

CVE-2024-5606

HIGH CVSS 8.8 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-4627 - Rank Math Seo Plugin

The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager feature of the Rank Math SEO WordPress plugin before 1.0.219) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Rank Math Seo

CVE-2024-4627

MEDIUM CVSS 5.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-3999 - Before 2 Plugin

The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2024-3999

MEDIUM CVSS 4.8 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-1427 - Post Grid Plugin

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Post Grid

CVE-2024-1427

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-5349 - Element Kit For Elementor Plugin

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'map_style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Element Kit For Elementor

CVE-2024-5349

HIGH CVSS 8.8 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-5419 - Void Contact Form 7 Widget For Elementor Page Builder Plugin

The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cf7_redirect_page' attribute within the plugin's Void Contact From 7 widget in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Void Contact Form 7 Widget For Elementor Page Builder

CVE-2024-5419

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-12-26

CVE-2024-5938 - Boot Store Plugin

The Boot Store theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Boot Store

CVE-2024-5938

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-39310 - Basil Recipe Theme

The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` parameter in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. Because the of the default WordPress validation, it is not possible to insert the payload directly but if the Cooked plugin is installed, it is possible to create a recipe post…

THEME Basil Recipe

CVE-2024-39310

MEDIUM CVSS 5.4 2024-07-01
Threat Entry Updated 2025-05-01

CVE-2024-4934 - Before 9 Plugin

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 9

CVE-2024-4934

MEDIUM CVSS 5.5 2024-07-01
Threat Entry Updated 2025-05-01

CVE-2024-6130 - Form Maker By 10web Plugin

The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Form Maker By 10web

CVE-2024-6130

MEDIUM CVSS 4.8 2024-07-01
Threat Entry Updated 2024-11-21

CVE-2024-2386 - Wp Maps Plugin

The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Maps

CVE-2024-2386

HIGH CVSS 8.8 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2023-4017 - Goya Theme

The Goya theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attra-color’, 'attra-size', and 'product-cata' parameters in versions up to, and including, 1.0.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Goya

CVE-2023-4017

MEDIUM CVSS 6.1 2024-06-29
Threat Entry Updated 2025-02-07

CVE-2024-5819 - Gutenberg Blocks With Ai Plugin

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data attributes in all versions up to, and including, 3.2.45 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Blocks With Ai

CVE-2024-5819

MEDIUM CVSS 6.4 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-6363 - Stock Ticker Plugin

The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortcode in all versions up to, and including, 3.24.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Stock Ticker

CVE-2024-6363

MEDIUM CVSS 6.4 2024-06-29
Scroll to top