Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 9161-9180 of 15036 records
Threat Entry Updated 2024-11-21

CVE-2024-5543 - Slideshow Gallery Plugin

The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Slideshow Gallery

CVE-2024-5543

HIGH CVSS 8.1 2024-06-12
Threat Entry Updated 2025-06-05

CVE-2024-4892 - Buddypress Plugin

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Buddypress

CVE-2024-4892

MEDIUM CVSS 6.4 2024-06-12
Threat Entry Updated 2025-02-05

CVE-2024-5646 - Futurio Extra Plugin

The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute within the Advanced Text Block widget in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Futurio Extra

CVE-2024-5646

MEDIUM CVSS 6.4 2024-06-11
Threat Entry Updated 2025-05-28

CVE-2024-4669 - Events Addon For Elementor Plugin

The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Basic Slider, Upcoming Events, and Schedule widgets in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Events Addon For Elementor

CVE-2024-4669

MEDIUM CVSS 6.4 2024-06-11
Threat Entry Updated 2024-11-21

CVE-2024-34826 - Contact Form 7 Plugin

Missing Authorization vulnerability in Tobias Conrad Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler.This issue affects Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler: from n/a through 1.6.4.

PLUGIN Contact Form 7

CVE-2024-34826

MEDIUM CVSS 6.3 2024-06-11
Threat Entry Updated 2025-01-15

CVE-2024-5189 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_js’ parameter in all versions up to, and including, 5.9.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2024-5189

MEDIUM CVSS 6.4 2024-06-11
Threat Entry Updated 2024-11-21

CVE-2024-5584 - Bookly Responsive Appointment Booking Tool Plugin

The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Color Profile parameter in all versions up to, and including, 23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with the staff member role and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bookly Responsive Appointment Booking Tool

CVE-2024-5584

MEDIUM CVSS 6.4 2024-06-11
Threat Entry Updated 2024-11-21

CVE-2024-5531 - Ocean Extra Plugin

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ocean Extra

CVE-2024-5531

MEDIUM CVSS 6.4 2024-06-11
Threat Entry Updated 2025-02-26

CVE-2024-4266 - Metform Elementor Contact Form Builder Plugin

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from files uploaded by users.

PLUGIN Metform Elementor Contact Form Builder

CVE-2024-4266

MEDIUM CVSS 5.3 2024-06-11
Threat Entry Updated 2025-06-05

CVE-2024-3549 - Blog2social Plugin

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Blog2social

CVE-2024-3549

CRITICAL CVSS 9.9 2024-06-11
Threat Entry Updated 2024-11-21

CVE-2024-4319 - Advanced Cf7 Db Plugin

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to download the entry data for submitted forms.

PLUGIN Advanced Cf7 Db

CVE-2024-4319

MEDIUM CVSS 5.3 2024-06-11
Threat Entry Updated 2024-11-21

CVE-2024-3723 - Advanced Cf7 Db Plugin

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced-cf7-upload directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this plugin through a form.

PLUGIN Advanced Cf7 Db

CVE-2024-3723

MEDIUM CVSS 5.3 2024-06-11
Threat Entry Updated 2025-11-25

CVE-2024-5530 - Shoplentor Plugin

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WL: Product Horizontal Filter widget in all versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shoplentor

CVE-2024-5530

MEDIUM CVSS 6.4 2024-06-11
Threat Entry Updated 2025-02-05

CVE-2023-7264 - Build App Online Plugin

The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.

PLUGIN Build App Online

CVE-2023-7264

HIGH CVSS 8.1 2024-06-11
Threat Entry Updated 2025-03-24

CVE-2024-5090 - Siteorigin Widgets Bundle Plugin

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SiteOrigin Blog Widget in all versions up to, and including, 1.61.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Siteorigin Widgets Bundle

CVE-2024-5090

MEDIUM CVSS 6.4 2024-06-11
Threat Entry Updated 2024-11-21

CVE-2024-2473 - Wps Hide Login Plugin

The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.

PLUGIN Wps Hide Login

CVE-2024-2473

MEDIUM CVSS 5.3 2024-06-11
Threat Entry Updated 2025-01-29

CVE-2024-0627 - Custom Field Template Plugin

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom field name column in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied custom fields. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Custom Field Template

CVE-2024-0627

MEDIUM CVSS 6.4 2024-06-11
Threat Entry Updated 2025-01-29

CVE-2023-6745 - Custom Field Template Plugin

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cpt' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied post meta. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Custom Field Template

CVE-2023-6745

MEDIUM CVSS 6.4 2024-06-11
Threat Entry Updated 2025-01-29

CVE-2024-0653 - Custom Field Template Plugin

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Custom Field Template

CVE-2024-0653

MEDIUM CVSS 4.4 2024-06-11
Scroll to top