Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 9341-9360 of 15036 records
Threat Entry Updated 2025-03-06

CVE-2024-5427 - Wpcafe Plugin

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Reservation Form shortcode in all versions up to, and including, 2.2.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wpcafe

CVE-2024-5427

MEDIUM CVSS 6.4 2024-05-31
Threat Entry Updated 2025-05-21

CVE-2024-4469 - Wp Staging Wordpress Backup Plugin

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.

PLUGIN Wp Staging Wordpress Backup

CVE-2024-4469

HIGH CVSS 7.5 2024-05-31
Threat Entry Updated 2025-01-15

CVE-2024-4376 - Premium Addons For Elementor Plugin

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, and including, 4.10.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. While 4.10.32 is patched, it is recommended to update to 4.10.33 because 4.10.32 caused a fatal error.

PLUGIN Premium Addons For Elementor

CVE-2024-4376

MEDIUM CVSS 6.4 2024-05-31
Threat Entry Updated 2025-01-15

CVE-2024-4379 - Premium Addons For Elementor Plugin

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Global Tooltip widget in all versions up to, and including, 4.10.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Premium Addons For Elementor

CVE-2024-4379

MEDIUM CVSS 5.4 2024-05-31
Threat Entry Updated 2025-01-15

CVE-2024-4205 - Premium Addons For Elementor Plugin

The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content() function in all versions up to, and including, 4.10.31. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve Elementor template data.

PLUGIN Premium Addons For Elementor

CVE-2024-4205

MEDIUM CVSS 4.3 2024-05-31
Threat Entry Updated 2024-11-21

CVE-2024-2793 - Atarim Visual Collaboration Plugin

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting via comments in all versions up to, and including, 3.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Atarim Visual Collaboration

CVE-2024-2793

HIGH CVSS 7.2 2024-05-31
Threat Entry Updated 2024-11-21

CVE-2024-5345 - Responsive Owl Carousel Elementor Plugin

The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.0 via the layout parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The inclusion is…

PLUGIN Responsive Owl Carousel Elementor

CVE-2024-5345

HIGH CVSS 8.8 2024-05-31
Threat Entry Updated 2025-03-24

CVE-2024-5418 - Dethemekit For Elementor

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide widget in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Dethemekit For Elementor

CVE-2024-5418

MEDIUM CVSS 6.4 2024-05-31
Threat Entry Updated 2024-11-21

CVE-2024-5326 - Ultimate Post Plugin

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'postx_presets_callback' function in all versions up to, and including, 4.1.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.

PLUGIN Ultimate Post

CVE-2024-5326

HIGH CVSS 8.8 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-3583 - Simple Like Page Plugin

The Simple Like Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Like Page

CVE-2024-3583

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-4668 - Gum Elementor Addon Plugin

The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Price Table and Post Slider widgets in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gum Elementor Addon

CVE-2024-4668

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2025-02-12

CVE-2024-4422 - Comparison Slider Plugin

The Comparison Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider title parameter in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Comparison Slider

CVE-2024-4422

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2025-02-12

CVE-2024-4427 - Comparison Slider Plugin

The Comparison Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 1.0.5. This makes it possible for authenticated attackers, with subscriber access or above, to change plugin settings and perform other actions such deleting sliders.

PLUGIN Comparison Slider

CVE-2024-4427

MEDIUM CVSS 4.3 2024-05-30
Threat Entry Updated 2025-02-12

CVE-2024-4426 - Comparison Slider Plugin

The Comparison Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on several functions hooked to AJAX actions. This makes it possible for unauthenticated attackers to change slider titles, delete sliders and modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Comparison Slider

CVE-2024-4426

MEDIUM CVSS 4.3 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-2089 - Remote Content Shortcode Plugin

The Remote Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'remote_content' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Remote Content Shortcode

CVE-2024-2089

MEDIUM CVSS 5.4 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-2657 - Font Farsi Plugin

The Font Farsi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Font Farsi

CVE-2024-2657

MEDIUM CVSS 4.4 2024-05-30
Threat Entry Updated 2024-11-21

CVE-2024-4355 - Stopbadbots Plugin

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stopbadbots_get_ajax_data() function in all versions up to, and including, 10.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose visitor data.

PLUGIN Stopbadbots

CVE-2024-4355

MEDIUM CVSS 4.3 2024-05-30
Threat Entry Updated 2025-01-15

CVE-2024-5327 - Powerpack Addons For Elementor Plugin

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘pp_animated_gradient_bg_color’ parameter in all versions up to, and including, 2.7.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Powerpack Addons For Elementor

CVE-2024-5327

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2025-01-15

CVE-2024-5073 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Feed component in all versions up to, and including, 5.9.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2024-5073

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2025-06-05

CVE-2024-5207 - Post Smtp Plugin

The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the selected parameter in all versions up to, and including, 2.9.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrator access or higher to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Post Smtp

CVE-2024-5207

HIGH CVSS 7.2 2024-05-30
Scroll to top