Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 9841-9860 of 15036 records
Threat Entry Updated 2024-11-21

CVE-2024-1945 - Arforms Form Builder Plugin

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'arflite_remove_preview_data' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with subscriber access and above, to delete arbitrary site options, resulting in loss of availability.

PLUGIN Arforms Form Builder

CVE-2024-1945

HIGH CVSS 7.1 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-1993 - Icon Widget Plugin

The Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Icon Widget

CVE-2024-1993

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-1959 - Social Warfare Plugin

The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialWarfare' shortcode in all versions up to, and including, 4.4.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Social Warfare

CVE-2024-1959

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-28

CVE-2024-1842 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1842

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-03-05

CVE-2024-1797 - Wp Ulike Plugin

The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the 'wp_ulike_counter' and 'wp_ulike' shortcodes in all versions up to, and including, 4.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Ulike

CVE-2024-1797

HIGH CVSS 8.8 2024-05-02
Threat Entry Updated 2025-05-28

CVE-2024-1841 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1841

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-28

CVE-2024-1840 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1840

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-28

CVE-2024-1805 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1805

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-06-05

CVE-2024-1809 - Analytify Google Analytics Dashboard Plugin

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain certain sensitive information related to plugin settings.

PLUGIN Analytify Google Analytics Dashboard

CVE-2024-1809

MEDIUM CVSS 5.4 2024-05-02
Threat Entry Updated 2025-03-05

CVE-2024-1759 - Wp Ulike Plugin

The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Ulike

CVE-2024-1759

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-06-05

CVE-2024-1679 - Print Labels With Barcodes Plugin

The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template and javascript label fields in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Print Labels With Barcodes

CVE-2024-1679

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-06-05

CVE-2024-1677 - Print Labels With Barcodes Plugin

The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to an improper capability check on 42 separate AJAX functions in all versions up to, and including, 3.4.6. This makes it possible for authenticated attackers, with subscriber access and above, to fully control the plugin which includes the ability to modify plugin settings and profiles, and create, edit, retrieve, and delete templates and barcodes.

PLUGIN Print Labels With Barcodes

CVE-2024-1677

MEDIUM CVSS 6.3 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-1688 - Woo Total Sales Plugin

The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_orders_archive() function in all versions up to, and including, 3.1.4. This makes it possible for unauthenticated attackers to retrieve sales reports for the store.

PLUGIN Woo Total Sales

CVE-2024-1688

MEDIUM CVSS 5.3 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-1678 - Subway Plugin

The Subway – Private Site Option plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's private site feature and view restricted page and post content.

PLUGIN Subway

CVE-2024-1678

MEDIUM CVSS 5.3 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-1716 - Admin Bar Plugin

The Admin Bar Remover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_form() function in all versions up to, and including, 1.0.2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to enable or disable the admin bar on the front-end of the site.

PLUGIN Admin Bar

CVE-2024-1716

MEDIUM CVSS 4.3 2024-05-02
Threat Entry Updated 2025-01-08

CVE-2024-1567 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on the affected site's server which may make cross-site scripting or remote code execution possible.

PLUGIN Royal Elementor Addons

CVE-2024-1567

HIGH CVSS 8.2 2024-05-02
Threat Entry Updated 2025-03-05

CVE-2024-1572 - Wp Ulike Plugin

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_ulike' shortcode in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping on the user supplied 'wrapper_class' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Ulike

CVE-2024-1572

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-29

CVE-2024-1533 - Shortcodes And Extra Features For Phlox Theme

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML Element in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Requires Elementor and the Phlox theme to be installed.

THEME Shortcodes And Extra Features For Phlox Theme

CVE-2024-1533

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-06-05

CVE-2024-1584 - Analytify Google Analytics Dashboard Plugin

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated attackers to modify the site's Google Analytics tracking ID.

PLUGIN Analytify Google Analytics Dashboard

CVE-2024-1584

MEDIUM CVSS 5.3 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2024-1416 - Lead Form Builder Plugin

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on several functions in all versions up to, and including, 1.8.9. This makes it possible for unauthenticated attackers to invoke those functions.

PLUGIN Lead Form Builder

CVE-2024-1416

MEDIUM CVSS 4.3 2024-05-02
Scroll to top