Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,008
Critical1,352
High4,609
Medium12,761
Reset
Showing 10821-10840 of 19008 records
Threat Entry Updated 2024-12-18

CVE-2024-11912 - Travel Booking Wordpress Theme

The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id’ parameter in all versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

THEME Travel Booking Wordpress Theme

CVE-2024-11912

HIGH CVSS 7.5 2024-12-18
Threat Entry Updated 2025-02-04

CVE-2024-11291 - Membership Content Restriction Paid Member Subscriptions Plugin

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.4 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as logged-in users.

PLUGIN Membership Content Restriction Paid Member Subscriptions

CVE-2024-11291

MEDIUM CVSS 5.3 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-12454 - Slicewp Affiliates Plugin

The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.23. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Slicewp Affiliates

CVE-2024-12454

MEDIUM CVSS 6.1 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-12554 - Peters Custom Anti Spam Image Plugin

The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is due to missing nonce validation on the cas_register_post() function. This makes it possible for unauthenticated attackers to blacklist emails via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Peters Custom Anti Spam Image

CVE-2024-12554

MEDIUM CVSS 5.4 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-12340 - Animation Addons For Elementor Plugin

The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the 'render' function in widgets/content-slider.php and widgets/tabs.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft Elementor template data.

PLUGIN Animation Addons For Elementor

CVE-2024-12340

MEDIUM CVSS 4.3 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-12287 - Biagiotti Membership Plugin

The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, such as administrators, granted they have access to an email.

PLUGIN Biagiotti Membership

CVE-2024-12287

CRITICAL CVSS 9.8 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-11295 - Simple Page Access Restriction Plugin

The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as logged-in users.

PLUGIN Simple Page Access Restriction

CVE-2024-11295

MEDIUM CVSS 5.3 2024-12-18
Threat Entry Updated 2025-05-14

CVE-2024-10892 - Cost Calculator Builder Plugin

The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

PLUGIN Cost Calculator Builder

CVE-2024-10892

MEDIUM CVSS 5.4 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-12449 - Turnkey Video Site Builder Script Plugin

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_player_html' shortcode in all versions up to, and including, 2.6.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Turnkey Video Site Builder Script

CVE-2024-12449

MEDIUM CVSS 6.4 2024-12-18
Threat Entry Updated 2025-07-11

CVE-2024-12596 - Lifterlms Plugin

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts.

PLUGIN Lifterlms

CVE-2024-12596

MEDIUM CVSS 4.3 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-12259 - Repairbuddy Plugin

The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior to updating their email through the wc_update_user_data AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

PLUGIN Repairbuddy

CVE-2024-12259

HIGH CVSS 8.8 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-12432 - Wpc Shop As A Customer For Woocommerce Plugin

The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently random value. This makes it possible for authenticated attackers, with Subscriber-level access and above, to log in as site administrators, granted they have triggered the ajax_login() function which generates a unique key that can be used to log in.

PLUGIN Wpc Shop As A Customer For Woocommerce

CVE-2024-12432

HIGH CVSS 8.1 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-12025 - Collapsing Categories Plugin

The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Collapsing Categories

CVE-2024-12025

HIGH CVSS 7.5 2024-12-18
Threat Entry Updated 2025-02-28

CVE-2024-11254 - Accelerated Mobile Pages Plugin

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Accelerated Mobile Pages

CVE-2024-11254

MEDIUM CVSS 6.1 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-12250 - Net Payments Using Contact Form 7 Plugin

The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2 via the cf7adn-info.php file. This makes it possible for unauthenticated attackers to extract configuration data which can be used to aid in other attacks.

PLUGIN Net Payments Using Contact Form 7

CVE-2024-12250

MEDIUM CVSS 5.3 2024-12-18
Threat Entry Updated 2025-06-05

CVE-2024-12061 - Events Addon For Elementor Plugin

The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.3 via the naevents_elementor_template shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.

PLUGIN Events Addon For Elementor

CVE-2024-12061

MEDIUM CVSS 4.3 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-12513 - Contests By Rewards Fuel Plugin

The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONTEST' shortcode in all versions up to, and including, 2.0.65 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Contests By Rewards Fuel

CVE-2024-12513

MEDIUM CVSS 6.4 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-12500 - Donations And Donor Management Plugin

The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Donations And Donor Management

CVE-2024-12500

MEDIUM CVSS 6.4 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-11881 - Easy Waveform Player Plugin

The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywaveformplayer' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Waveform Player

CVE-2024-11881

MEDIUM CVSS 6.4 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-11748 - Taeggie Feed Plugin

The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'taeggie-feed' shortcode in all versions up to, and including, 0.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Taeggie Feed

CVE-2024-11748

MEDIUM CVSS 6.4 2024-12-18
Scroll to top