Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,008
Critical1,352
High4,609
Medium12,761
Reset
Showing 11181-11200 of 19008 records
Threat Entry Updated 2025-07-09

CVE-2024-11453 - Gs Pinterest Portfolio Plugin

The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_pin_widget' shortcode in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gs Pinterest Portfolio

CVE-2024-11453

MEDIUM CVSS 6.4 2024-12-03
Threat Entry Updated 2025-01-29

CVE-2024-9058 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lightbox widget in all versions up to, and including, 5.10.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-9058

MEDIUM CVSS 6.4 2024-12-03
Threat Entry Updated 2025-05-17

CVE-2024-10893 - Wp Booking Calendar Plugin

The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Wp Booking Calendar

CVE-2024-10893

MEDIUM CVSS 4.8 2024-12-03
Threat Entry Updated 2025-02-07

CVE-2024-10484 - Spectra Plugin

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Spectra

CVE-2024-10484

MEDIUM CVSS 6.4 2024-12-03
Threat Entry Updated 2024-12-03

CVE-2024-9694 - Cmsmasters Elementor Addon Plugin

The CMSMasters Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.14.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cmsmasters Elementor Addon

CVE-2024-9694

MEDIUM CVSS 6.4 2024-12-03
Threat Entry Updated 2025-02-10

CVE-2024-52478 - Jobify Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ben Marshall Jobify - Job Board WordPress Theme allows Stored XSS.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.

PLUGIN Jobify

CVE-2024-52478

MEDIUM CVSS 6.5 2024-12-02
Threat Entry Updated 2025-02-10

CVE-2024-52479 - Jobify Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Ben Marshall Jobify - Job Board WordPress Theme allows Cross Site Request Forgery.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.

PLUGIN Jobify

CVE-2024-52479

MEDIUM CVSS 4.3 2024-12-02
Threat Entry Updated 2024-12-02

CVE-2024-52461 - Infinite Slider Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kinsta WordPress Hosting Infinite Slider allows Reflected XSS.This issue affects Infinite Slider: from n/a through 2.0.1.

PLUGIN Infinite Slider

CVE-2024-52461

HIGH CVSS 7.1 2024-12-02
Threat Entry Updated 2024-11-30

CVE-2024-53788 - WordPress Portfolio Builder – Portfolio Gallery Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portfoliohub WordPress Portfolio Builder – Portfolio Gallery allows Stored XSS.This issue affects WordPress Portfolio Builder – Portfolio Gallery: from n/a through 1.1.7.

PLUGIN WordPress Portfolio Builder – Portfolio Gallery

CVE-2024-53788

MEDIUM CVSS 5.9 2024-11-30
Threat Entry Updated 2025-07-09

CVE-2024-11252 - Sassy Social Share Plugin

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.69 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Sassy Social Share

CVE-2024-11252

MEDIUM CVSS 6.1 2024-11-30
Threat Entry Updated 2025-05-07

CVE-2024-10980 - Before 5 Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 5

CVE-2024-10980

MEDIUM CVSS 5.4 2024-11-29
Threat Entry Updated 2025-05-07

CVE-2024-10704 - Photo Gallery By 10web Plugin

The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Photo Gallery By 10web

CVE-2024-10704

MEDIUM CVSS 4.8 2024-11-29
Threat Entry Updated 2025-07-15

CVE-2024-7747 - Terawallet Plugin

The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versions up to, and including, 1.5.6. This is due to a numerical logic flaw when transferring funds to another user. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create funds during a transfer and distribute these funds to any number of other users or their own account, rendering products free. Attackers could also request to withdraw funds if the Wallet Withdrawal extension is used and the request is…

PLUGIN Terawallet

CVE-2024-7747

MEDIUM CVSS 6.5 2024-11-28
Threat Entry Updated 2025-02-10

CVE-2024-52481 - Jobify Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Astoundify Jobify - Job Board WordPress Theme allows Relative Path Traversal.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.

PLUGIN Jobify

CVE-2024-52481

HIGH CVSS 7.5 2024-11-28
Threat Entry Updated 2024-11-28

CVE-2024-8672 - Widget Options Plugin

The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 via the display logic functionality that extends several page builders. This is due to the plugin allowing users to supply input that will be passed through eval() without any filtering or capability checks. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server. Special note: We suggested the vendor implement an allowlist of…

PLUGIN Widget Options

CVE-2024-8672

CRITICAL CVSS 9.9 2024-11-28
Threat Entry Updated 2025-04-11

CVE-2024-11103 - Contest Gallery Plugin

The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Contest Gallery

CVE-2024-11103

CRITICAL CVSS 9.8 2024-11-28
Threat Entry Updated 2024-11-28

CVE-2024-11082 - Tumult Hype Animations Plugin

The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hypeanimations_panel() function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Tumult Hype Animations

CVE-2024-11082

CRITICAL CVSS 9.9 2024-11-28
Threat Entry Updated 2025-03-04

CVE-2024-10798 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created via Elementor that they should not have access to.

PLUGIN Royal Elementor Addons

CVE-2024-10798

MEDIUM CVSS 4.3 2024-11-28
Threat Entry Updated 2025-07-14

CVE-2024-10780 - Restaurant Cafe Addon For Elementor Plugin

The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.9 via the 'narestaurant_elementor_template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.

PLUGIN Restaurant Cafe Addon For Elementor

CVE-2024-10780

MEDIUM CVSS 4.3 2024-11-28
Scroll to top