Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,008
Critical1,352
High4,609
Medium12,761
Reset
Showing 11261-11280 of 19008 records
Threat Entry Updated 2024-11-26

CVE-2024-9942 - Wordpress Gym Management System Plugin

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Wordpress Gym Management System

CVE-2024-9942

CRITICAL CVSS 9.8 2024-11-23
Threat Entry Updated 2024-11-26

CVE-2024-9941 - Wordpress Gym Management System Plugin

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new user accounts with the administrator role.

PLUGIN Wordpress Gym Management System

CVE-2024-9941

HIGH CVSS 8.8 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-9660 - School Management System Plugin

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_load_documets_new() and mj_smgt_load_documets() functions in all versions up to, and including, 91.5.0. This makes it possible for authenticated attackers, with Student-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN School Management System

CVE-2024-9660

HIGH CVSS 8.8 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-9659 - School Management System Plugin

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN School Management System

CVE-2024-9659

CRITICAL CVSS 9.8 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-9511 - Fluent Smtp Plugin

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.82 via deserialization of untrusted input in the 'formatResult' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary…

PLUGIN Fluent Smtp

CVE-2024-9511

CRITICAL CVSS 9.8 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-10803 - Mp3 Sticky Player Plugin

The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Please note the vendor released the patched version as the same version as the affected version.

PLUGIN Mp3 Sticky Player

CVE-2024-10803

HIGH CVSS 7.5 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-9635 - Wc Cashapp Plugin

The Checkout with Cash App on WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wp_http_referer' parameter in several files in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wc Cashapp

CVE-2024-9635

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11446 - Chessgame Shizzle Plugin

The Chessgame Shizzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'cs_nonce' parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Chessgame Shizzle

CVE-2024-11446

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11330 - Custom Css Plugin

The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Custom Css

CVE-2024-11330

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11265 - Wp Maximum Upload File Size Plugin

The Increase Maximum Upload File Size | Increase Execution Time plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.3. This is due to returning image upload error messages with full path information. This makes it possible for authenticated attackers, with author-level permissions and above, to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected…

PLUGIN Wp Maximum Upload File Size

CVE-2024-11265

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-11188 - Formidable Forms Plugin

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Formidable Forms

CVE-2024-11188

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11426 - Autolisticle Automatically Update Numbered List Articles Plugin

The AutoListicle: Automatically Update Numbered List Articles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-list-number' shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Autolisticle Automatically Update Numbered List Articles

CVE-2024-11426

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-10873 - Element Kit For Elementor Plugin

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the _load_template function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Element Kit For Elementor

CVE-2024-10873

HIGH CVSS 8.8 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11408 - Slotti Ajanvaraus Plugin

The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti' shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slotti Ajanvaraus

CVE-2024-11408

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11387 - Easy Liveblogs Plugin

The Easy Liveblogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elb_liveblog' shortcode in all versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Liveblogs

CVE-2024-11387

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11332 - Sign Hipaa Documents Plugin

The HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hipaatizer' shortcode in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sign Hipaa Documents

CVE-2024-11332

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11361 - Pdf Invoicing For Woocommerce Plugin

The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Pdf Invoicing For Woocommerce

CVE-2024-11361

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-10880 - Jobboardwp Plugin

The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Jobboardwp

CVE-2024-10880

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2025-02-11

CVE-2024-10606 - Wp Travel Engine Plugin

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpte_onboard_save_function_callback() function in all versions up to, and including, 6.2.1. This makes it possible for authenticated attackers, with contributor-level access and above, to modify several settings that could have an impact such as lost revenue and page updates.

PLUGIN Wp Travel Engine

CVE-2024-10606

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-9223 - Wpdash Notes Plugin

The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_ajax_post_it_list_comment' function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view comments on any post, including private and password protected posts, and pending and draft posts if they were previously published. The vulnerability was partially patched in version 1.3.5.

PLUGIN Wpdash Notes

CVE-2024-9223

MEDIUM CVSS 4.3 2024-11-23
Scroll to top