Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,129
Critical1,380
High4,682
Medium12,810
Reset
Showing 11401-11420 of 19129 records
Threat Entry Updated 2024-11-23

CVE-2024-9223 - Wpdash Notes Plugin

The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_ajax_post_it_list_comment' function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view comments on any post, including private and password protected posts, and pending and draft posts if they were previously published. The vulnerability was partially patched in version 1.3.5.

PLUGIN Wpdash Notes

CVE-2024-9223

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2024-12-06

CVE-2024-10961 - Oa Social Login Plugin

The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

PLUGIN Oa Social Login

CVE-2024-10961

CRITICAL CVSS 9.8 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11415 - Wp Orphanage Extended Plugin

The WP-Orphanage Extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the wporphanageex_menu_settings() function. This makes it possible for unauthenticated attackers to escalate the privileges of all orphan accounts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Orphanage Extended

CVE-2024-11415

HIGH CVSS 8.8 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-10886 - Tribute Testimonial Gridslider Plugin

The Tribute Testimonials – WordPress Testimonial Grid/Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tribute_testimonials_slider' shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tribute Testimonial Gridslider

CVE-2024-10886

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-10874 - Quotes Llama Plugin

The Quotes llama plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quotes-llama' shortcode in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Quotes Llama

CVE-2024-10874

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11463 - Debounce Email Validator Plugin

The DeBounce Email Validator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'from', 'to', and 'key' parameters in all versions up to, and including, 5.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Debounce Email Validator

CVE-2024-11463

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-11362 - Peachpay For Woocommerce Plugin

The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.112.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Peachpay For Woocommerce

CVE-2024-11362

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2024-11-23

CVE-2024-10869 - Stop Brute Force Attacks Plugin

The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Stop Brute Force Attacks

CVE-2024-10869

MEDIUM CVSS 6.1 2024-11-23
Threat Entry Updated 2025-07-15

CVE-2024-10116 - Twitter Follow Button Plugin

The Twitter Follow Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'username' parameter in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Twitter Follow Button

CVE-2024-10116

MEDIUM CVSS 6.4 2024-11-23
Threat Entry Updated 2025-07-12

CVE-2024-10813 - Woo Product Table Plugin

The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1 via the var_dump_table parameter. This makes it possible for unauthenticated attackers var data.

PLUGIN Woo Product Table

CVE-2024-10813

MEDIUM CVSS 5.3 2024-11-23
Threat Entry Updated 2025-01-23

CVE-2024-10868 - Enter Addons Plugin

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.9 via the Advanced Tabs widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.

PLUGIN Enter Addons

CVE-2024-10868

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2025-02-07

CVE-2024-10537 - Wp User Manager Plugin

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_user_meta_key() function in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate user meta keys.

PLUGIN Wp User Manager

CVE-2024-10537

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2025-02-07

CVE-2024-10216 - Wp User Manager Plugin

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add or remove a Carbon Fields custom sidebar if the Carbon Fields (carbon-fields) plugin is installed.

PLUGIN Wp User Manager

CVE-2024-10216

MEDIUM CVSS 4.3 2024-11-23
Threat Entry Updated 2025-06-09

CVE-2024-9422 - Gmw Premium Settings Plugin

The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

PLUGIN Gmw Premium Settings

CVE-2024-9422

MEDIUM CVSS 6.6 2024-11-22
Threat Entry Updated 2025-02-11

CVE-2024-8735 - Mailmunch Plugin

The MailMunch – Grow your Email List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.1.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Mailmunch

CVE-2024-8735

MEDIUM CVSS 6.1 2024-11-22
Threat Entry Updated 2025-02-05

CVE-2024-11601 - Sky Addons For Elementor Plugin

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect nonce validation on the save_options() function. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Please note this…

PLUGIN Sky Addons For Elementor

CVE-2024-11601

HIGH CVSS 8.1 2024-11-22
Threat Entry Updated 2025-02-05

CVE-2024-11104 - Sky Addons For Elementor Plugin

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the save_options() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. Please note this is limited to option values that can be saved as arrays.

PLUGIN Sky Addons For Elementor

CVE-2024-11104

HIGH CVSS 8.1 2024-11-22
Threat Entry Updated 2024-11-22

CVE-2024-11381 - Control Horas Plugin

The Control horas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ch_registro' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Control Horas

CVE-2024-11381

MEDIUM CVSS 6.4 2024-11-22
Threat Entry Updated 2024-11-22

CVE-2024-11225 - Wpdm Premium Packages Plugin

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.9.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wpdm Premium Packages

CVE-2024-11225

MEDIUM CVSS 6.1 2024-11-22
Threat Entry Updated 2024-11-22

CVE-2024-11355 - Ultimate Youtube Video Player Plugin

The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_setting() function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view settings for playlists.

PLUGIN Ultimate Youtube Video Player

CVE-2024-11355

MEDIUM CVSS 4.3 2024-11-22
Scroll to top