Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,129
Critical1,380
High4,682
Medium12,810
Reset
Showing 11441-11460 of 19129 records
Threat Entry Updated 2024-11-21

CVE-2024-11435 - Salavat Counter Plugin

The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 0.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Salavat Counter

CVE-2024-11435

MEDIUM CVSS 6.1 2024-11-21
Threat Entry Updated 2024-11-21

CVE-2024-11428 - Lazy Load Videos And Sticky Control Plugin

The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lazy-load-videos-and-sticky-control' shortcode in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Lazy Load Videos And Sticky Control

CVE-2024-11428

MEDIUM CVSS 6.4 2024-11-21
Threat Entry Updated 2024-11-21

CVE-2024-11424 - Slick Sitemap Plugin

The Slick Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slick-sitemap' shortcode in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slick Sitemap

CVE-2024-11424

MEDIUM CVSS 6.4 2024-11-21
Threat Entry Updated 2024-11-21

CVE-2024-11416 - Wip Incoming Lite Plugin

The WIP Incoming Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the save_option() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wip Incoming Lite

CVE-2024-11416

MEDIUM CVSS 6.1 2024-11-21
Threat Entry Updated 2024-11-21

CVE-2024-11414 - Recipepress Reloaded Plugin

The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all versions up to, and including, 2.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Recipepress Reloaded

CVE-2024-11414

MEDIUM CVSS 6.4 2024-11-21
Threat Entry Updated 2024-11-21

CVE-2024-11412 - Shine Pdf Plugin

The Shine PDF Embeder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shinepdf' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shine Pdf

CVE-2024-11412

MEDIUM CVSS 6.4 2024-11-21
Threat Entry Updated 2024-11-21

CVE-2024-11409 - Grid View Gallery Plugin

The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input from cs_all_photos_details parameter. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Grid View Gallery

CVE-2024-11409

HIGH CVSS 7.2 2024-11-21
Threat Entry Updated 2024-11-26

CVE-2024-11388 - Dino Game Plugin

The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dino-game' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Dino Game

CVE-2024-11388

MEDIUM CVSS 6.4 2024-11-21
Threat Entry Updated 2024-11-26

CVE-2024-11385 - Pure Css Circle Progress Bar Plugin

The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'circle_progress' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Pure Css Circle Progress Bar

CVE-2024-11385

MEDIUM CVSS 6.4 2024-11-21
Threat Entry Updated 2024-12-16

CVE-2024-11371 - Theater For Wordpress Plugin

The Theater for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 0.18.6.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Theater For Wordpress

CVE-2024-11371

MEDIUM CVSS 6.1 2024-11-21
Threat Entry Updated 2024-11-26

CVE-2024-11370 - Subaccounts For Woocommerce Plugin

The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Subaccounts For Woocommerce

CVE-2024-11370

MEDIUM CVSS 6.1 2024-11-21
Threat Entry Updated 2024-11-26

CVE-2024-11365 - Crypto And Defi Widgets Plugin

The Crypto and DeFi Widgets – Web3 Cryptocurrency Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Crypto And Defi Widgets

CVE-2024-11365

MEDIUM CVSS 6.1 2024-11-21
Threat Entry Updated 2024-11-26

CVE-2024-11360 - Page Parts Plugin

The Page Parts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Page Parts

CVE-2024-11360

MEDIUM CVSS 6.1 2024-11-21
Threat Entry Updated 2024-11-26

CVE-2024-11354 - Ultimate Youtube Video Shorts Player With Vimeo Plugin

The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the del_ytsingvid() function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete single playlists.

PLUGIN Ultimate Youtube Video Shorts Player With Vimeo

CVE-2024-11354

MEDIUM CVSS 4.3 2024-11-21
Threat Entry Updated 2024-11-26

CVE-2024-11334 - My Contador Lesr Plugin

The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportar_registros() function in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to export user data.

PLUGIN My Contador Lesr

CVE-2024-11334

MEDIUM CVSS 4.3 2024-11-21
Threat Entry Updated 2024-11-21

CVE-2024-11197 - Lock User Account Plugin

The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5. This is due to permitting application password logins when user accounts are locked. This makes it possible for authenticated attackers, with existing application passwords, to interact with the vulnerable site via an API such as XML-RPC or REST despite their account being locked.

PLUGIN Lock User Account

CVE-2024-11197

MEDIUM CVSS 4.2 2024-11-21
Threat Entry Updated 2024-11-26

CVE-2024-10898 - Contact Form 7 Email Add On Plugin

The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the cf7_email_add_on_add_admin_template() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php files can be uploaded and included.

PLUGIN Contact Form 7 Email Add On

CVE-2024-10898

HIGH CVSS 8.8 2024-11-21
Threat Entry Updated 2024-11-21

CVE-2024-10890 - Wpadverts Plugin

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wpadverts

CVE-2024-10890

MEDIUM CVSS 6.1 2024-11-21
Threat Entry Updated 2025-07-09

CVE-2024-10788 - Activity Log Plugin

The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page.

PLUGIN Activity Log

CVE-2024-10788

HIGH CVSS 7.2 2024-11-21
Threat Entry Updated 2025-02-07

CVE-2024-10785 - Gutenberg Blocks With Ai Plugin

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Blocks With Ai

CVE-2024-10785

MEDIUM CVSS 6.4 2024-11-21
Scroll to top