Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,129
Critical1,380
High4,682
Medium12,810
Reset
Showing 11481-11500 of 19129 records
Threat Entry Updated 2024-11-21

CVE-2024-11154 - Approve And Schedule Content Changes Plugin

The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.15 via the 'actAjaxRevisionDiffs' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including revisions of posts and pages.

PLUGIN Approve And Schedule Content Changes

CVE-2024-11154

MEDIUM CVSS 4.3 2024-11-20
Threat Entry Updated 2025-02-05

CVE-2024-10520 - Wp Project Manager Plugin

The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to create milestones, create task lists, create tasks, or delete tasks in any project. NOTE: Version 2.6.14 implemented a partial fix for this vulnerability.

PLUGIN Wp Project Manager

CVE-2024-10520

MEDIUM CVSS 5.3 2024-11-20
Threat Entry Updated 2024-11-23

CVE-2024-10872 - Getwid Plugin

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-custom-field` block in all versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Getwid

CVE-2024-10872

MEDIUM CVSS 6.4 2024-11-20
Threat Entry Updated 2024-11-22

CVE-2024-11179 - Mstore Api Plugin

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Mstore Api

CVE-2024-11179

MEDIUM CVSS 6.5 2024-11-20
Threat Entry Updated 2025-07-09

CVE-2024-10891 - Save As Pdf Plugin

The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'save_as_pdf_pdfcrowd' shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Save As Pdf

CVE-2024-10891

MEDIUM CVSS 6.4 2024-11-20
Threat Entry Updated 2024-11-21

CVE-2024-10665 - Yaad Sarig Payment Gateway For Wc Plugin

The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data due to a missing capability check on the yaadpay_view_log_callback() and yaadpay_delete_log_callback() functions in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view and delete logs.

PLUGIN Yaad Sarig Payment Gateway For Wc

CVE-2024-10665

MEDIUM CVSS 5.4 2024-11-20
Threat Entry Updated 2025-02-05

CVE-2024-9239 - Booster For Woocommerce Plugin

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Booster For Woocommerce

CVE-2024-9239

MEDIUM CVSS 6.1 2024-11-20
Threat Entry Updated 2024-11-26

CVE-2024-11277 - 404 Solution Plugin

The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 2.35.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN 404 Solution

CVE-2024-11277

MEDIUM CVSS 6.1 2024-11-20
Threat Entry Updated 2024-11-29

CVE-2024-8726 - Mailchimp Forms Plugin

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Mailchimp Forms

CVE-2024-8726

MEDIUM CVSS 6.1 2024-11-20
Threat Entry Updated 2024-11-26

CVE-2024-10899 - Woocommerce Product Table Plugin

The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The same 'id' parameter is vulnerable to Reflected Cross-Site Scripting as well.

PLUGIN Woocommerce Product Table

CVE-2024-10899

HIGH CVSS 7.3 2024-11-20
Threat Entry Updated 2024-11-29

CVE-2024-10900 - Profilegrid Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_file_attachment() function in all versions up to, and including, 5.9.3.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary user meta which can do things like deny an administrator's access to their site. .

PLUGIN Profilegrid

CVE-2024-10900

MEDIUM CVSS 6.5 2024-11-20
Threat Entry Updated 2024-11-26

CVE-2024-10855 - Sirv Plugin

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the filename parameter of the sirv_upload_file_by_chunks() function and lack of in all versions up to, and including, 7.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary option values on the WordPress site. This can be leveraged to delete an option that would create an error on the site and deny service to…

PLUGIN Sirv

CVE-2024-10855

HIGH CVSS 8.1 2024-11-20
Threat Entry Updated 2024-11-26

CVE-2024-10365 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.3 via the render function in modules/widgets/tp_carousel_anything.php, modules/widgets/tp_page_scroll.php, and other widgets. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

PLUGIN Plus Addons For Elementor

CVE-2024-10365

MEDIUM CVSS 4.3 2024-11-20
Threat Entry Updated 2024-11-26

CVE-2024-9653 - Restaurant Menu Food Ordering System Table Reservation Plugin

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Restaurant Menu Food Ordering System Table Reservation

CVE-2024-9653

MEDIUM CVSS 6.1 2024-11-20
Threat Entry Updated 2025-03-31

CVE-2024-10515 - In The Process Of Testing The Seo Plugin By Squirrly Seo

In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

PLUGIN In The Process Of Testing The Seo Plugin By Squirrly Seo

CVE-2024-10515

LOW CVSS 3.5 2024-11-20
Threat Entry Updated 2024-11-21

CVE-2024-11278 - Gd Bbpress Attachments Plugin

The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Gd Bbpress Attachments

CVE-2024-11278

MEDIUM CVSS 6.1 2024-11-20
Threat Entry Updated 2024-11-25

CVE-2024-11400 - Woocommerce Products Filter Plugin

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the really_curr_tax parameter in all versions up to, and including, 1.3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Woocommerce Products Filter

CVE-2024-11400

MEDIUM CVSS 6.1 2024-11-19
Threat Entry Updated 2024-11-19

CVE-2024-51807 - AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Black and White Digital Ltd AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress allows Stored XSS.This issue affects AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress: from n/a through 1.0.8.

PLUGIN AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress

CVE-2024-51807

MEDIUM CVSS 6.5 2024-11-19
Threat Entry Updated 2024-11-19

CVE-2024-51634 - Webriti Custom Login Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Webriti WordPress Themes & Plugins Shop Webriti Custom Login allows Reflected XSS.This issue affects Webriti Custom Login: from n/a through 0.3.

PLUGIN Webriti Custom Login

CVE-2024-51634

HIGH CVSS 7.1 2024-11-19
Threat Entry Updated 2024-11-19

CVE-2024-50541 - Advanced Control Manager for WordPress by ItalyStrap Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enea Overclokk Advanced Control Manager for WordPress by ItalyStrap allows Stored XSS.This issue affects Advanced Control Manager for WordPress by ItalyStrap: from n/a through 2.16.0.

PLUGIN Advanced Control Manager for WordPress by ItalyStrap

CVE-2024-50541

MEDIUM CVSS 6.5 2024-11-19
Scroll to top