Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,129
Critical1,380
High4,682
Medium12,810
Reset
Showing 11501-11520 of 19129 records
Threat Entry Updated 2024-11-19

CVE-2024-9830 - Bard Theme

The Bard theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.216. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Bard

CVE-2024-9830

MEDIUM CVSS 6.1 2024-11-19
Threat Entry Updated 2024-11-19

CVE-2024-11224 - Parallax Image Plugin

The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘position’ parameter in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Parallax Image

CVE-2024-11224

MEDIUM CVSS 6.4 2024-11-19
Threat Entry Updated 2024-11-19

CVE-2024-11198 - Gd Rating System Plugin

The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gd Rating System

CVE-2024-11198

MEDIUM CVSS 6.4 2024-11-19
Threat Entry Updated 2024-11-29

CVE-2024-9777 - Ashe Plugin

The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.243. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Ashe

CVE-2024-9777

MEDIUM CVSS 6.1 2024-11-19
Threat Entry Updated 2024-11-19

CVE-2024-11194 - Classified Listing Plugin

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigured check on the 'rtcl_import_settings' function in all versions up to, and including, 3.1.15.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update limited arbitrary options on the WordPress site. This can be leveraged to update the Subscriber role with Administrator-level capabilities to gain administrative user access to a vulnerable site. The vulnerability is limited in…

PLUGIN Classified Listing

CVE-2024-11194

HIGH CVSS 8.8 2024-11-19
Threat Entry Updated 2025-07-09

CVE-2024-11038 - Wpb Popup For Contact Form 7 Plugin

The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress is vulnerable to arbitrary shortcode execution via wpb_pcf_fire_contact_form AJAX action in all versions up to, and including, 1.7.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Wpb Popup For Contact Form 7

CVE-2024-11038

HIGH CVSS 7.3 2024-11-19
Threat Entry Updated 2025-07-09

CVE-2024-11195 - Email Subscription Popup Plugin

The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_email_subscribe_form shortcode in all versions up to, and including, 1.2.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Email Subscription Popup

CVE-2024-11195

MEDIUM CVSS 6.4 2024-11-19
Threat Entry Updated 2025-02-04

CVE-2024-11036 - Gamipress Plugin

The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_get_user_earnings AJAX action in all versions up to, and including, 7.1.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Gamipress

CVE-2024-11036

HIGH CVSS 7.3 2024-11-19
Threat Entry Updated 2025-01-23

CVE-2024-10388 - Wordpress Gdpr Plugin

The WordPress GDPR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_firstname' and 'gdpr_lastname' parameters in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wordpress Gdpr

CVE-2024-10388

HIGH CVSS 7.2 2024-11-19
Threat Entry Updated 2025-01-23

CVE-2024-11069 - Wordpress Gdpr Plugin

The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'WordPress_GDPR_Data_Delete::check_action' function in all versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to delete arbitrary users.

PLUGIN Wordpress Gdpr

CVE-2024-11069

MEDIUM CVSS 6.5 2024-11-19
Threat Entry Updated 2024-11-19

CVE-2024-11098 - Svg Block Plugin

The SVG Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Svg Block

CVE-2024-11098

MEDIUM CVSS 5.5 2024-11-19
Threat Entry Updated 2025-01-17

CVE-2024-10268 - Mp3 Audio Player For Music Radio Podcast Plugin

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mp3 Audio Player For Music Radio Podcast

CVE-2024-10268

MEDIUM CVSS 6.4 2024-11-19
Threat Entry Updated 2025-06-12

CVE-2024-10103 - In The Process Of Testing The Mailpoet Plugin

In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

PLUGIN In The Process Of Testing The Mailpoet

CVE-2024-10103

MEDIUM CVSS 6.1 2024-11-19
Threat Entry Updated 2024-11-19

CVE-2024-10486 - Google Listings And Ads Plugin

The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attackers to retrieve information about Webserver and PHP configuration, which can be used to aid other attacks.

PLUGIN Google Listings And Ads

CVE-2024-10486

MEDIUM CVSS 5.3 2024-11-18
Threat Entry Updated 2024-11-19

CVE-2024-10390 - Elfsight Telegram Chat Cc Plugin

The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'updatePreferences' function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elfsight Telegram Chat Cc

CVE-2024-10390

MEDIUM CVSS 6.4 2024-11-18
Threat Entry Updated 2024-11-20

CVE-2024-52431 - Wordpress Video Robot Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pressaholic WordPress Video Robot - The Ultimate Video Importer allows SQL Injection.This issue affects WordPress Video Robot - The Ultimate Video Importer: from n/a through 1.20.0.

PLUGIN Wordpress Video Robot

CVE-2024-52431

CRITICAL CVSS 9.3 2024-11-18
Threat Entry Updated 2025-05-15

CVE-2024-5030 - Cm Table Of Contents Plugin

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack

PLUGIN Cm Table Of Contents

CVE-2024-5030

LOW CVSS 3.8 2024-11-18
Threat Entry Updated 2024-11-18

CVE-2024-52408 - Push Notifications for WordPress by PushAssist Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Team PushAssist Push Notifications for WordPress by PushAssist allows Upload a Web Shell to a Web Server.This issue affects Push Notifications for WordPress by PushAssist: from n/a through 3.0.8.

PLUGIN Push Notifications for WordPress by PushAssist

CVE-2024-52408

CRITICAL CVSS 9.9 2024-11-16
Threat Entry Updated 2024-11-18

CVE-2024-9887 - Miniorange Wp As Saml Idp Plugin

The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.15.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Miniorange Wp As Saml Idp

CVE-2024-9887

HIGH CVSS 7.2 2024-11-16
Threat Entry Updated 2024-11-18

CVE-2024-10592 - Mapster Wp Maps Plugin

The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mapster Wp Maps

CVE-2024-10592

MEDIUM CVSS 6.4 2024-11-16
Scroll to top