Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,129
Critical1,380
High4,682
Medium12,810
Reset
Showing 11661-11680 of 19129 records
Threat Entry Updated 2025-05-15

CVE-2024-7982 - Registrations For The Events Calendar Plugin

The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

PLUGIN Registrations For The Events Calendar

CVE-2024-7982

CRITICAL CVSS 9.6 2024-11-08
Threat Entry Updated 2024-11-08

CVE-2024-10621 - Simple Shortcode For Google Maps Plugin

The Simple Shortcode for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pw_map shortcode in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Shortcode For Google Maps

CVE-2024-10621

MEDIUM CVSS 6.4 2024-11-08
Threat Entry Updated 2025-05-17

CVE-2024-8378 - Safe Svg Plugin

The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.

PLUGIN Safe Svg

CVE-2024-8378

MEDIUM CVSS 4.8 2024-11-07
Threat Entry Updated 2025-05-28

CVE-2024-9926 - Jetpack Plugin

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

PLUGIN Jetpack

CVE-2024-9926

MEDIUM CVSS 4.3 2024-11-07
Threat Entry Updated 2025-02-05

CVE-2024-8442 - Prime Slider Plugin

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Prime Slider

CVE-2024-8442

MEDIUM CVSS 6.4 2024-11-07
Threat Entry Updated 2025-05-15

CVE-2024-10027 - Wp Booking Calendar Plugin

The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Wp Booking Calendar

CVE-2024-10027

MEDIUM CVSS 4.8 2024-11-07
Threat Entry Updated 2024-11-08

CVE-2024-10186 - Event Post Plugin

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Event Post

CVE-2024-10186

MEDIUM CVSS 6.4 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10168 - Woot Plugin

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions up to, and including, 1.0.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Woot

CVE-2024-10168

MEDIUM CVSS 6.4 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-8323 - Easy Pricing Tables Plugin

The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fontFamily’ attribute in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Pricing Tables

CVE-2024-8323

MEDIUM CVSS 6.4 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10715 - Mappress Plugin

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mappress

CVE-2024-10715

MEDIUM CVSS 6.4 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-8615 - Jobsearch Wp Job Board Plugin

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Jobsearch Wp Job Board

CVE-2024-8615

CRITICAL CVSS 10.0 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-8614 - Jobsearch Wp Job Board Plugin

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Jobsearch Wp Job Board

CVE-2024-8614

CRITICAL CVSS 9.9 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-9307 - Mfolio Plugin

The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file or upload arbitrary EXE files on the affected site's server which may make remote code execution possible if the attacker can also gain access to run the .exe file, or trick a site visitor into downloading…

PLUGIN Mfolio

CVE-2024-9307

CRITICAL CVSS 9.9 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-9946 - Super Socializer Plugin

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they have access to the email and the user does not have an already-existing account for the service returning the token. An attacker cannot authenticate as an administrator…

PLUGIN Super Socializer

CVE-2024-9946

HIGH CVSS 8.1 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-6626 - Eleforms Plugin

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several functions in all versions up to, and including, 2.9.9.9. This makes it possible for unauthenticated attackers to view form submissions.

PLUGIN Eleforms

CVE-2024-6626

MEDIUM CVSS 5.3 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10543 - Tumult Hype Animations Plugin

The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hypeanimations_getcontent function in all versions up to, and including, 1.9.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve animation information.

PLUGIN Tumult Hype Animations

CVE-2024-10543

MEDIUM CVSS 4.3 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10020 - Social Login Plugin

The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they have access to the email and the user does not have an already-existing account for the service returning the token. An attacker cannot authenticate as an administrator by default, but these accounts are also…

PLUGIN Social Login

CVE-2024-10020

HIGH CVSS 8.1 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10535 - Video Gallery For Woocommerce Plugin

The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_unused_thumbnails() function in all versions up to, and including, 1.31. This makes it possible for unauthenticated attackers to delete thumbnails in the video-wc-gallery-thumb directory.

PLUGIN Video Gallery For Woocommerce

CVE-2024-10535

MEDIUM CVSS 5.3 2024-11-06
Threat Entry Updated 2025-05-17

CVE-2024-9934 - Wp Imagezoom Plugin

The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Wp Imagezoom

CVE-2024-9934

MEDIUM CVSS 6.1 2024-11-06
Threat Entry Updated 2025-04-11

CVE-2024-7879 - Wp Ulike Plugin

The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Wp Ulike

CVE-2024-7879

MEDIUM CVSS 4.8 2024-11-06
Scroll to top