Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,129
Critical1,380
High4,682
Medium12,810
Reset
Showing 11681-11700 of 19129 records
Threat Entry Updated 2024-11-08

CVE-2024-10647 - Ws Form Plugin

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.244. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Ws Form

CVE-2024-10647

MEDIUM CVSS 6.1 2024-11-06
Threat Entry Updated 2024-11-08

CVE-2024-10028 - Everest Backup Plugin

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process. This makes it possible for unauthenticated attackers to obtain an archive file name and download the site's backup.

PLUGIN Everest Backup

CVE-2024-10028

HIGH CVSS 7.5 2024-11-06
Threat Entry Updated 2025-07-11

CVE-2024-10084 - Contact Form 7 Dynamic Text Extension Plugin

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract the titles and text contents of private and password-protected posts, they do not own.

PLUGIN Contact Form 7 Dynamic Text Extension

CVE-2024-10084

MEDIUM CVSS 4.3 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-10329 - Ultimate Bootstrap Elements For Elementor Plugin

The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the 'ube_get_page_templates' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the contents of templates that are private.

PLUGIN Ultimate Bootstrap Elements For Elementor

CVE-2024-10329

MEDIUM CVSS 4.3 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-10263 - Tickera Plugin

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Tickera

CVE-2024-10263

HIGH CVSS 7.3 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-9657 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip' parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-9657

MEDIUM CVSS 6.5 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-9867 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Open Map Widget' marker_content parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-9867

MEDIUM CVSS 5.4 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-9178 - Xt Floating Cart For Woocommerce Plugin

The XT Floating Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Xt Floating Cart For Woocommerce

CVE-2024-9178

MEDIUM CVSS 6.4 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-10319 - Xpro Addons For Elementor Plugin

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the render function in widgets/content-toggle/layout/frontend.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

PLUGIN Xpro Addons For Elementor

CVE-2024-10319

MEDIUM CVSS 4.3 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-9878 - Photo Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Photo Gallery

CVE-2024-9878

MEDIUM CVSS 4.4 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-7429 - Zotpress Plugin

The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Zotpress_process_accounts_AJAX function in all versions up to, and including, 7.3.12. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset the plugin's settings.

PLUGIN Zotpress

CVE-2024-7429

MEDIUM CVSS 4.3 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-10687 - Contest Gallery Plugin

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and including, 24.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Contest Gallery

CVE-2024-10687

CRITICAL CVSS 9.8 2024-11-05
Threat Entry Updated 2024-11-07

CVE-2024-9443 - Framework Plugin

The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Framework

CVE-2024-9443

MEDIUM CVSS 6.4 2024-11-05
Threat Entry Updated 2024-11-08

CVE-2024-9667 - Seriously Simple Podcasting Plugin

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.5.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Seriously Simple Podcasting

CVE-2024-9667

MEDIUM CVSS 6.1 2024-11-05
Threat Entry Updated 2024-11-07

CVE-2024-10711 - Woocommerce Report Plugin

The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update arbitrary options that can be leveraged for privilege escalation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Woocommerce Report

CVE-2024-10711

HIGH CVSS 8.8 2024-11-05
Threat Entry Updated 2025-08-01

CVE-2024-10114 - Woocommerce Social Login Plugin

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

PLUGIN Woocommerce Social Login

CVE-2024-10114

HIGH CVSS 8.1 2024-11-05
Threat Entry Updated 2024-11-06

CVE-2024-10097 - Loginizer Plugin

The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

PLUGIN Loginizer

CVE-2024-10097

HIGH CVSS 8.1 2024-11-05
Threat Entry Updated 2024-11-06

CVE-2024-9883 - Before 3 Plugin

The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2024-9883

MEDIUM CVSS 4.8 2024-11-05
Threat Entry Updated 2024-12-20

CVE-2024-9689 - Post From Frontend Plugin

The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin perform such action via a CSRF attack

PLUGIN Post From Frontend

CVE-2024-9689

MEDIUM CVSS 4.3 2024-11-05
Threat Entry Updated 2024-11-06

CVE-2024-7877 - Simply Schedule Appointments Booking Plugin

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Simply Schedule Appointments Booking

CVE-2024-7877

MEDIUM CVSS 4.8 2024-11-05
Scroll to top