Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,140
Critical1,383
High4,684
Medium12,815
Reset
Showing 12061-12080 of 19140 records
Threat Entry Updated 2025-02-27

CVE-2024-9417 - Hash Form Plugin

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to upload files that are excluded from both the 'allowedExtensions' and 'unallowed_extensions' arrays on the affected site's server, including files that may contain cross-site scripting.

PLUGIN Hash Form

CVE-2024-9417

MEDIUM CVSS 6.1 2024-10-05
Threat Entry Updated 2025-05-22

CVE-2024-8486 - Shortcodes And Extra Features For Phlox Theme

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Shortcodes And Extra Features For Phlox Theme

CVE-2024-8486

MEDIUM CVSS 6.4 2024-10-05
Threat Entry Updated 2024-10-07

CVE-2024-8743 - Open Source File Manager And Code Editor For Wordpress Plugin

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an administrator, to upload .css and .js files, which could lead to Stored Cross-Site Scripting.

PLUGIN Open Source File Manager And Code Editor For Wordpress

CVE-2024-8743

MEDIUM CVSS 6.8 2024-10-05
Threat Entry Updated 2025-02-06

CVE-2024-9528 - Contact Form Plugin

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to edit forms (administrator by default), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Contact Form

CVE-2024-9528

MEDIUM CVSS 4.9 2024-10-05
Threat Entry Updated 2024-10-07

CVE-2024-9455 - Wp Cleanup And Basic Functions Plugin

The WP Cleanup and Basic Functions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Wp Cleanup And Basic Functions

CVE-2024-9455

MEDIUM CVSS 6.4 2024-10-05
Threat Entry Updated 2025-02-07

CVE-2024-9385 - Builder Plugin

The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Builder

CVE-2024-9385

MEDIUM CVSS 6.1 2024-10-05
Threat Entry Updated 2026-02-17

CVE-2024-8499 - Checkout Field Editor For Woocommerce Plugin

The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘render_review_request_notice’ function in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Checkout Field Editor For Woocommerce

CVE-2024-8499

MEDIUM CVSS 4.7 2024-10-04
Threat Entry Updated 2024-10-08

CVE-2024-9271 - Rewp Plugin

The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Rewp

CVE-2024-9271

MEDIUM CVSS 6.4 2024-10-04
Threat Entry Updated 2024-10-08

CVE-2024-9071 - Easy Demo Importer Plugin

The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Easy Demo Importer

CVE-2024-9071

MEDIUM CVSS 6.4 2024-10-04
Threat Entry Updated 2024-10-08

CVE-2024-9435 - Shiftcontroller Plugin

The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL keys in all versions up to, and including, 4.9.66 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Shiftcontroller

CVE-2024-9435

MEDIUM CVSS 6.1 2024-10-04
Threat Entry Updated 2024-10-08

CVE-2024-9306 - Wp Booking Calendar Plugin

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. In addition, site administrators have the option to grant lower-level users with access to manage the plugin's…

PLUGIN Wp Booking Calendar

CVE-2024-9306

MEDIUM CVSS 4.4 2024-10-04
Threat Entry Updated 2024-10-08

CVE-2024-9242 - Memberful Plugin

The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'memberful_buy_subscription_link' and 'memberful_podcasts_link' shortcodes in all versions up to, and including, 1.73.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Memberful

CVE-2024-9242

MEDIUM CVSS 6.4 2024-10-04
Threat Entry Updated 2024-10-10

CVE-2024-8804 - Code Embed Plugin

The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insufficient restrictions on who can utilize the functionality. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Code Embed

CVE-2024-8804

MEDIUM CVSS 6.4 2024-10-04
Threat Entry Updated 2024-10-10

CVE-2024-9445 - Display Medium Posts Plugin

The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medium_posts shortcode in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Display Medium Posts

CVE-2024-9445

MEDIUM CVSS 6.4 2024-10-04
Threat Entry Updated 2024-10-10

CVE-2024-9421 - Login Logout Shortcode Plugin

The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Login Logout Shortcode

CVE-2024-9421

MEDIUM CVSS 6.4 2024-10-04
Threat Entry Updated 2024-10-10

CVE-2024-9372 - Wp Blocks Hub Plugin

The WP Blocks Hub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Wp Blocks Hub

CVE-2024-9372

MEDIUM CVSS 6.4 2024-10-04
Threat Entry Updated 2024-10-10

CVE-2024-9368 - Aggregator Advanced Settings Plugin

The Aggregator Advanced Settings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Aggregator Advanced Settings

CVE-2024-9368

MEDIUM CVSS 6.4 2024-10-04
Threat Entry Updated 2024-10-10

CVE-2024-9384 - Quantity Dynamic Pricing Bulk Discounts For Woocommerce Plugin

The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Quantity Dynamic Pricing Bulk Discounts For Woocommerce

CVE-2024-9384

MEDIUM CVSS 6.1 2024-10-04
Threat Entry Updated 2024-10-10

CVE-2024-9375 - Captcha Bank Plugin

The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.0.36. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Captcha Bank

CVE-2024-9375

MEDIUM CVSS 6.1 2024-10-04
Threat Entry Updated 2024-10-08

CVE-2024-9353 - Popularis Extra Plugin

The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Popularis Extra

CVE-2024-9353

MEDIUM CVSS 6.1 2024-10-04
Scroll to top