Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,140
Critical1,383
High4,684
Medium12,815
Reset
Showing 12341-12360 of 19140 records
Threat Entry Updated 2024-09-26

CVE-2023-2919 - Tutor Plugin

The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addon_enable_disable' function. This makes it possible for unauthenticated attackers to enable or disable addons via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Tutor

CVE-2023-2919

MEDIUM CVSS 4.3 2024-09-10
Threat Entry Updated 2024-09-19

CVE-2024-7655 - Peepso Plugin

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Peepso

CVE-2024-7655

MEDIUM CVSS 4.4 2024-09-10
Threat Entry Updated 2024-09-19

CVE-2024-7618 - Peepso Plugin

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Peepso

CVE-2024-7618

MEDIUM CVSS 4.4 2024-09-10
Threat Entry Updated 2025-05-16

CVE-2024-7955 - Before 3 Plugin

The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2024-7955

MEDIUM CVSS 4.8 2024-09-10
Threat Entry Updated 2025-05-16

CVE-2024-7891 - Floating Contact Button Plugin

The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Floating Contact Button

CVE-2024-7891

MEDIUM CVSS 4.8 2024-09-10
Threat Entry Updated 2024-09-26

CVE-2024-8268 - Frontend Dashboard Plugin

The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to call arbitrary functions that can be leverage for privilege escalation by changing user's passwords.

PLUGIN Frontend Dashboard

CVE-2024-8268

HIGH CVSS 8.8 2024-09-10
Threat Entry Updated 2024-09-26

CVE-2024-8478 - The Affiliate Super Assistent Plugin

The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply arbitrary shortcodes in comments when the 'Parse comments' option is enabled. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN The Affiliate Super Assistent

CVE-2024-8478

HIGH CVSS 7.3 2024-09-10
Threat Entry Updated 2024-10-07

CVE-2024-7688 - Azindex Plugin

The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack

PLUGIN Azindex

CVE-2024-7688

MEDIUM CVSS 6.5 2024-09-09
Threat Entry Updated 2024-10-07

CVE-2024-7918 - Pocket Widget Plugin

The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Pocket Widget

CVE-2024-7918

MEDIUM CVSS 4.8 2024-09-09
Threat Entry Updated 2024-10-07

CVE-2024-6910 - Before 2 Plugin

The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Before 2

CVE-2024-6910

MEDIUM CVSS 4.8 2024-09-09
Threat Entry Updated 2024-10-07

CVE-2024-7689 - Snapshot Backup Plugin

The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

PLUGIN Snapshot Backup

CVE-2024-7689

MEDIUM CVSS 4.3 2024-09-09
Threat Entry Updated 2024-10-07

CVE-2024-7687 - Azindex Plugin

The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

PLUGIN Azindex

CVE-2024-7687

MEDIUM CVSS 4.3 2024-09-09
Threat Entry Updated 2024-10-07

CVE-2024-5561 - Popup Maker Plugin

The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Popup Maker

CVE-2024-5561

MEDIUM CVSS 4.8 2024-09-09
Threat Entry Updated 2024-10-07

CVE-2024-6928 - Opti Marketing Plugin

The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

PLUGIN Opti Marketing

CVE-2024-6928

CRITICAL CVSS 9.8 2024-09-08
Threat Entry Updated 2024-09-11

CVE-2024-6924 - Before 1 Plugin

The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

PLUGIN Before 1

CVE-2024-6924

CRITICAL CVSS 9.8 2024-09-08
Threat Entry Updated 2024-09-11

CVE-2024-6859 - Wp Multitasking Plugin

The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Wp Multitasking

CVE-2024-6859

MEDIUM CVSS 5.4 2024-09-08
Threat Entry Updated 2024-09-11

CVE-2024-6925 - Before 1 Plugin

The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

PLUGIN Before 1

CVE-2024-6925

MEDIUM CVSS 4.3 2024-09-08
Threat Entry Updated 2024-09-11

CVE-2024-6856 - Wp Multitasking Plugin

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Wp Multitasking

CVE-2024-6856

MEDIUM CVSS 4.3 2024-09-08
Threat Entry Updated 2024-09-11

CVE-2024-6855 - Wp Multitasking Plugin

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a CSRF attack

PLUGIN Wp Multitasking

CVE-2024-6855

MEDIUM CVSS 4.3 2024-09-08
Threat Entry Updated 2024-09-11

CVE-2024-6853 - Wp Multitasking Plugin

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack

PLUGIN Wp Multitasking

CVE-2024-6853

MEDIUM CVSS 4.3 2024-09-08
Scroll to top