Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,232
Critical1,394
High4,706
Medium12,862
Reset
Showing 13101-13120 of 19232 records
Threat Entry Updated 2024-11-21

CVE-2024-5219 - Easy Google Maps Plugin

The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easy Google Maps

CVE-2024-5219

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-5767 - Sitetweet Plugin

The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Sitetweet

CVE-2024-5767

HIGH CVSS 8.8 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-5606 - Before 9 Plugin

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role

PLUGIN Before 9

CVE-2024-5606

HIGH CVSS 8.8 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-4627 - Rank Math Seo Plugin

The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager feature of the Rank Math SEO WordPress plugin before 1.0.219) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Rank Math Seo

CVE-2024-4627

MEDIUM CVSS 5.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-3999 - Before 2 Plugin

The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2024-3999

MEDIUM CVSS 4.8 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-1427 - Post Grid Plugin

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Post Grid

CVE-2024-1427

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-5349 - Element Kit For Elementor Plugin

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'map_style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Element Kit For Elementor

CVE-2024-5349

HIGH CVSS 8.8 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-5419 - Void Contact Form 7 Widget For Elementor Page Builder Plugin

The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cf7_redirect_page' attribute within the plugin's Void Contact From 7 widget in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Void Contact Form 7 Widget For Elementor Page Builder

CVE-2024-5419

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-12-26

CVE-2024-5938 - Boot Store Plugin

The Boot Store theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Boot Store

CVE-2024-5938

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-39310 - Basil Recipe Theme

The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` parameter in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. Because the of the default WordPress validation, it is not possible to insert the payload directly but if the Cooked plugin is installed, it is possible to create a recipe post…

THEME Basil Recipe

CVE-2024-39310

MEDIUM CVSS 5.4 2024-07-01
Threat Entry Updated 2025-05-01

CVE-2024-4934 - Before 9 Plugin

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 9

CVE-2024-4934

MEDIUM CVSS 5.5 2024-07-01
Threat Entry Updated 2025-05-01

CVE-2024-6130 - Form Maker By 10web Plugin

The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Form Maker By 10web

CVE-2024-6130

MEDIUM CVSS 4.8 2024-07-01
Threat Entry Updated 2024-11-21

CVE-2024-2386 - Wp Maps Plugin

The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Maps

CVE-2024-2386

HIGH CVSS 8.8 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2023-4017 - Goya Theme

The Goya theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attra-color’, 'attra-size', and 'product-cata' parameters in versions up to, and including, 1.0.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Goya

CVE-2023-4017

MEDIUM CVSS 6.1 2024-06-29
Threat Entry Updated 2025-02-07

CVE-2024-5819 - Gutenberg Blocks With Ai Plugin

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data attributes in all versions up to, and including, 3.2.45 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Blocks With Ai

CVE-2024-5819

MEDIUM CVSS 6.4 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-6363 - Stock Ticker Plugin

The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortcode in all versions up to, and including, 3.24.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Stock Ticker

CVE-2024-6363

MEDIUM CVSS 6.4 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-5790 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Happy Addons For Elementor

CVE-2024-5790

MEDIUM CVSS 6.4 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-5666 - Extensions For Elementor Plugin

The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the EE Button widget in all versions up to, and including, 2.0.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Extensions For Elementor

CVE-2024-5666

MEDIUM CVSS 6.4 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-6265 - Userswp Plugin

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Userswp

CVE-2024-6265

CRITICAL CVSS 9.8 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-5889 - Events Manager Plugin

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Events Manager

CVE-2024-5889

MEDIUM CVSS 6.1 2024-06-29
Scroll to top