Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,409
Critical1,426
High4,784
Medium12,920
Reset
Showing 14341-14360 of 19409 records
Threat Entry Updated 2025-01-21

CVE-2024-3818 - Essential Blocks Plugin

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" block in all versions up to, and including, 4.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Blocks

CVE-2024-3818

MEDIUM CVSS 5.4 2024-04-19
Threat Entry Updated 2025-01-08

CVE-2024-3598 - Elementskit Plugin

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Elementskit

CVE-2024-3598

MEDIUM CVSS 6.4 2024-04-19
Threat Entry Updated 2025-01-08

CVE-2024-3560 - Learnpress Plugin

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Learnpress

CVE-2024-3560

MEDIUM CVSS 6.4 2024-04-19
Threat Entry Updated 2024-11-21

CVE-2023-50885 - Store Locator WordPress Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AGILELOGIX Store Locator WordPress.This issue affects Store Locator WordPress: from n/a through 1.4.14.

PLUGIN Store Locator WordPress

CVE-2023-50885

MEDIUM CVSS 6.8 2024-04-18
Threat Entry Updated 2025-02-11

CVE-2023-6892 - Ean For Woocommerce Plugin

The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ean For Woocommerce

CVE-2023-6892

MEDIUM CVSS 6.4 2024-04-18
Threat Entry Updated 2025-02-11

CVE-2023-6897 - Ean For Woocommerce Plugin

The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to expose potentially sensitive post metadata.

PLUGIN Ean For Woocommerce

CVE-2023-6897

MEDIUM CVSS 4.3 2024-04-18
Threat Entry Updated 2024-11-21

CVE-2024-32585 - WooCommerce Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendWP Import Content in WordPress & WooCommerce with Excel allows Reflected XSS.This issue affects Import Content in WordPress & WooCommerce with Excel: from n/a through 4.2.

PLUGIN WooCommerce

CVE-2024-32585

HIGH CVSS 7.1 2024-04-18
Threat Entry Updated 2025-02-28

CVE-2024-2833 - Jobs For Wordpress Plugin

The Jobs for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘job-search’ parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Jobs For Wordpress

CVE-2024-2833

MEDIUM CVSS 6.1 2024-04-18
Threat Entry Updated 2026-01-13

CVE-2024-32597 - Wp Smart Import Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WordPress Importer allows Stored XSS.This issue affects WordPress Importer: from n/a through 1.0.7.

PLUGIN Wp Smart Import

CVE-2024-32597

MEDIUM CVSS 5.9 2024-04-18
Threat Entry Updated 2025-01-21

CVE-2024-1429 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab_link’ attribute of the Panel Slider widget in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-1429

MEDIUM CVSS 6.4 2024-04-18
Threat Entry Updated 2025-05-08

CVE-2024-2729 - Otter Blocks Plugin

The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.

PLUGIN Otter Blocks

CVE-2024-2729

MEDIUM CVSS 6.1 2024-04-18
Threat Entry Updated 2025-01-21

CVE-2024-1426 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute of the Price List widget in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-1426

MEDIUM CVSS 6.4 2024-04-18
Threat Entry Updated 2025-01-14

CVE-2023-6805 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 4.4.7 via the fetch_feed functionality. This makes it possible for authenticated attackers, with contributor access and above, to make web requests to arbitrary locations originating from the web application and can be used to modify information from internal services. NOTE: This vulnerability, exploitable by contributor-level users, was was fixed in version 4.4.7. The same vulnerability was fixed…

PLUGIN Rss Aggregator By Feedzy

CVE-2023-6805

MEDIUM CVSS 6.4 2024-04-17
Threat Entry Updated 2025-01-08

CVE-2024-3333 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attributes of widgets in all versions up to, and including, 5.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2024-3333

MEDIUM CVSS 6.4 2024-04-17
Threat Entry Updated 2024-11-21

CVE-2024-32517 - WooCommerce Plugin

Missing Authorization vulnerability in WooCommerce & WordPress Tutorials Custom Thank You Page Customize For WooCommerce by Binary Carpenter.This issue affects Custom Thank You Page Customize For WooCommerce by Binary Carpenter: from n/a through 1.4.12.

PLUGIN WooCommerce

CVE-2024-32517

MEDIUM CVSS 4.3 2024-04-17
Threat Entry Updated 2025-05-08

CVE-2024-2118 - Social Sharing Icons Plugin

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Social Sharing Icons

CVE-2024-2118

MEDIUM CVSS 5.9 2024-04-17
Threat Entry Updated 2025-04-14

CVE-2024-2101 - Salon Booking System Plugin

The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers' page and the malicious script is executed in the admin context.

PLUGIN Salon Booking System

CVE-2024-2101

MEDIUM CVSS 5.7 2024-04-17
Threat Entry Updated 2025-05-08

CVE-2024-1219 - Easy Social Feed Plugin

The Easy Social Feed WordPress plugin before 6.5.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

PLUGIN Easy Social Feed

CVE-2024-1219

MEDIUM CVSS 5.3 2024-04-17
Threat Entry Updated 2025-06-17

CVE-2024-0868 - Activity Logging Plugin

The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value

PLUGIN Activity Logging

CVE-2024-0868

MEDIUM CVSS 5.3 2024-04-17
Scroll to top