Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,409
Critical1,426
High4,784
Medium12,920
Reset
Showing 14561-14580 of 19409 records
Threat Entry Updated 2025-05-06

CVE-2023-6695 - Beaver Themer

The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including arbitrary user_meta values.

THEME Beaver Themer

CVE-2023-6695

MEDIUM CVSS 6.5 2024-04-09
Threat Entry Updated 2025-05-06

CVE-2023-6694 - Beaver Themer

The Beaver Themer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied custom fields. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Beaver Themer

CVE-2023-6694

MEDIUM CVSS 6.4 2024-04-09
Threat Entry Updated 2025-02-06

CVE-2023-6486 - Spectra Plugin

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions up to and including 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Spectra

CVE-2023-6486

MEDIUM CVSS 6.4 2024-04-09
Threat Entry Updated 2025-04-07

CVE-2023-6799 - Most Advanced Wordpress Reset Tool Plugin

The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 via the use of insufficiently random snapshot names. This makes it possible for unauthenticated attackers to extract sensitive data including site backups by brute-forcing the snapshot filenames. Please note that the vendor does not plan to do any further hardening on this functionality.

PLUGIN Most Advanced Wordpress Reset Tool

CVE-2023-6799

MEDIUM CVSS 5.9 2024-04-09
Threat Entry Updated 2025-02-11

CVE-2023-6777 - Wp Go Maps Plugin

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This makes it possible for unauthenticated attackers to obtain the developer's Google API key. While this does not affect the security of sites using this plugin, it allows unauthenticated attackers to make requests using this API key with the potential of exhausting requests resulting in an inability to use the map functionality offered…

PLUGIN Wp Go Maps

CVE-2023-6777

MEDIUM CVSS 5.3 2024-04-09
Threat Entry Updated 2025-05-13

CVE-2024-1664 - Responsive Gallery Grid Plugin

The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Responsive Gallery Grid

CVE-2024-1664

MEDIUM CVSS 6.1 2024-04-09
Threat Entry Updated 2025-04-11

CVE-2023-7164 - Before 4 Plugin

The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.

PLUGIN Before 4

CVE-2023-7164

HIGH CVSS 7.5 2024-04-08
Threat Entry Updated 2025-03-28

CVE-2024-1588 - Sendpress Plugin

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Sendpress

CVE-2024-1588

MEDIUM CVSS 6.8 2024-04-08
Threat Entry Updated 2025-05-19

CVE-2024-1956 - Wpb Show Core Plugin

The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scripting

PLUGIN Wpb Show Core

CVE-2024-1956

MEDIUM CVSS 6.1 2024-04-08
Threat Entry Updated 2025-05-28

CVE-2024-1752 - Font Farsi Plugin

The Font Farsi WordPress plugin through 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Font Farsi

CVE-2024-1752

MEDIUM CVSS 6.1 2024-04-08
Threat Entry Updated 2025-03-24

CVE-2024-1589 - Sendpress Plugin

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Sendpress

CVE-2024-1589

MEDIUM CVSS 6.1 2024-04-08
Threat Entry Updated 2025-05-19

CVE-2024-1958 - Wpb Show Core Plugin

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users

PLUGIN Wpb Show Core

CVE-2024-1958

MEDIUM CVSS 4.8 2024-04-08
Threat Entry Updated 2025-05-19

CVE-2024-1292 - Wpb Show Core Plugin

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Wpb Show Core

CVE-2024-1292

MEDIUM CVSS 4.7 2024-04-08
Threat Entry Updated 2024-11-21

CVE-2024-31344 - Easy Login Styler – White Label Admin Login Page for WordPress Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phpbits Creative Studio Easy Login Styler – White Label Admin Login Page for WordPress allows Stored XSS.This issue affects Easy Login Styler – White Label Admin Login Page for WordPress: from n/a through 1.0.6.

PLUGIN Easy Login Styler – White Label Admin Login Page for WordPress

CVE-2024-31344

MEDIUM CVSS 5.9 2024-04-07
Threat Entry Updated 2025-01-14

CVE-2023-6877 - Youtube Video Feeds Aggregator Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping on the Content-Type field of error messages when retrieving an invalid RSS feed. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Youtube Video Feeds Aggregator

CVE-2023-6877

MEDIUM CVSS 6.4 2024-04-07
Threat Entry Updated 2025-01-15

CVE-2024-2132 - Ultimate Bootstrap Elements For Elementor Plugin

The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Widget in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Bootstrap Elements For Elementor

CVE-2024-2132

MEDIUM CVSS 6.4 2024-04-06
Threat Entry Updated 2025-03-06

CVE-2024-2296 - Photo Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Photo Gallery

CVE-2024-2296

MEDIUM CVSS 5.5 2024-04-06
Threat Entry Updated 2025-02-27

CVE-2024-2458 - Powerkit – Supercharge your WordPress Site Plugin

The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Powerkit – Supercharge your WordPress Site

CVE-2024-2458

MEDIUM CVSS 6.4 2024-04-06
Threat Entry Updated 2025-01-17

CVE-2024-1428 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘element_pack_wrapper_link’ attribute of the Trailer Box widget in all versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-1428

MEDIUM CVSS 6.4 2024-04-06
Threat Entry Updated 2025-01-17

CVE-2024-0837 - Element Pack Plugin

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Element Pack

CVE-2024-0837

MEDIUM CVSS 6.4 2024-04-06
Scroll to top