Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,409
Critical1,426
High4,784
Medium12,920
Reset
Showing 14821-14840 of 19409 records
Threat Entry Updated 2025-01-15

CVE-2024-1751 - Tutor Lms Plugin

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber/student access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Tutor Lms

CVE-2024-1751

HIGH CVSS 8.8 2024-03-13
Threat Entry Updated 2025-03-20

CVE-2024-1763 - Wp Social Login And Register Social Counter Plugin

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable certain providers for the social share and login features.

PLUGIN Wp Social Login And Register Social Counter

CVE-2024-1763

MEDIUM CVSS 6.5 2024-03-13
Threat Entry Updated 2025-03-13

CVE-2024-1723 - Siteorigin Widgets Bundle Plugin

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.58.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Affected parameters include: $instance['fonts']['title_options']['tag'], $headline_tag, $sub_headline_tag, $feature['icon'].

PLUGIN Siteorigin Widgets Bundle

CVE-2024-1723

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-23

CVE-2024-1691 - Otter Blocks Plugin

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upload form, which allows SVG uploads, in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that the patch in 2.6.4 allows SVG uploads but the uploaded SVG files are sanitized.

PLUGIN Otter Blocks

CVE-2024-1691

MEDIUM CVSS 6.1 2024-03-13
Threat Entry Updated 2025-02-05

CVE-2024-1690 - Terawallet Plugin

The TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the terawallet_export_user_search() function in all versions up to, and including, 1.4.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to export a list of registered users and their emails.

PLUGIN Terawallet

CVE-2024-1690

MEDIUM CVSS 4.3 2024-03-13
Threat Entry Updated 2025-01-31

CVE-2024-1668 - Avada Plugin

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submissions, including fields that are obfuscated (such as the contact form's "password" field).

PLUGIN Avada

CVE-2024-1668

MEDIUM CVSS 6.5 2024-03-13
Threat Entry Updated 2025-01-23

CVE-2024-1684 - Otter Blocks Plugin

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form file field CSS metabox in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Otter Blocks

CVE-2024-1684

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-15

CVE-2024-1680 - Premium Addons For Elementor Plugin

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Settings URL of the Banner, Team Members, and Image Scroll widgets in all versions up to, and including, 4.10.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Premium Addons For Elementor

CVE-2024-1680

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-04-03

CVE-2024-1642 - Mainwp Dashboard Plugin

The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.0.1. This is due to missing or incorrect nonce validation on the 'posting_bulk' function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Mainwp Dashboard

CVE-2024-1642

MEDIUM CVSS 4.3 2024-03-13
Threat Entry Updated 2025-01-08

CVE-2024-1536 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's event calendar widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2024-1536

HIGH CVSS 7.4 2024-03-13
Threat Entry Updated 2025-03-05

CVE-2024-1585 - Metform Elementor Contact Form Builder Plugin

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Metform Elementor Contact Form Builder

CVE-2024-1585

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2024-12-12

CVE-2024-1541 - Gutenberg Blocks With Ai Plugin

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the htmlTag attribute in all versions up to, and including, 3.2.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Gutenberg Blocks With Ai

CVE-2024-1541

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-08

CVE-2024-1537 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Data Table widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2024-1537

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-22

CVE-2024-1535 - Profilepress Plugin

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.15.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Profilepress

CVE-2024-1535

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-04-03

CVE-2024-1640 - Contact Form Builder Plugin

The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient user validation on the bitforms_update_form_entry AJAX action in all versions up to, and including, 2.10.1. This makes it possible for unauthenticated attackers to modify form submissions.

PLUGIN Contact Form Builder

CVE-2024-1640

MEDIUM CVSS 5.3 2024-03-13
Threat Entry Updated 2025-01-22

CVE-2024-1505 - Academy Lms Plugin

The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. This makes it possible for authenticated attackers, with minimal permissions such as students, to elevate their user role to that of an administrator.

PLUGIN Academy Lms

CVE-2024-1505

HIGH CVSS 8.8 2024-03-13
Threat Entry Updated 2025-01-22

CVE-2024-1499 - Orbit Fox Plugin

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in the $settings['title_tags'] parameter in all versions up to, and including, 2.10.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Orbit Fox

CVE-2024-1499

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-22

CVE-2024-1497 - Orbit Fox Plugin

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form widget addr2_width attribute in all versions up to, and including, 2.10.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Orbit Fox

CVE-2024-1497

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-03-12

CVE-2024-1484 - Amelia Plugin

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the date parameters in all versions up to, and including, 1.0.98 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Amelia

CVE-2024-1484

MEDIUM CVSS 6.1 2024-03-13
Threat Entry Updated 2025-03-06

CVE-2024-1479 - Wp Show Posts Plugin

The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the wpsp_display function. This makes it possible for authenticated attackers with contributor access and above to view the contents of draft, trash, future, private and pending posts and pages.

PLUGIN Wp Show Posts

CVE-2024-1479

MEDIUM CVSS 5.3 2024-03-13
Scroll to top