Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,409
Critical1,426
High4,784
Medium12,920
Reset
Showing 14901-14920 of 19409 records
Threat Entry Updated 2025-03-05

CVE-2023-7015 - File Manager Pro Plugin

The File Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tb' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN File Manager Pro

CVE-2023-7015

MEDIUM CVSS 6.1 2024-03-13
Threat Entry Updated 2025-02-07

CVE-2023-6969 - User Shortcodes Plus Plugin

The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the user_meta shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to retrieve potentially sensitive user meta.

PLUGIN User Shortcodes Plus

CVE-2023-6969

MEDIUM CVSS 5.3 2024-03-13
Threat Entry Updated 2025-04-04

CVE-2023-6957 - Fluent Forms Plugin

The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploitation level depends on who is granted the right to create forms by an administrator. This level can be as low as contributor, but by default is admin.

PLUGIN Fluent Forms

CVE-2023-6957

MEDIUM CVSS 4.9 2024-03-13
Threat Entry Updated 2025-01-21

CVE-2023-6825 - File Manager Plugin

The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file…

PLUGIN File Manager

CVE-2023-6825

CRITICAL CVSS 9.9 2024-03-13
Threat Entry Updated 2025-02-28

CVE-2023-5663 - News Announcement Scroll Plugin

The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN News Announcement Scroll

CVE-2023-5663

HIGH CVSS 8.8 2024-03-13
Threat Entry Updated 2025-01-21

CVE-2023-6809 - Beepress Plugin

The Custom fields shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied custom post meta values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Beepress

CVE-2023-6809

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-03-21

CVE-2023-6785 - Download Manager Plugin

The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).

PLUGIN Download Manager

CVE-2023-6785

MEDIUM CVSS 5.3 2024-03-13
Threat Entry Updated 2025-01-21

CVE-2024-1508 - Prime Slider Plugin

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings['title_tags']' attribute of the Mercury widget in all versions up to, and including, 3.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Prime Slider

CVE-2024-1508

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-21

CVE-2024-1507 - Prime Slider Plugin

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Rubix widget in all versions up to, and including, 3.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Prime Slider

CVE-2024-1507

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-03-05

CVE-2024-2123 - Ultimate Member Plugin

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ultimate Member

CVE-2024-2123

HIGH CVSS 7.2 2024-03-13
Threat Entry Updated 2025-02-11

CVE-2024-1582 - Wp Go Maps Plugin

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Go Maps

CVE-2024-1582

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-02-11

CVE-2023-4839 - Wp Go Maps Plugin

The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Wp Go Maps

CVE-2023-4839

MEDIUM CVSS 4.4 2024-03-13
Threat Entry Updated 2025-01-22

CVE-2023-7072 - Post Grid Plugin

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' REST API Endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including full draft posts and password protected posts, as well as the password for password-protected posts.

PLUGIN Post Grid

CVE-2023-7072

HIGH CVSS 7.5 2024-03-12
Threat Entry Updated 2025-01-22

CVE-2024-1421 - Ht Mega Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel widget in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ht Mega

CVE-2024-1421

MEDIUM CVSS 6.4 2024-03-12
Threat Entry Updated 2025-01-22

CVE-2024-1397 - Ht Mega Plugin

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on the 'titleTag' user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ht Mega

CVE-2024-1397

MEDIUM CVSS 6.4 2024-03-12
Threat Entry Updated 2025-01-22

CVE-2024-2395 - Bulgarisation For Woocommerce Plugin

The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to generate and delete labels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Bulgarisation For Woocommerce

CVE-2024-2395

HIGH CVSS 7.3 2024-03-12
Threat Entry Updated 2025-01-15

CVE-2024-0386 - Weforms Plugin

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Weforms

CVE-2024-0386

HIGH CVSS 7.2 2024-03-12
Threat Entry Updated 2025-01-22

CVE-2024-2107 - Blossom Spa Plugin

The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.4 via generated source. This makes it possible for unauthenticated attackers to extract sensitive data including contents of password-protected or scheduled posts.

PLUGIN Blossom Spa

CVE-2024-2107

MEDIUM CVSS 5.8 2024-03-12
Threat Entry Updated 2025-04-03

CVE-2024-2130 - Cww Companion Plugin

The CWW Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Module2 widget in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cww Companion

CVE-2024-2130

MEDIUM CVSS 6.4 2024-03-12
Threat Entry Updated 2025-03-13

CVE-2024-2031 - Video Conferencing With Zoom Plugin

The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoom_recordings_by_meeting' shortcode in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Video Conferencing With Zoom

CVE-2024-2031

MEDIUM CVSS 6.4 2024-03-12
Scroll to top