Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,409
Critical1,426
High4,784
Medium12,920
Reset
Showing 15141-15160 of 19409 records
Threat Entry Updated 2025-01-28

CVE-2024-1590 - Pagelayer Plugin

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Pagelayer

CVE-2024-1590

MEDIUM CVSS 4.6 2024-02-23
Threat Entry Updated 2025-01-16

CVE-2024-1779 - Admin Side Data Storage For Contact Form 7 Plugin

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_status() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to alter the message read status of messages.

PLUGIN Admin Side Data Storage For Contact Form 7

CVE-2024-1779

MEDIUM CVSS 5.3 2024-02-23
Threat Entry Updated 2025-01-16

CVE-2024-1776 - Admin Side Data Storage For Contact Form 7 Plugin

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up to, and including, 1.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Admin Side Data Storage For Contact Form 7

CVE-2024-1776

HIGH CVSS 7.2 2024-02-23
Threat Entry Updated 2025-01-16

CVE-2024-1778 - Admin Side Data Storage For Contact Form 7 Plugin

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_bookmark() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to alter bookmark statuses.

PLUGIN Admin Side Data Storage For Contact Form 7

CVE-2024-1778

MEDIUM CVSS 4.3 2024-02-23
Threat Entry Updated 2025-01-16

CVE-2024-1777 - Admin Side Data Storage For Contact Form 7 Plugin

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the settings update function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Admin Side Data Storage For Contact Form 7

CVE-2024-1777

MEDIUM CVSS 4.3 2024-02-23
Threat Entry Updated 2025-02-05

CVE-2024-0903 - Userfeedback Plugin

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_submitted' 'link' value in all versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in the feedback submission page that will execute when a user clicks the link, while also pressing the command key.

PLUGIN Userfeedback

CVE-2024-0903

MEDIUM CVSS 5.4 2024-02-22
Threat Entry Updated 2025-02-07

CVE-2024-1053 - Event Tickets Plugin

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to email the attendees list to themselves.

PLUGIN Event Tickets

CVE-2024-1053

MEDIUM CVSS 4.3 2024-02-22
Threat Entry Updated 2024-11-21

CVE-2024-24837 - WooCommerce Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joomla to WordPress.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.44.3; FG Drupal to WordPress: from n/a through 3.67.0; FG Joomla to WordPress: from n/a through 4.15.0.

PLUGIN WooCommerce

CVE-2024-24837

MEDIUM CVSS 4.3 2024-02-21
Threat Entry Updated 2025-02-04

CVE-2024-1081 - 3d Flipbook Plugin

The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bookmark feature in all versions up to, and including, 1.15.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN 3d Flipbook

CVE-2024-1081

MEDIUM CVSS 6.4 2024-02-21
Threat Entry Updated 2025-01-31

CVE-2024-0593 - Simple Job Board Plugin

The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.

PLUGIN Simple Job Board

CVE-2024-0593

MEDIUM CVSS 5.3 2024-02-21
Threat Entry Updated 2025-03-07

CVE-2024-1562 - Woocommerce Google Sheet Connector Plugin

The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for unauthenticated attackers to update plugin settings.

PLUGIN Woocommerce Google Sheet Connector

CVE-2024-1562

MEDIUM CVSS 5.3 2024-02-21
Threat Entry Updated 2025-02-26

CVE-2024-1501 - Wp Database Reset Plugin

The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This makes it possible for unauthenticated attackers to install the WP Reset Plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Database Reset

CVE-2024-1501

MEDIUM CVSS 4.7 2024-02-21
Threat Entry Updated 2025-01-28

CVE-2024-1108 - Plugin Groups

The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_init() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to change the settings of the plugin, which can also cause a denial of service due to a misconfiguration.

PLUGIN Plugin Groups

CVE-2024-1108

MEDIUM CVSS 6.5 2024-02-21
Threat Entry Updated 2025-02-05

CVE-2024-1559 - Link Library Plugin

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Link Library

CVE-2024-1559

MEDIUM CVSS 6.5 2024-02-20
Threat Entry Updated 2025-02-04

CVE-2024-1510 - Shortcodes Ultimate Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_tooltip shortcode in all versions up to, and including, 7.0.2 due to insufficient input sanitization and output escaping on user supplied attributes and user supplied tags. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shortcodes Ultimate

CVE-2024-1510

MEDIUM CVSS 6.4 2024-02-20
Threat Entry Updated 2024-12-18

CVE-2024-1512 - Masterstudy Lms Plugin

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Masterstudy Lms

CVE-2024-1512

CRITICAL CVSS 9.8 2024-02-17
Threat Entry Updated 2025-02-26

CVE-2024-0610 - Piraeus Bank Woocommerce Payment Gateway Plugin

The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'MerchantReference' parameter in all versions up to, and including, 1.6.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Piraeus Bank Woocommerce Payment Gateway

CVE-2024-0610

CRITICAL CVSS 9.8 2024-02-17
Threat Entry Updated 2025-01-23

CVE-2024-0708 - Landing Page Cat Plugin

The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.2. This makes it possible for unauthenticated attackers to access landing pages that may not be public.

PLUGIN Landing Page Cat

CVE-2024-0708

MEDIUM CVSS 5.3 2024-02-15
Threat Entry Updated 2024-11-21

CVE-2024-1159 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-1159

MEDIUM CVSS 6.4 2024-02-13
Threat Entry Updated 2024-11-21

CVE-2024-1160 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-1160

MEDIUM CVSS 5.4 2024-02-13
Scroll to top