Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,409
Critical1,426
High4,784
Medium12,920
Reset
Showing 15161-15180 of 19409 records
Threat Entry Updated 2024-11-21

CVE-2024-1157 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-1157

MEDIUM CVSS 5.4 2024-02-13
Threat Entry Updated 2025-05-07

CVE-2024-0566 - Smart Manager Plugin

The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Smart Manager

CVE-2024-0566

HIGH CVSS 7.2 2024-02-12
Threat Entry Updated 2025-04-24

CVE-2023-6294 - Popup Builder Plugin

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.

PLUGIN Popup Builder

CVE-2023-6294

HIGH CVSS 7.2 2024-02-12
Threat Entry Updated 2025-03-26

CVE-2024-0250 - Before 6 Plugin

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

PLUGIN Before 6

CVE-2024-0250

MEDIUM CVSS 6.1 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-0420 - Mappress Maps For Plugin

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

PLUGIN Mappress Maps For

CVE-2024-0420

MEDIUM CVSS 5.4 2024-02-12
Threat Entry Updated 2025-05-06

CVE-2023-6499 - Lastunes Plugin

The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Lastunes

CVE-2023-6499

MEDIUM CVSS 5.4 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2023-6082 - Chartjs Plugin

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Chartjs

CVE-2023-6082

MEDIUM CVSS 5.4 2024-02-12
Threat Entry Updated 2025-05-06

CVE-2023-6081 - Chartjs Plugin

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Chartjs

CVE-2023-6081

MEDIUM CVSS 5.4 2024-02-12
Threat Entry Updated 2025-05-07

CVE-2024-0421 - Mappress Maps For Plugin

The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.

PLUGIN Mappress Maps For

CVE-2024-0421

MEDIUM CVSS 5.3 2024-02-12
Threat Entry Updated 2025-03-14

CVE-2023-7233 - Gigpress Plugin

The GigPress WordPress plugin through 2.3.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Gigpress

CVE-2023-7233

MEDIUM CVSS 4.8 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2023-6591 - Popup Box Plugin

The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Popup Box

CVE-2023-6591

MEDIUM CVSS 4.8 2024-02-12
Threat Entry Updated 2025-05-07

CVE-2024-0248 - Before 2 Plugin

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.

PLUGIN Before 2

CVE-2024-0248

MEDIUM CVSS 4.3 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2023-6501 - Splashscreen Plugin

The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Splashscreen

CVE-2023-6501

MEDIUM CVSS 4.3 2024-02-12
Threat Entry Updated 2025-05-06

CVE-2023-6036 - Before 3 Plugin

The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

PLUGIN Before 3

CVE-2023-6036

CRITICAL CVSS 9.8 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-24887 - Contest Gallery Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress.This issue affects Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress: from n/a through 21.2.8.4.

PLUGIN Contest Gallery

CVE-2024-24887

MEDIUM CVSS 5.4 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-24926 - Creative Multi Purpose Responsive Theme

Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.

THEME Creative Multi Purpose Responsive

CVE-2024-24926

HIGH CVSS 7.5 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-24796 - Event Manager And Tickets Selling For Woocommerce Plugin

Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a through 4.1.1.

PLUGIN Event Manager And Tickets Selling For Woocommerce

CVE-2024-24796

HIGH CVSS 8.2 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2023-47526 - Chartify Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team Chartify – WordPress Chart Plugin allows Stored XSS.This issue affects Chartify – WordPress Chart Plugin: from n/a through 2.0.6.

PLUGIN Chartify

CVE-2023-47526

MEDIUM CVSS 5.9 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-24927 - Allows Reflected Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme allows Reflected XSS.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.

THEME Allows Reflected Xss

CVE-2024-24927

HIGH CVSS 7.1 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-23517 - Scheduling Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Start Booking Scheduling Plugin – Online Booking for WordPress allows Stored XSS.This issue affects Scheduling Plugin – Online Booking for WordPress: from n/a through 3.5.10.

PLUGIN Scheduling

CVE-2024-23517

MEDIUM CVSS 6.5 2024-02-10
Scroll to top