Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,409
Critical1,426
High4,784
Medium12,920
Reset
Showing 15181-15200 of 19409 records
Threat Entry Updated 2024-11-21

CVE-2023-51404 - My Agile Privacy Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyAgilePrivacy My Agile Privacy – The only GDPR solution for WordPress that you can truly trust allows Stored XSS.This issue affects My Agile Privacy – The only GDPR solution for WordPress that you can truly trust: from n/a through 2.1.7.

PLUGIN My Agile Privacy

CVE-2023-51404

MEDIUM CVSS 6.5 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-24801 - Owl Carousel Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt OWL Carousel – WordPress Owl Carousel Slider allows Stored XSS.This issue affects OWL Carousel – WordPress Owl Carousel Slider: from n/a through 1.4.0.

PLUGIN Owl Carousel

CVE-2024-24801

MEDIUM CVSS 6.5 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-24713 - Auto Listings Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Auto Listings Auto Listings – Car Listings & Car Dealership Plugin for WordPress allows Stored XSS.This issue affects Auto Listings – Car Listings & Car Dealership Plugin for WordPress: from n/a through 2.6.5.

PLUGIN Auto Listings

CVE-2024-24713

MEDIUM CVSS 6.5 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-24712 - Social Login Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress allows Stored XSS.This issue affects Heateor Social Login WordPress: from n/a through 1.1.30.

PLUGIN Social Login

CVE-2024-24712

MEDIUM CVSS 6.5 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-0596 - Awesome Support Plugin

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to view password protected and draft posts.

PLUGIN Awesome Support

CVE-2024-0596

MEDIUM CVSS 5.3 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-0595 - Awesome Support Plugin

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve user data such as emails.

PLUGIN Awesome Support

CVE-2024-0595

MEDIUM CVSS 4.3 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-0594 - Awesome Support Plugin

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Awesome Support

CVE-2024-0594

HIGH CVSS 8.8 2024-02-10
Threat Entry Updated 2024-11-21

CVE-2024-0842 - Backuply Plugin

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.5. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in the server running out of resources.

PLUGIN Backuply

CVE-2024-0842

HIGH CVSS 7.5 2024-02-09
Threat Entry Updated 2024-11-21

CVE-2024-1122 - Eventin Plugin

The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible for unauthenticated attackers to export event data.

PLUGIN Eventin

CVE-2024-1122

MEDIUM CVSS 5.3 2024-02-09
Threat Entry Updated 2024-11-21

CVE-2024-0657 - Internal Link Juicer Plugin

The Internal Link Juicer: SEO Auto Linker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as 'ilj_settings_field_links_per_page' in all versions up to, and including, 2.23.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Internal Link Juicer

CVE-2024-0657

MEDIUM CVSS 4.4 2024-02-09
Threat Entry Updated 2024-12-17

CVE-2024-24881 - Wp Sms Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc allows Reflected XSS.This issue affects WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc: from n/a through 6.5.2.

PLUGIN Wp Sms

CVE-2024-24881

HIGH CVSS 7.1 2024-02-08
Threat Entry Updated 2024-11-21

CVE-2024-1207 - Booking Calendar Plugin

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Booking Calendar

CVE-2024-1207

CRITICAL CVSS 9.8 2024-02-08
Threat Entry Updated 2024-11-21

CVE-2024-0965 - Simple Page Access Restriction Plugin

The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content.

PLUGIN Simple Page Access Restriction

CVE-2024-0965

MEDIUM CVSS 5.3 2024-02-08
Threat Entry Updated 2024-11-21

CVE-2024-0511 - Royal Elementor Addons Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This makes it possible for unauthenticated attackers to post metadata via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Royal Elementor Addons

CVE-2024-0511

MEDIUM CVSS 4.3 2024-02-08
Threat Entry Updated 2024-11-21

CVE-2023-5665 - Payment Forms For Paystack Plugin

The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32130 is likely a duplicate of this issue.

PLUGIN Payment Forms For Paystack

CVE-2023-5665

MEDIUM CVSS 6.4 2024-02-08
Threat Entry Updated 2024-11-21

CVE-2024-1118 - Podlove Subscribe Button Plugin

The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-button shortcode in all versions up to, and including, 1.3.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Podlove Subscribe Button

CVE-2024-1118

HIGH CVSS 8.8 2024-02-07
Threat Entry Updated 2025-05-15

CVE-2024-1110 - Podlove Podcast Publisher Plugin

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init() function in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to import the plugin's settings.

PLUGIN Podlove Podcast Publisher

CVE-2024-1110

MEDIUM CVSS 5.3 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-1109 - Podlove Podcast Publisher Plugin

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_download() and init() functions in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to export the plugin's tracking data and podcast information.

PLUGIN Podlove Podcast Publisher

CVE-2024-1109

MEDIUM CVSS 5.3 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-1079 - Quiz Maker Plugin

The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. This makes it possible for unauthenticated attackers to fetch arbitrary quiz results which can contain PII.

PLUGIN Quiz Maker

CVE-2024-1079

MEDIUM CVSS 5.3 2024-02-07
Threat Entry Updated 2024-11-21

CVE-2024-1078 - Quiz Maker Plugin

The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary quizzes.

PLUGIN Quiz Maker

CVE-2024-1078

MEDIUM CVSS 4.3 2024-02-07
Scroll to top