CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Lava Code Lava Ajax Search Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Lava Ajax Search WordPress plugin, affecting versions through 1.1.9. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Sakurapixel Lunar WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Sakurapixel Lunar WordPress plugin, affecting versions through 1.3.0. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress MaxA/B Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress MaxA/B plugin, specifically in versions through 2.2.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress Insert Code Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Insert Code plugin, specifically in versions through 2.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the website.
DevriX WordPress Hashtags Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the DevriX WordPress Hashtags plugin, specifically in versions through 0.3.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress List Mixcloud Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress List Mixcloud plugin, affecting versions through 1.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Vivek Marakana Tabbed Login Widget Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Tabbed Login Widget plugin, affecting versions through 1.1.2. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
WordPress Display Template Name Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Display Template Name plugin, affecting versions through 1.7.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Post Read Time Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Post Read Time plugin, specifically in versions through 1.2.6. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Hieu Nguyen WATI Chat and Notification Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WATI Chat and Notification WordPress plugin, specifically in versions through 1.1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.
WordPress No Disposable Email Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress No Disposable Email plugin, affecting versions through 2.5.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress Go To Top Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Go To Top plugin, specifically in versions through 0.0.8. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.
WordPress Responsive Google Map Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WordPress Responsive Google Map plugin, affecting versions through 3.1.5. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
WordPress Easy Image Display Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Easy Image Display plugin, affecting versions through 1.2.5. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Featured Image Thumbnail Grid Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Featured Image Thumbnail Grid plugin, affecting versions through 6.8. The issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
ThemeEgg Toolkit WordPress Plugin Arbitrary File Upload Vulnerability
A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the ThemeEgg Toolkit WordPress plugin, affecting versions through 1.2.9. This vulnerability could be exploited to upload a web shell to the server, potentially leading to unauthorized access or control over the website.
WordPress Login Form to Anywhere Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Login Form to Anywhere plugin, specifically in versions through 0.2. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that are executed when users visit the affected site.
WordPress WP Add Active Class To Menu Item Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress plugin 'WP Add Active Class To Menu Item' versions through 1.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Custom Dashboard Page Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Custom Dashboard Page plugin, specifically in versions through 1.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP Hide Admin Bar Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Hide Admin Bar plugin for WordPress, specifically in versions through 2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP No-Bot Question Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WP No-Bot Question plugin, affecting versions through 0.1.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
pipdig pipDisqus WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the pipdig pipDisqus WordPress plugin, affecting versions through 1.6. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when guests visit the site.
WordPress WP Last Modified Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress WP Last Modified plugin, affecting versions through 0.1. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.
Thiago S.F. Skitter Slideshow Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Thiago S.F. Skitter Slideshow WordPress plugin, affecting versions through 2.5.2. This vulnerability arises from improper input sanitization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the affected site.
Chaser324 Featured Posts Grid Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Chaser324 Featured Posts Grid plugin for WordPress, affecting versions through 1.7. This vulnerability arises from improper input sanitization during web page generation, allowing malicious users to inject harmful scripts that are executed when the affected page is viewed.
WordPress Contact Form 7 Select Box Editor Button CSRF Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Contact Form 7 Select Box Editor Button plugin, affecting versions through 0.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Members Page Only for Logged-in Users Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Members Page Only for Logged-in Users plugin, affecting versions through 1.4.2. This vulnerability allows for Stored Cross-Site Scripting, as it enables attackers to trick users with higher privileges into performing actions that could introduce malicious scripts, which are then permanently stored and potentially executed later.
WordPress TabGarb Pro Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress TabGarb Pro plugin, affecting versions through 2.6. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.
Steveorevo Domain Theme Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Steveorevo Domain Theme, specifically in versions through 1.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the theme's insufficient protection against CSRF, enabling attackers to manipulate users with higher privileges into performing actions that could introduce malicious scripts, which are then permanently stored and executed.
Akshar Soft Solutions AS English Admin Open Redirect Vulnerability
A URL redirection vulnerability allowing untrusted site redirection (open redirect) has been identified in the Akshar Soft Solutions AS English Admin plugin, affecting versions through 1.0.0. This vulnerability could be exploited for phishing attacks by redirecting users to malicious sites.
WordPress Custom Top Bar Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Custom Top Bar plugin, specifically in versions through 2.0.2. This issue arises from improper input neutralization during web page generation, allowing malicious users to inject harmful scripts that are executed when the page is viewed.
WordPress List of Posts from Each Category Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the 'List of Posts from each Category' plugin for WordPress, affecting versions through 2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress FTP Sync Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress FTP Sync plugin, specifically in versions through 1.1.6. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.
WordPress Price-Calc Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Price-Calc plugin, specifically in versions through 0.6.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress Fastmover Plugins Last Updated Column Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Fastmover WordPress plugin 'Last Updated Column', affecting versions through 0.1.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress REST API TO MiniProgram Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress REST API TO MiniProgram plugin, affecting versions through 4.7.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP Bulk Post Duplicator Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WP Bulk Post Duplicator plugin, affecting versions through 1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP Compare Tables Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Compare Tables plugin, specifically in versions through 1.0.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the application.
WordPress Mobile Themes Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Mobile Themes plugin, specifically in versions through 1.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Bee Layer Slider Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Bee Layer Slider WordPress plugin, affecting versions through 1.1. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Awesome Surveys Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Awesome Surveys plugin, affecting versions through 2.0.10. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Skrill Official WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Skrill Official WordPress plugin, specifically in versions through 1.0.65. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress BP Email Assign Templates Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress BP Email Assign Templates plugin, affecting versions through 1.6. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
Shanebp BP Email Assign Templates WordPress Plugin Authorization Bypass Vulnerability
An authorization bypass vulnerability has been identified in the BP Email Assign Templates WordPress plugin, specifically in versions through 1.7. This vulnerability allows for exploitation of improperly configured access control security levels, potentially leading to arbitrary content deletion.
WordPress Block Spam By Math Reloaded Missing Authorization Vulnerability
A broken access control vulnerability has been identified in the WordPress Block Spam By Math Reloaded plugin, affecting versions through 2.2.4. This vulnerability allows users to access functionalities that are not properly restricted by access control lists (ACLs).
WordPress Block Spam By Math Reloaded Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress plugin Block Spam By Math Reloaded, affecting versions through 2.2.4. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
amoCRM WebForm Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the amoCRM WebForm WordPress plugin, affecting versions through 1.1. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
WordPress ZipList Recipe Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the ZipList Recipe WordPress plugin, affecting versions through 3.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Frontpage Category Filter Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Frontpage Category Filter plugin, specifically in versions through 1.0.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Login Logger Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Login Logger plugin, specifically in versions through 1.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
