CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Mar 11, 2025

Lava Code Lava Ajax Search Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Lava Ajax Search WordPress plugin, affecting versions through 1.1.9. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.5
Mar 11, 2025

Sakurapixel Lunar WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Sakurapixel Lunar WordPress plugin, affecting versions through 1.3.0. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.5
Mar 11, 2025

WordPress MaxA/B Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress MaxA/B plugin, specifically in versions through 2.2.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Mar 11, 2025

WordPress Insert Code Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Insert Code plugin, specifically in versions through 2.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the website.

2.0
Mar 11, 2025

DevriX WordPress Hashtags Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the DevriX WordPress Hashtags plugin, specifically in versions through 0.3.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Mar 11, 2025

WordPress List Mixcloud Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress List Mixcloud plugin, affecting versions through 1.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.6
Mar 11, 2025

Vivek Marakana Tabbed Login Widget Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Tabbed Login Widget plugin, affecting versions through 1.1.2. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.

1.7
Mar 11, 2025

WordPress Display Template Name Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Display Template Name plugin, affecting versions through 1.7.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress Post Read Time Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Post Read Time plugin, specifically in versions through 1.2.6. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.5
Mar 11, 2025

Hieu Nguyen WATI Chat and Notification Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WATI Chat and Notification WordPress plugin, specifically in versions through 1.1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.

2.0
Mar 11, 2025

WordPress No Disposable Email Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress No Disposable Email plugin, affecting versions through 2.5.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Mar 11, 2025

WordPress Go To Top Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Go To Top plugin, specifically in versions through 0.0.8. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Mar 11, 2025

WordPress Responsive Google Map Plugin Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the WordPress Responsive Google Map plugin, affecting versions through 3.1.5. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.

2.6
Mar 11, 2025

WordPress Easy Image Display Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Easy Image Display plugin, affecting versions through 1.2.5. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.6
Mar 11, 2025

WordPress Featured Image Thumbnail Grid Plugin Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Featured Image Thumbnail Grid plugin, affecting versions through 6.8. The issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.

1.7
Mar 11, 2025

ThemeEgg Toolkit WordPress Plugin Arbitrary File Upload Vulnerability

A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the ThemeEgg Toolkit WordPress plugin, affecting versions through 1.2.9. This vulnerability could be exploited to upload a web shell to the server, potentially leading to unauthorized access or control over the website.

1.7
Mar 11, 2025

WordPress Login Form to Anywhere Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Login Form to Anywhere plugin, specifically in versions through 0.2. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that are executed when users visit the affected site.

1.5
Mar 11, 2025

WordPress WP Add Active Class To Menu Item Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress plugin 'WP Add Active Class To Menu Item' versions through 1.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress Custom Dashboard Page Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Custom Dashboard Page plugin, specifically in versions through 1.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress WP Hide Admin Bar Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Hide Admin Bar plugin for WordPress, specifically in versions through 2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress WP No-Bot Question Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WP No-Bot Question plugin, affecting versions through 0.1.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

pipdig pipDisqus WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the pipdig pipDisqus WordPress plugin, affecting versions through 1.6. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when guests visit the site.

1.5
Mar 11, 2025

WordPress WP Last Modified Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress WP Last Modified plugin, affecting versions through 0.1. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.

1.5
Mar 11, 2025

Thiago S.F. Skitter Slideshow Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Thiago S.F. Skitter Slideshow WordPress plugin, affecting versions through 2.5.2. This vulnerability arises from improper input sanitization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the affected site.

1.5
Mar 11, 2025

Chaser324 Featured Posts Grid Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Chaser324 Featured Posts Grid plugin for WordPress, affecting versions through 1.7. This vulnerability arises from improper input sanitization during web page generation, allowing malicious users to inject harmful scripts that are executed when the affected page is viewed.

2.0
Mar 11, 2025

WordPress Contact Form 7 Select Box Editor Button CSRF Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Contact Form 7 Select Box Editor Button plugin, affecting versions through 0.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress Members Page Only for Logged-in Users Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Members Page Only for Logged-in Users plugin, affecting versions through 1.4.2. This vulnerability allows for Stored Cross-Site Scripting, as it enables attackers to trick users with higher privileges into performing actions that could introduce malicious scripts, which are then permanently stored and potentially executed later.

2.0
Mar 11, 2025

WordPress TabGarb Pro Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress TabGarb Pro plugin, affecting versions through 2.6. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Mar 11, 2025

Steveorevo Domain Theme Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Steveorevo Domain Theme, specifically in versions through 1.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the theme's insufficient protection against CSRF, enabling attackers to manipulate users with higher privileges into performing actions that could introduce malicious scripts, which are then permanently stored and executed.

2.0
Mar 11, 2025

Akshar Soft Solutions AS English Admin Open Redirect Vulnerability

A URL redirection vulnerability allowing untrusted site redirection (open redirect) has been identified in the Akshar Soft Solutions AS English Admin plugin, affecting versions through 1.0.0. This vulnerability could be exploited for phishing attacks by redirecting users to malicious sites.

2.5
Mar 11, 2025

WordPress Custom Top Bar Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Custom Top Bar plugin, specifically in versions through 2.0.2. This issue arises from improper input neutralization during web page generation, allowing malicious users to inject harmful scripts that are executed when the page is viewed.

2.0
Mar 11, 2025

WordPress List of Posts from Each Category Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the 'List of Posts from each Category' plugin for WordPress, affecting versions through 2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Mar 11, 2025

WordPress FTP Sync Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress FTP Sync plugin, specifically in versions through 1.1.6. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Mar 11, 2025

WordPress Price-Calc Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Price-Calc plugin, specifically in versions through 0.6.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Mar 11, 2025

WordPress Fastmover Plugins Last Updated Column Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Fastmover WordPress plugin 'Last Updated Column', affecting versions through 0.1.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress REST API TO MiniProgram Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress REST API TO MiniProgram plugin, affecting versions through 4.7.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress WP Bulk Post Duplicator Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WP Bulk Post Duplicator plugin, affecting versions through 1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Mar 11, 2025

WordPress WP Compare Tables Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Compare Tables plugin, specifically in versions through 1.0.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the application.

2.0
Mar 11, 2025

WordPress Mobile Themes Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Mobile Themes plugin, specifically in versions through 1.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

Bee Layer Slider Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Bee Layer Slider WordPress plugin, affecting versions through 1.1. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

2.0
Mar 11, 2025

WordPress Awesome Surveys Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Awesome Surveys plugin, affecting versions through 2.0.10. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.7
Mar 11, 2025

Skrill Official WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Skrill Official WordPress plugin, specifically in versions through 1.0.65. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress BP Email Assign Templates Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress BP Email Assign Templates plugin, affecting versions through 1.6. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.

1.5
Mar 11, 2025

Shanebp BP Email Assign Templates WordPress Plugin Authorization Bypass Vulnerability

An authorization bypass vulnerability has been identified in the BP Email Assign Templates WordPress plugin, specifically in versions through 1.7. This vulnerability allows for exploitation of improperly configured access control security levels, potentially leading to arbitrary content deletion.

1.6
Mar 11, 2025

WordPress Block Spam By Math Reloaded Missing Authorization Vulnerability

A broken access control vulnerability has been identified in the WordPress Block Spam By Math Reloaded plugin, affecting versions through 2.2.4. This vulnerability allows users to access functionalities that are not properly restricted by access control lists (ACLs).

2.5
Mar 11, 2025

WordPress Block Spam By Math Reloaded Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress plugin Block Spam By Math Reloaded, affecting versions through 2.2.4. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.5
Mar 11, 2025

amoCRM WebForm Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the amoCRM WebForm WordPress plugin, affecting versions through 1.1. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Mar 11, 2025

WordPress ZipList Recipe Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ZipList Recipe WordPress plugin, affecting versions through 3.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Mar 11, 2025

WordPress Frontpage Category Filter Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Frontpage Category Filter plugin, specifically in versions through 1.0.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress Login Logger Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Login Logger plugin, specifically in versions through 1.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0