CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 24, 2025

Themeisle PPOM for WooCommerce Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Themeisle PPOM for WooCommerce plugin, affecting versions through 33.0.8. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the site.

1.5
Jan 24, 2025

ThemeIsle AI Chatbot for WordPress Hyve Lite Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the ThemeIsle AI Chatbot for WordPress – Hyve Lite plugin, affecting versions through 1.2.2. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.5
Jan 24, 2025

WordPress Simple Download Monitor SQL Injection Vulnerability

A blind SQL injection vulnerability has been identified in the WordPress Simple Download Monitor plugin, affecting versions through 3.9.25. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling direct interaction with the database, such as stealing information.

3.6
Jan 24, 2025

WordPress Download Manager Premium Packages SQL Injection Vulnerability

A blind SQL injection vulnerability has been identified in the WordPress Download Manager Premium Packages plugin, affecting versions through 5.9.6. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing for direct interaction with the database, such as stealing information.

2.9
Jan 24, 2025

WordPress Auction Nudge Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Auction Nudge – Your eBay on Your Site plugin, affecting versions through 7.2.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.5
Jan 24, 2025

WebToffee Wishlist for WooCommerce Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WebToffee Wishlist for WooCommerce plugin, affecting versions through 2.1.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.5
Jan 24, 2025

Revmakx WP Duplicate WordPress Migration Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the Revmakx WP Duplicate – WordPress Migration Plugin, affecting versions through 1.1.6. This vulnerability allows exploitation of improperly configured access control, potentially enabling unprivileged users to perform actions reserved for higher privileges.

1.8
Jan 24, 2025

Themefic Tourfic WordPress Plugin Arbitrary File Upload Vulnerability

A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the Themefic Tourfic WordPress plugin, affecting versions through 2.15.3. This vulnerability could be exploited to upload a web shell to the server.

2.1
Jan 24, 2025

WordPress Admin and Site Enhancements (ASE) Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the WordPress Admin and Site Enhancements (ASE) Plugin, affecting versions through 7.6.2. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.

2.2
Jan 24, 2025

WordPress WooCommerce Cloak Affiliate Links Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WooCommerce Cloak Affiliate Links plugin, affecting versions through 1.0.35. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 24, 2025

WebToffee WooCommerce PDF Invoices Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin, affecting versions through 4.7.1. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users view the affected content.

3.7
Jan 24, 2025

WordPress Create with Code Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress Create with Code plugin, affecting versions through 1.4. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 24, 2025

Laymance Technologies MachForm Shortcode Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the MachForm Shortcode plugin by Laymance Technologies, LLC. This vulnerability allows for Stored Cross-Site Scripting (XSS) and affects versions of the plugin through 1.4.1.

2.0
Jan 24, 2025

WordPress Orbisius Simple Notice Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Orbisius Simple Notice WordPress plugin, specifically in versions through 1.1.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.5
Jan 24, 2025

Silverplugins Build Private Store For WooCommerce Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the Silverplugins Build Private Store For WooCommerce plugin, affecting versions through 1.0. This vulnerability arises from missing authorization checks, allowing unprivileged users to perform actions reserved for higher privileges.

2.6
Jan 24, 2025

WordPress Blur Text Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Blur Text plugin, specifically in versions through 1.0.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.6
Jan 24, 2025

WordPress Taxonomy/Term and Role Based Discounts for WooCommerce Missing Authorization Vulnerability

A missing authorization vulnerability has been identified in the WordPress plugin Taxonomy/Term and Role Based Discounts for WooCommerce, affecting versions through 5.1. This vulnerability allows exploitation of incorrectly configured access control security levels, potentially leading to unauthorized changes in settings.

2.0
Jan 24, 2025

Really Simple SSL WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Really Simple SSL WordPress plugin, affecting versions through 9.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 24, 2025

PickPlugins Job Board Manager Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the PickPlugins Job Board Manager WordPress plugin, affecting versions through 2.1.59. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 24, 2025

ElementInvader Addons for Elementor Missing Authorization Vulnerability

A broken access control vulnerability has been identified in the ElementInvader Addons for Elementor plugin, affecting versions through 1.3.1. This vulnerability arises from missing authorization checks, allowing users with lower privileges to perform actions reserved for higher privileged users.

2.4
Jan 24, 2025

Foliovision FV Thoughtful Comments Missing Authorization Vulnerability Allowing Access Control Exploitation

A missing authorization vulnerability has been identified in the Foliovision FV Thoughtful Comments WordPress plugin, affecting versions through 0.3.5. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions or access.

1.8
Jan 24, 2025

Smackcoders WP Ultimate Exporter Path Traversal Vulnerability Allowing Arbitrary File Download

A path traversal vulnerability has been identified in the Smackcoders WP Ultimate Exporter plugin, specifically in versions through 2.9. This vulnerability allows for absolute path traversal, enabling unauthorized access to files on the server. An attacker could exploit this to download sensitive files, such as those containing login credentials or backup data.

2.5
Jan 24, 2025

WordPress Restrict Anonymous Access Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Restrict Anonymous Access plugin, specifically in versions through 1.2. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when visitors access the affected site.

1.6
Jan 24, 2025

Vikas Ratudi VForm WordPress Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the Vikas Ratudi VForm WordPress plugin, specifically in versions through 3.0.5. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.

2.7
Jan 24, 2025

WC Product Table WooCommerce Product Table Lite Missing Authorization Vulnerability

A missing authorization vulnerability has been identified in the WC Product Table WooCommerce Product Table Lite plugin, affecting versions through 3.8.7. This vulnerability allows exploitation of improperly configured access control, potentially leading to unauthorized actions by users with lower privileges.

4.0
Jan 24, 2025

WordPress All Embed – Elementor Addons Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress All Embed – Elementor Addons plugin, affecting versions through 1.1.3. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.6
Jan 24, 2025

Speedcomp Linet ERP-Woocommerce Integration Missing Authorization Vulnerability

A missing authorization vulnerability has been identified in the Speedcomp Linet ERP-Woocommerce Integration plugin, affecting versions through 3.5.7. This vulnerability allows exploitation of improperly configured access control security levels, potentially leading to unauthorized actions being performed by users with higher privileges.

2.0
Jan 24, 2025

NinjaTeam GDPR CCPA Compliance Support Missing Authorization Vulnerability

A broken access control vulnerability has been identified in the NinjaTeam GDPR CCPA Compliance Support WordPress plugin, affecting versions through 2.7.1. This vulnerability arises from missing authorization checks, which can be exploited to manipulate access control security levels improperly.

3.8
Jan 24, 2025

WordPress JSM Show Post Metadata Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the WordPress JSM Show Post Metadata plugin, affecting versions through 4.6.0. This vulnerability allows exploitation of improperly configured access control security levels, potentially leading to unauthorized actions by users with lower privileges.

1.8
Jan 24, 2025

Patreon WordPress Plugin Missing Authorization Vulnerability Allowing Broken Access Control

A missing authorization vulnerability has been identified in the Patreon WordPress plugin, specifically in versions through 1.9.1. This vulnerability allows for broken access control by exploiting incorrectly configured security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.

4.7
Jan 24, 2025

I Thirteen Web Solution Email Subscription Popup SQL Injection Vulnerability

A blind SQL injection vulnerability has been identified in the I Thirteen Web Solution Email Subscription Popup plugin, affecting versions through 1.2.23. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing malicious actors to interact with the database and potentially steal information.

2.1
Jan 24, 2025

N.O.U.S. WordPress Event Post Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the N.O.U.S. WordPress Event Post plugin, affecting versions through 5.9.7. This vulnerability allows for the injection of malicious scripts that are executed when users visit the affected site.

2.0
Jan 24, 2025

Code for Recovery 12 Step Meeting List Sensitive Data Exposure Vulnerability

A vulnerability allowing the insertion of sensitive information into sent data has been identified in the Code for Recovery 12 Step Meeting List plugin, affecting versions through 3.16.5. This vulnerability could allow unauthorized retrieval of embedded sensitive data, which is typically not accessible to regular users.

3.0
Jan 24, 2025

Code for Recovery 12 Step Meeting List Missing Authorization Vulnerability Allowing Arbitrary Content Deletion

A missing authorization vulnerability has been identified in the Code for Recovery 12 Step Meeting List WordPress plugin, affecting versions through 3.16.5. This vulnerability allows exploitation of improperly configured access control security levels, leading to arbitrary content deletion. As a result, malicious actors could potentially remove posts, pages, or media from affected websites.

2.1
Jan 24, 2025

WordPress Nested Pages Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Nested Pages plugin, affecting versions through 3.2.9. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

3.6
Jan 24, 2025

ElementInvader Addons for Elementor DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the ElementInvader Addons for Elementor plugin, affecting versions through 1.3.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the affected site.

2.3
Jan 24, 2025

HelloAsso WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the HelloAsso WordPress plugin, affecting versions through 1.1.11. This vulnerability allows for the injection of malicious scripts that are executed when users visit the affected site.

2.0
Jan 24, 2025

WordPress PageLayer Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress PageLayer plugin, affecting versions through 1.9.4. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

3.7
Jan 24, 2025

Epsiloncool WP Fast Total Search Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Epsiloncool WP Fast Total Search plugin for WordPress, specifically in versions through 1.78.258. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 24, 2025

Epsiloncool WP Fast Total Search Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the Epsiloncool WP Fast Total Search plugin for WordPress, specifically in versions through 1.78.258. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.

1.8
Jan 24, 2025

Atarim WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Atarim WordPress plugin, affecting versions through 4.0.8. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.5
Jan 24, 2025

Brainstorm Force Starter Templates Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Brainstorm Force Starter Templates plugin for WordPress, affecting versions through 4.4.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

4.6
Jan 24, 2025

Optimal Access KBucket WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Optimal Access KBucket WordPress plugin, affecting versions through 4.1.6. This vulnerability allows for Stored Cross-Site Scripting, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 24, 2025

WordPress ReviewsTap Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress ReviewsTap plugin, specifically in versions through 1.1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 24, 2025

WordPress Subscription DNA Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Subscription DNA plugin, affecting versions through 2.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.

2.0
Jan 24, 2025

David de Boer Paytium WordPress Plugin Full Path Disclosure Vulnerability

A full path disclosure vulnerability has been identified in the David de Boer Paytium WordPress plugin, affecting versions through 4.4.11. This vulnerability allows the retrieval of embedded sensitive data by disclosing the full path of files or directories on the server.

2.5
Jan 24, 2025

Matthias Wagner Caching Compatible Cookie Opt-In and JavaScript Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress plugin 'Caching Compatible Cookie Opt-In and JavaScript' versions through 0.0.10. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that are executed when visitors access the affected site.

1.7
Jan 24, 2025

RSTheme Ultimate Coming Soon & Maintenance Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the RSTheme Ultimate Coming Soon & Maintenance plugin for WordPress, affecting versions through 1.0.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 24, 2025

WordPress Ultimate Coming Soon and Maintenance Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Ultimate Coming Soon & Maintenance plugin, specifically in versions through 1.0.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 24, 2025

Icegram WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Icegram WordPress plugin, affecting versions through 3.1.31. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

3.7