CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 24, 2025

HT Plugins HT Contact Form 7 Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the HT Contact Form 7 WordPress plugin, affecting versions through 1.2.1. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.

1.7
Jan 24, 2025

ThimPress Thim Elementor Kit Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the Thim Elementor Kit WordPress plugin, specifically in versions through 1.2.8. This vulnerability allows exploitation of improperly configured access control, potentially enabling users to perform actions reserved for higher privileges.

1.8
Jan 24, 2025

WordPress Side Menu Lite Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Side Menu Lite plugin, affecting versions through 5.3.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 24, 2025

CodePeople Booking Calendar Contact Form Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the CodePeople Booking Calendar Contact Form plugin, affecting versions through 1.2.55. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

2.8
Jan 24, 2025

WordPress FAQ Builder AYS Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress FAQ Builder AYS plugin, affecting versions through 1.7.3. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.5
Jan 24, 2025

Aleksandar Urošević Easy YouTube Gallery Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Easy YouTube Gallery plugin by Aleksandar Urošević, affecting versions through 1.0.4. This vulnerability allows for the injection of malicious scripts that could be executed when users visit the affected site.

1.7
Jan 24, 2025

Wow-Company Sticky Buttons WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Sticky Buttons WordPress plugin, affecting versions through 4.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.7
Jan 24, 2025

WordPress Widget Countdown Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Widget Countdown plugin, affecting versions through 2.7.1. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7
Jan 24, 2025

Wow-Company Modal Window Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Modal Window plugin for WordPress, affecting versions through 6.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 24, 2025

Wow-Company Herd Effects WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Herd Effects WordPress plugin, affecting versions through 6.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 24, 2025

Wow-Company Counter Box Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Counter Box WordPress plugin, affecting versions through 2.0.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.5
Jan 24, 2025

WordPress Bubble Menu Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Bubble Menu – circle floating menu plugin, affecting versions through 4.0.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 24, 2025

WordPress Button Generator Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Button Generator - Easily Button Builder plugin, affecting versions through 3.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 24, 2025

RadiusTheme Radius Blocks Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the RadiusTheme Radius Blocks plugin for WordPress, affecting versions through 2.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 24, 2025

WordPress Popup Box Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Popup Box plugin, specifically in versions through 3.2.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.5
Jan 24, 2025

Plethora Plugins Tabs + Accordions Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress plugin Plethora Plugins Tabs + Accordions, affecting versions through 1.1.5. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7
Jan 24, 2025

MultiVendorX WC Marketplace Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the MultiVendorX WC Marketplace plugin for WordPress, affecting versions through 4.2.13. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

3.0
Jan 24, 2025

Arshid WooCommerce Quick View Missing Authorization Vulnerability Allowing Sensitive Data Exposure

A missing authorization vulnerability in the Arshid WooCommerce Quick View plugin, affecting versions through 1.1.1, allows exploitation of improperly configured access control. This vulnerability could lead to unauthorized exposure of sensitive data that regular users typically cannot access.

2.5
Jan 24, 2025

WordPress Magic the Gathering Card Tooltips Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Magic the Gathering Card Tooltips plugin, affecting versions through 3.4.0. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.

1.6
Jan 24, 2025

WordPress DLX Plugins Comment Edit Core Server-Side Request Forgery Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability exists in the WordPress Comment Edit Core – Simple Comment Editing plugin, affecting versions through 3.0.33. This vulnerability allows attackers to manipulate the server into making requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.

1.5
Jan 24, 2025

Xagio SEO Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Xagio SEO WordPress plugin, affecting versions through 7.0.0.20. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.7
Jan 24, 2025

Kiboko Labs Chained Quiz Server-Side Request Forgery Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability exists in the Kiboko Labs Chained Quiz WordPress plugin, affecting versions through 1.3.2.9. This vulnerability allows attackers to manipulate the server into making requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.

2.4
Jan 24, 2025

G5Theme Essential Real Estate Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the G5Theme Essential Real Estate WordPress plugin, affecting versions through 5.1.8. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

3.0
Jan 24, 2025

WP Attire Attire Blocks Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Attire Attire Blocks plugin, affecting versions through 1.9.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 24, 2025

HasThemes Extensions For CF7 Server-Side Request Forgery Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability exists in HasThemes Extensions For CF7, affecting versions through 3.2.0. This vulnerability allows attackers to make the server send requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.

2.9
Jan 24, 2025

Yehi Advanced Notifications Plugin Missing Authorization Vulnerability Allowing Access Control Exploitation

A missing authorization vulnerability has been identified in the Yehi Advanced Notifications WordPress plugin, specifically in versions through 1.2.7. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions or changes.

1.8
Jan 24, 2025

WordPress People Lists Plugin Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the WordPress People Lists plugin, affecting versions through 1.3.10. This vulnerability arises from missing authorization checks, allowing unprivileged users to exploit incorrectly configured access control security levels.

1.8
Jan 24, 2025

WordPress Show/Hide Shortcode Plugin Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Show/Hide Shortcode plugin, specifically in versions through 1.0.0. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7
Jan 24, 2025

WPChill RSVP and Event Management Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the WPChill RSVP and Event Management Plugin, affecting versions through 2.7.14. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling malicious actors to interact with the database in unauthorized ways.

2.5
Jan 24, 2025

WordPress Super Block Slider Missing Authorization Vulnerability Allowing Access Control Exploitation

A missing authorization vulnerability has been identified in the WordPress Super Block Slider plugin, specifically in versions through 2.7.9. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions or changes.

1.8
Jan 24, 2025

wpWax Product Carousel Slider & Grid Ultimate for WooCommerce Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the wpWax Product Carousel Slider & Grid Ultimate for WooCommerce, affecting versions through 1.10.0. This vulnerability arises from improper input neutralization during web page generation, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.

1.7
Jan 24, 2025

Webraketen Internal Links Manager Missing Authorization Vulnerability

A broken access control vulnerability has been identified in the Webraketen Internal Links Manager plugin for WordPress, affecting versions through 2.5.2. This vulnerability arises from missing authorization checks, which can be exploited by users with lower privileges to perform actions reserved for higher privileged users.

1.8
Jan 24, 2025

Listamester WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Listamester WordPress plugin, affecting versions through 2.3.4. This vulnerability allows users to inject malicious scripts that are executed when other users visit the affected page.

2.0
Jan 24, 2025

WordPress WP Visitor Statistics Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress WP Visitor Statistics (Real Time Traffic) plugin, affecting versions through 7.2. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

2.1
Jan 24, 2025

Teplitsa ShMapper WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Teplitsa ShMapper WordPress plugin, affecting versions through 1.5.0. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.

1.6
Jan 24, 2025

AyeCode Ketchup Shortcodes Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the AyeCode Ketchup Shortcodes WordPress plugin, affecting versions through 0.1.2. This vulnerability arises from improper neutralization of script-related HTML tags, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.

2.3
Jan 24, 2025

CodePeople Form Builder CP SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the CodePeople Form Builder CP plugin for WordPress, affecting versions through 1.2.41. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact with the database in unauthorized ways.

3.1
Jan 24, 2025

SERPed WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the SERPed WordPress plugin, specifically in versions through 4.4. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact directly with the database.

1.7
Jan 24, 2025

Themeisle PPOM for WooCommerce Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Themeisle PPOM for WooCommerce plugin, affecting versions through 33.0.8. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the site.

1.5
Jan 24, 2025

ThemeIsle AI Chatbot for WordPress Hyve Lite Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the ThemeIsle AI Chatbot for WordPress – Hyve Lite plugin, affecting versions through 1.2.2. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.5
Jan 24, 2025

WordPress Simple Download Monitor SQL Injection Vulnerability

A blind SQL injection vulnerability has been identified in the WordPress Simple Download Monitor plugin, affecting versions through 3.9.25. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling direct interaction with the database, such as stealing information.

3.6
Jan 24, 2025

WordPress Download Manager Premium Packages SQL Injection Vulnerability

A blind SQL injection vulnerability has been identified in the WordPress Download Manager Premium Packages plugin, affecting versions through 5.9.6. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing for direct interaction with the database, such as stealing information.

2.9
Jan 24, 2025

WordPress Auction Nudge Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Auction Nudge – Your eBay on Your Site plugin, affecting versions through 7.2.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.5
Jan 24, 2025

WebToffee Wishlist for WooCommerce Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WebToffee Wishlist for WooCommerce plugin, affecting versions through 2.1.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.5
Jan 24, 2025

Revmakx WP Duplicate WordPress Migration Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the Revmakx WP Duplicate – WordPress Migration Plugin, affecting versions through 1.1.6. This vulnerability allows exploitation of improperly configured access control, potentially enabling unprivileged users to perform actions reserved for higher privileges.

1.8
Jan 24, 2025

Themefic Tourfic WordPress Plugin Arbitrary File Upload Vulnerability

A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the Themefic Tourfic WordPress plugin, affecting versions through 2.15.3. This vulnerability could be exploited to upload a web shell to the server.

2.1
Jan 24, 2025

WordPress Admin and Site Enhancements (ASE) Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the WordPress Admin and Site Enhancements (ASE) Plugin, affecting versions through 7.6.2. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.

2.2
Jan 24, 2025

WordPress WooCommerce Cloak Affiliate Links Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WooCommerce Cloak Affiliate Links plugin, affecting versions through 1.0.35. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 24, 2025

WebToffee WooCommerce PDF Invoices Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin, affecting versions through 4.7.1. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users view the affected content.

3.7
Jan 24, 2025

WordPress Create with Code Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress Create with Code plugin, affecting versions through 1.4. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6