CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
HT Plugins HT Contact Form 7 Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the HT Contact Form 7 WordPress plugin, affecting versions through 1.2.1. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
ThimPress Thim Elementor Kit Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Thim Elementor Kit WordPress plugin, specifically in versions through 1.2.8. This vulnerability allows exploitation of improperly configured access control, potentially enabling users to perform actions reserved for higher privileges.
WordPress Side Menu Lite Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Side Menu Lite plugin, affecting versions through 5.3.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
CodePeople Booking Calendar Contact Form Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the CodePeople Booking Calendar Contact Form plugin, affecting versions through 1.2.55. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress FAQ Builder AYS Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress FAQ Builder AYS plugin, affecting versions through 1.7.3. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Aleksandar Urošević Easy YouTube Gallery Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Easy YouTube Gallery plugin by Aleksandar Urošević, affecting versions through 1.0.4. This vulnerability allows for the injection of malicious scripts that could be executed when users visit the affected site.
Wow-Company Sticky Buttons WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Sticky Buttons WordPress plugin, affecting versions through 4.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Widget Countdown Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Widget Countdown plugin, affecting versions through 2.7.1. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Wow-Company Modal Window Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Modal Window plugin for WordPress, affecting versions through 6.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Wow-Company Herd Effects WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Herd Effects WordPress plugin, affecting versions through 6.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Wow-Company Counter Box Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Counter Box WordPress plugin, affecting versions through 2.0.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Bubble Menu Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Bubble Menu – circle floating menu plugin, affecting versions through 4.0.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Button Generator Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Button Generator - Easily Button Builder plugin, affecting versions through 3.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
RadiusTheme Radius Blocks Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the RadiusTheme Radius Blocks plugin for WordPress, affecting versions through 2.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Popup Box Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Popup Box plugin, specifically in versions through 3.2.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Plethora Plugins Tabs + Accordions Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress plugin Plethora Plugins Tabs + Accordions, affecting versions through 1.1.5. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
MultiVendorX WC Marketplace Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the MultiVendorX WC Marketplace plugin for WordPress, affecting versions through 4.2.13. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Arshid WooCommerce Quick View Missing Authorization Vulnerability Allowing Sensitive Data Exposure
A missing authorization vulnerability in the Arshid WooCommerce Quick View plugin, affecting versions through 1.1.1, allows exploitation of improperly configured access control. This vulnerability could lead to unauthorized exposure of sensitive data that regular users typically cannot access.
WordPress Magic the Gathering Card Tooltips Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Magic the Gathering Card Tooltips plugin, affecting versions through 3.4.0. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.
WordPress DLX Plugins Comment Edit Core Server-Side Request Forgery Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in the WordPress Comment Edit Core – Simple Comment Editing plugin, affecting versions through 3.0.33. This vulnerability allows attackers to manipulate the server into making requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.
Xagio SEO Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Xagio SEO WordPress plugin, affecting versions through 7.0.0.20. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
Kiboko Labs Chained Quiz Server-Side Request Forgery Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in the Kiboko Labs Chained Quiz WordPress plugin, affecting versions through 1.3.2.9. This vulnerability allows attackers to manipulate the server into making requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.
G5Theme Essential Real Estate Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the G5Theme Essential Real Estate WordPress plugin, affecting versions through 5.1.8. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WP Attire Attire Blocks Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Attire Attire Blocks plugin, affecting versions through 1.9.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
HasThemes Extensions For CF7 Server-Side Request Forgery Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in HasThemes Extensions For CF7, affecting versions through 3.2.0. This vulnerability allows attackers to make the server send requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.
Yehi Advanced Notifications Plugin Missing Authorization Vulnerability Allowing Access Control Exploitation
A missing authorization vulnerability has been identified in the Yehi Advanced Notifications WordPress plugin, specifically in versions through 1.2.7. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions or changes.
WordPress People Lists Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WordPress People Lists plugin, affecting versions through 1.3.10. This vulnerability arises from missing authorization checks, allowing unprivileged users to exploit incorrectly configured access control security levels.
WordPress Show/Hide Shortcode Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Show/Hide Shortcode plugin, specifically in versions through 1.0.0. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WPChill RSVP and Event Management Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WPChill RSVP and Event Management Plugin, affecting versions through 2.7.14. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling malicious actors to interact with the database in unauthorized ways.
WordPress Super Block Slider Missing Authorization Vulnerability Allowing Access Control Exploitation
A missing authorization vulnerability has been identified in the WordPress Super Block Slider plugin, specifically in versions through 2.7.9. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions or changes.
wpWax Product Carousel Slider & Grid Ultimate for WooCommerce Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the wpWax Product Carousel Slider & Grid Ultimate for WooCommerce, affecting versions through 1.10.0. This vulnerability arises from improper input neutralization during web page generation, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.
Webraketen Internal Links Manager Missing Authorization Vulnerability
A broken access control vulnerability has been identified in the Webraketen Internal Links Manager plugin for WordPress, affecting versions through 2.5.2. This vulnerability arises from missing authorization checks, which can be exploited by users with lower privileges to perform actions reserved for higher privileged users.
Listamester WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Listamester WordPress plugin, affecting versions through 2.3.4. This vulnerability allows users to inject malicious scripts that are executed when other users visit the affected page.
WordPress WP Visitor Statistics Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress WP Visitor Statistics (Real Time Traffic) plugin, affecting versions through 7.2. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Teplitsa ShMapper WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Teplitsa ShMapper WordPress plugin, affecting versions through 1.5.0. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.
AyeCode Ketchup Shortcodes Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the AyeCode Ketchup Shortcodes WordPress plugin, affecting versions through 0.1.2. This vulnerability arises from improper neutralization of script-related HTML tags, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.
CodePeople Form Builder CP SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the CodePeople Form Builder CP plugin for WordPress, affecting versions through 1.2.41. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact with the database in unauthorized ways.
SERPed WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the SERPed WordPress plugin, specifically in versions through 4.4. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact directly with the database.
Themeisle PPOM for WooCommerce Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Themeisle PPOM for WooCommerce plugin, affecting versions through 33.0.8. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the site.
ThemeIsle AI Chatbot for WordPress Hyve Lite Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the ThemeIsle AI Chatbot for WordPress – Hyve Lite plugin, affecting versions through 1.2.2. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Simple Download Monitor SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the WordPress Simple Download Monitor plugin, affecting versions through 3.9.25. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling direct interaction with the database, such as stealing information.
WordPress Download Manager Premium Packages SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the WordPress Download Manager Premium Packages plugin, affecting versions through 5.9.6. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing for direct interaction with the database, such as stealing information.
WordPress Auction Nudge Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Auction Nudge – Your eBay on Your Site plugin, affecting versions through 7.2.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WebToffee Wishlist for WooCommerce Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WebToffee Wishlist for WooCommerce plugin, affecting versions through 2.1.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Revmakx WP Duplicate WordPress Migration Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Revmakx WP Duplicate – WordPress Migration Plugin, affecting versions through 1.1.6. This vulnerability allows exploitation of improperly configured access control, potentially enabling unprivileged users to perform actions reserved for higher privileges.
Themefic Tourfic WordPress Plugin Arbitrary File Upload Vulnerability
A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the Themefic Tourfic WordPress plugin, affecting versions through 2.15.3. This vulnerability could be exploited to upload a web shell to the server.
WordPress Admin and Site Enhancements (ASE) Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WordPress Admin and Site Enhancements (ASE) Plugin, affecting versions through 7.6.2. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.
WordPress WooCommerce Cloak Affiliate Links Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WooCommerce Cloak Affiliate Links plugin, affecting versions through 1.0.35. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WebToffee WooCommerce PDF Invoices Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin, affecting versions through 4.7.1. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users view the affected content.
WordPress Create with Code Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Create with Code plugin, affecting versions through 1.4. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
