CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 7, 2025

Progress Sitefinity Cross-Site Scripting Vulnerability in Administrative Backend

A cross-site scripting (XSS) vulnerability has been identified in the administrative backend of Progress Sitefinity. This issue affects Sitefinity versions 4.0 through 14.4.8142, as well as 15.0.8200 through 15.0.8229, 15.1.8300 through 15.1.8327, and 15.2.8400 through 15.2.8421. The vulnerability arises from improper neutralization of input during web page generation, allowing for the injection of malicious scripts that could be executed in the context of the user's browser.

3.6
Jan 7, 2025

Progress Sitefinity Information Exposure Vulnerability

A vulnerability allowing information exposure through error messages has been identified in Progress Sitefinity. This issue affects versions 4.0 prior to 14.4.8142, 15.0.8200 through 15.0.8229, 15.1.8300 through 15.1.8327, and 15.2.8400 through 15.2.8421.

4.6
Jan 7, 2025

Export Import Menus WordPress Plugin Missing Authorization Vulnerability

A vulnerability exists in the Export Import Menus plugin for WordPress, in all versions through 1.9.1. The issue arises from a lack of proper capability checks in the 'dsp_export_import_menus()' function, allowing unauthenticated users to export menu data and settings without authorization.

3.2
Jan 7, 2025

Master Addons Elementor Addons Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Master Addons - Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress. This vulnerability affects all versions through 2.0.6.7 and arises from inadequate input sanitization and output escaping in the plugin's Tooltip module. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will be executed when users access the affected pages.

4.1
Jan 7, 2025

Estatik Mortgage Calculator Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Estatik Mortgage Calculator plugin for WordPress, affecting all versions through 2.0.11. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link.

3.1
Jan 7, 2025

Aurum WordPress and WooCommerce Shopping Theme Missing Authorization Vulnerability in Demo Content Import

A vulnerability exists in the Aurum WordPress and WooCommerce Shopping Theme, all versions through 4.0.2. The issue arises from a missing capability check in the 'lab_1cl_demo_install_package_content' function, allowing authenticated attackers with Subscriber-level access and above to overwrite existing content with demo content. This unauthorized data modification could lead to potential disruption or misrepresentation of the site's content.

1.7
Jan 7, 2025

Sina Extension for Elementor Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Sina Extension for Elementor plugin for WordPress, affecting all versions through 3.5.91. The issue arises in the Sina Image Differ widget, where inadequate input sanitization and output escaping of user-supplied attributes allow authenticated attackers with contributor-level access or higher to inject arbitrary scripts. These scripts are executed when a user accesses the compromised page.

3.1
Jan 7, 2025

WP jQuery DataTable Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WP jQuery DataTable plugin for WordPress, affecting all versions through 4.0.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'wp_jdt' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.4
Jan 7, 2025

Bootstrap Blocks for WP Editor Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Bootstrap Blocks for WP Editor plugin, specifically in version 2.5.0 and prior. This issue arises within the 'gtb-bootstrap/column' block, where inadequate input sanitization and output escaping allow authenticated attackers with Contributor-level access or higher to inject arbitrary scripts. These scripts are executed when users access the affected pages.

2.3
Jan 7, 2025

WordPress Marketplace Items Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Marketplace Items plugin for WordPress, affecting all versions up to and including 1.5.5. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'envato' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.3
Jan 7, 2025

Solar Wizard Lite Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Solar Wizard Lite plugin for WordPress, affecting all versions through 1.2.4. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'solar_wizard' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.

2.7
Jan 7, 2025

SMS Alert Order Notifications for WooCommerce Missing Authorization Vulnerability Privilege Escalation

A vulnerability in the SMS Alert Order Notifications – WooCommerce plugin for WordPress, in versions through 3.7.6, allows for unauthorized data modification that could lead to privilege escalation. This issue arises from a lack of proper capability checks in the updateWcWarrantySettings() function. As a result, authenticated attackers with subscriber-level access or higher can manipulate arbitrary options on the WordPress site. This vulnerability can be exploited to change the default user role for new registrations to administrator, effectively granting admin access to the attacker. The issue requires the WooCommerce Warranty plugin to be present on the site.

3.6
Jan 7, 2025

Passster WordPress Plugin Sensitive Information Exposure Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the Passster – Password Protect Pages and Content plugin for WordPress, affecting all versions through 4.2.10. This vulnerability arises from an unauthenticated content restriction bypass, enabling attackers to access sensitive data from posts restricted to higher-level roles, such as administrators, via the WordPress core search feature.

3.2
Jan 7, 2025

Social Rocket WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Social Rocket – Social Sharing Plugin for WordPress, affecting all versions through 1.3.4. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'socialrocket-floating' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

3.0
Jan 7, 2025

Social Rocket Social Sharing Plugin Missing Authorization Vulnerability in WordPress

A vulnerability exists in the Social Rocket – Social Sharing Plugin for WordPress, in all versions through 1.3.4. The issue arises from a lack of proper capability checks in the tweet_settings_save() and tweet_settings_update() functions. This flaw allows authenticated attackers with Subscriber-level access or higher to unauthorizedly modify the plugin's settings.

1.7
Jan 7, 2025

Category Posts Widget WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Category Posts Widget WordPress plugin, affecting versions prior to 4.9.18. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.

5.4
Jan 7, 2025

WordPress Auction Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Auction Plugin, affecting versions through 3.7. The issue arises because the plugin fails to properly sanitize and escape certain settings, allowing high-privilege users, such as editors, to inject malicious scripts that are stored and executed later.

3.3
Jan 7, 2025

WordPress Auction Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the WordPress Auction Plugin, affecting versions through 3.7. The issue arises because the plugin fails to properly sanitize and escape a parameter before incorporating it into a SQL statement. This flaw enables users with editor privileges and above to execute SQL injection attacks.

3.1
Jan 7, 2025

Axis Camera Station Pro Audit Log Tampering and Denial-of-Service Vulnerability

A vulnerability exists in Axis Camera Station Pro versions prior to 6.5, allowing authenticated malicious clients to interfere with audit log creation or execute a denial-of-service attack on the server by using maliciously crafted audit log entries.

1.7
Jan 7, 2025

Error Log Viewer By WP Guru Arbitrary File Read Vulnerability

A vulnerability allowing arbitrary file read has been identified in the Error Log Viewer By WP Guru plugin for WordPress, affecting all versions through 1.0.1.3. The issue arises from the wp_ajax_nopriv_elvwp_log_download AJAX action, which lacks proper authorization, enabling unauthenticated attackers to read arbitrary files on the server that may contain sensitive information.

3.7
Jan 7, 2025

JoomSport WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the JoomSport WordPress plugin, specifically in versions through 5.6.17. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link that contains the malicious payload.

4.1
Jan 7, 2025

Host PHP Info WordPress Plugin Missing Authorization Vulnerability in Sensitive Information Disclosure

A vulnerability exists in the Host PHP Info plugin for WordPress, all versions through 1.0.4, due to a lack of proper capability checks. This flaw allows unauthenticated attackers to access sensitive data by reading server configuration settings and predefined variables. Notably, the vulnerability can be exploited even if the plugin is not activated.

3.1
Jan 7, 2025

Post Saint WordPress Plugin Arbitrary File Upload Vulnerability Allowing Remote Code Execution

A vulnerability exists in the Post Saint WordPress plugin, specifically in versions through 1.3.1, allowing authenticated users with subscriber-level access and above to upload arbitrary files. This issue arises from a lack of proper capability checks and file type validation in the add_image_to_library AJAX action. The vulnerability could be exploited to execute remote code on the server.

1.9
Jan 7, 2025

Chatroll Live Chat Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Chatroll Live Chat plugin for WordPress, affecting all versions through 2.5.0. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'chatroll' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected page.

2.3
Jan 7, 2025

Candifly WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Candifly plugin for WordPress, affecting all versions through 1.0.6. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'candifly' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.4
Jan 7, 2025

WordPress Marketplace Items Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Marketplace Items plugin for WordPress, affecting all versions up to and including 1.5.5. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'marketplace' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.3
Jan 7, 2025

WooCommerce Digital Content Delivery (incl. DRM) - FlickRocket Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WooCommerce Digital Content Delivery (including DRM) - FlickRocket plugin for WordPress. This issue affects all versions up to and including 4.74. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if the attacker successfully persuades a user to perform an action, such as clicking a link, that triggers the script execution.

3.0
Jan 7, 2025

Binary MLM Woocommerce Plugin for WordPress Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Binary MLM Woocommerce plugin for WordPress, affecting all versions up to and including 2.0. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts would execute if a user is tricked into clicking a link.

3.0
Jan 7, 2025

Binary MLM Woocommerce Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Binary MLM Woocommerce plugin for WordPress, affecting all versions through 2.0. The vulnerability arises from inadequate nonce validation in the 'bmw_display_pv_set_page' function, coupled with insufficient sanitization and escaping of the 'product_points' parameter. This flaw enables unauthenticated attackers to inject arbitrary web scripts by crafting a forged request, provided they can persuade a site administrator to perform a specific action, such as clicking a link.

3.1
Jan 7, 2025

SmartEmailing WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the SmartEmailing.cz plugin for WordPress, affecting all versions through 2.2.0. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link.

2.0
Jan 7, 2025

Meteor Slides WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Meteor Slides plugin for WordPress, affecting all versions through 1.5.7. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. These scripts are executed when users access the compromised pages.

3.7
Jan 7, 2025

Geo Content WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Geo Content plugin for WordPress, affecting all versions through 6.0. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'geotargetlygeocontent' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.3
Jan 7, 2025

SweepWidget WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the SweepWidget Contests, Giveaways, Photo Contests, Competitions plugin for WordPress, affecting all versions through 2.0.6. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'sweepwidget' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.4
Jan 7, 2025

App Embed WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the App Embed plugin for WordPress, affecting all versions through 2.3.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'appizy' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.3
Jan 7, 2025

Tabs Shortcode WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Tabs Shortcode WordPress plugin, affecting versions through 2.0.2. The issue arises because the plugin fails to properly validate and escape certain shortcode attributes before rendering them on pages or posts. This flaw enables users with contributor roles and above to inject malicious scripts that are stored and executed later.

2.9
Jan 7, 2025

Store Credit and Gift Cards for WooCommerce Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Store Credit/Gift Cards for WooCommerce plugin for WordPress, affecting all versions through 1.0.49.46. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. This injected script could be executed if the attacker successfully persuades a user to perform a specific action, such as clicking a link. The vulnerable parameters include 'coupon', 'start_date', and 'end_date'.

3.0
Jan 7, 2025

Form Maker by 10Web WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Form Maker by 10Web WordPress plugin, affecting versions prior to 1.15.31. The issue arises because the plugin fails to properly sanitize and escape certain settings. This flaw enables high-privilege users, such as administrators, to execute stored cross-site scripting attacks, even in environments where the unfiltered_html capability is restricted, such as multisite setups.

4.9
Jan 7, 2025

FancyPost WordPress Plugin Missing Authorization Vulnerability in Shortcode Export

A vulnerability exists in the FancyPost WordPress plugin, specifically in the 'Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor' version 6.0.0 and prior. The issue arises from a lack of proper capability checks in the 'handle_block_shortcode_export()' function, allowing authenticated users with Subscriber-level access and above to export shortcodes without authorization.

2.3
Jan 7, 2025

Rbs Image Gallery WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Rbs Image Gallery WordPress plugin, specifically in versions prior to 3.2.22. The issue arises because the plugin fails to properly sanitize and escape certain gallery settings. This flaw enables high-privilege users, such as contributors, to execute stored cross-site scripting attacks.

4.2
Jan 7, 2025

WordPress Enable Accessibility Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Enable Accessibility plugin for WordPress, affecting all versions through 1.4.1. The issue arises from the plugin's use of add_query_arg and remove_query_arg functions without proper escaping, allowing unauthenticated attackers to inject arbitrary scripts. These scripts could be executed if a user is tricked into clicking a link.

3.1
Jan 7, 2025

School Management System SakolaWP Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in the School Management System – SakolaWP plugin for WordPress, affecting all versions through 1.0.8. The issue arises because the registration function fails to properly restrict the roles users can choose when registering. This flaw allows unauthenticated attackers to create accounts with administrative privileges.

2.6
Jan 7, 2025

YOGO Booking WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the YOGO Booking plugin for WordPress, affecting all versions through 1.6.2. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'yogo-calendar' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected page.

2.3
Jan 7, 2025

Chat Support for Viber Stored Cross-Site Scripting Vulnerability in WordPress Plugin

A stored cross-site scripting vulnerability has been identified in the Chat Support for Viber WordPress plugin, specifically in the Chat Bubble and Chat Button features for Gutenberg, Elementor, and Shortcode. This vulnerability exists in all versions through 1.7.3 and is due to inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'vchat' shortcode. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will execute when users access the affected pages.

2.3
Jan 7, 2025

Uptodown APK Download Widget Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Uptodown APK Download Widget plugin for WordPress, affecting all versions through 0.1.10. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'utd-widget' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.3
Jan 7, 2025

RightMessage WP Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the RightMessage WP plugin for WordPress, affecting all versions through 0.9.7. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'rm_area' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.

2.4
Jan 7, 2025

Compare Products for WooCommerce Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Compare Products for WooCommerce plugin for WordPress, affecting all versions through 3.2.1. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link or performing a similar action.

3.0
Jan 7, 2025

WPSchoolPress SQL Injection Vulnerability in School Management System

A SQL injection vulnerability has been identified in the WPSchoolPress plugin for WordPress, affecting all versions up to and including 2.2.14. The vulnerability arises from inadequate escaping of user-supplied data in the 'cid' parameter, allowing authenticated attackers with Student or Parent-level access to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information in the database.

3.4
Jan 7, 2025

LazyLoad Background Images WordPress Plugin Missing Authorization Vulnerability in Settings Update

A vulnerability exists in the LazyLoad Background Images WordPress plugin, all versions through 1.0.7, allowing unauthorized data modification. The issue arises from a lack of capability checks in the 'pblzbg_save_settings()' function. This flaw enables authenticated attackers with Subscriber-level access and above to alter the plugin's settings.

2.4
Jan 7, 2025

Unilevel MLM Plan WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Unilevel MLM Plan plugin for WordPress, affecting all versions through 1.1.0. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'page' parameter. These scripts could be executed if a user is tricked into clicking a link.

2.7
Jan 7, 2025

ThePerfectWedding.nl Widget WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the ThePerfectWedding.nl Widget plugin for WordPress, affecting all versions through 2.8. The vulnerability arises from inadequate nonce validation in the 'update_option' function, allowing unauthenticated attackers to manipulate the 'tpwKey' option. This can be achieved by injecting stored cross-site scripting through a forged request, provided the attacker can persuade a site administrator to click a link or perform a similar action.

2.7