CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 16, 2025

Kreg Steppe Auphonic Importer Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Kreg Steppe Auphonic Importer WordPress plugin, affecting versions through 1.5.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.

2.0
Jan 16, 2025

WordPress QuoteMedia Tools Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the QuoteMedia Tools WordPress plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 16, 2025

WordPress Sidebar-Content from Shortcode Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress Sidebar-Content from Shortcode plugin, affecting versions through 2.0. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 16, 2025

WordPress Powie's pLinks PagePeeker Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in WordPress Powie's pLinks PagePeeker Plugin versions through 1.0.2. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 16, 2025

WordPress Rename Author Slug Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Rename Author Slug plugin, specifically in versions through 1.2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

MDC YouTube Downloader Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the MDC YouTube Downloader WordPress plugin, affecting versions through 3.0.0. This vulnerability allows for Stored Cross-Site Scripting, where an attacker could trick users with higher privileges into performing actions that introduce malicious scripts, which are then stored and potentially executed later.

2.5
Jan 16, 2025

WordPress Comment-Emailer Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Comment-Emailer plugin, specifically in versions through 1.0.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.

2.0
Jan 16, 2025

WordPress Contact Form 7 – CCAvenue Add-on Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Contact Form 7 – CCAvenue Add-on, affecting versions through 1.0. This vulnerability arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 16, 2025

WordPress Captchelfie Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Captchelfie – Captcha by Selfie plugin, affecting versions through 1.0.7. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.

2.0
Jan 16, 2025

WordPress Twitter Shortcode Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Twitter Shortcode plugin, affecting versions through 0.9. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.

2.0
Jan 16, 2025

Oliver Schaal Floatbox Plus Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Oliver Schaal Floatbox Plus WordPress plugin, specifically in versions through 1.4.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 16, 2025

Sourov Amin Word Freshener Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Sourov Amin Word Freshener plugin for WordPress, affecting versions through 1.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.

2.0
Jan 16, 2025

WordPress WP Background Tile Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Background Tile plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

WordPress UpDownUpDown Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress UpDownUpDown plugin, specifically in versions through 1.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

WordPress Shortcode in Comment Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Shortcode in Comment plugin, specifically in versions through 1.1.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could exploit higher privileged users into performing unintended actions under their current authentication.

2.0
Jan 16, 2025

Intuitive Design GDReseller Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Intuitive Design GDReseller WordPress plugin, affecting versions through 1.6. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

Syed Amir Hussain Custom Post Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Syed Amir Hussain Custom Post plugin for WordPress, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

WordPress Web Testimonials Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Web Testimonials plugin, specifically in versions through 1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the website.

2.0
Jan 16, 2025

WordPress MemeOne Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress MemeOne plugin, specifically in versions through 2.0.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.

2.0
Jan 16, 2025

WordPress Geotagged Media Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Geotagged Media plugin, specifically in versions through 0.3.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could potentially inject harmful scripts that are executed when the affected page is viewed.

2.0
Jan 16, 2025

WordPress Find Your Reps Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Find Your Reps plugin, specifically in versions through 1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

WordPress LH Login Page Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress LH Login Page plugin, affecting versions through 2.14. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 16, 2025

WordPress Add Custom Google Tag Manager Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress plugin 'Add Custom Google Tag Manager' versions through 1.0.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

WordPress WP Lyrics Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Lyrics plugin, specifically in versions through 0.4.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.

2.0
Jan 16, 2025

WordPress MyAnime Widget Privilege Escalation Vulnerability via Cross-Site Request Forgery

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress MyAnime Widget plugin, affecting versions through 1.0, allows for privilege escalation. This vulnerability could enable attackers to manipulate users with higher privileges into performing actions they did not intend to.

2.1
Jan 16, 2025

WordPress Custom Post Type Lockdown Cross-Site Request Forgery Vulnerability Allowing Privilege Escalation

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Custom Post Type Lockdown plugin, specifically in versions through 1.11. This vulnerability allows for privilege escalation by enabling attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 16, 2025

WordPress DD Roles Plugin Privilege Escalation Vulnerability

A privilege escalation vulnerability has been identified in the WordPress DD Roles plugin, affecting versions through 4.1. This vulnerability allows users with low privileges to gain higher privileges, potentially leading to full control of the website.

1.8
Jan 16, 2025

Sanjaysolutions Loginplus Missing Authorization Vulnerability Allowing Broken Access Control

A broken access control vulnerability has been identified in the Sanjaysolutions Loginplus WordPress plugin, affecting versions through 1.2. This vulnerability allows users to access functionalities that are not properly restricted by access control lists (ACLs), potentially leading to unauthorized actions or data exposure.

2.5
Jan 16, 2025

Joshua Wieczorek Bible Embed Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Joshua Wieczorek Bible Embed WordPress plugin, affecting versions through 0.0.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 16, 2025

WordPress WP-BlackCheck Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP-BlackCheck plugin, specifically in versions through 2.7.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.

2.0
Jan 16, 2025

Zaantar WordPress Logging Service Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Zaantar WordPress Logging Service plugin, affecting versions through 1.5.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 16, 2025

WordPress Extra Options – Favicons Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Extra Options – Favicons plugin, affecting versions through 1.1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts into the site.

2.0
Jan 16, 2025

SpruceJoy Cookie Consent & Autoblock for GDPR/CCPA Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the SpruceJoy Cookie Consent & Autoblock for GDPR/CCPA plugin, affecting versions through 1.0.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 16, 2025

WordPress Board Election Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Board Election plugin, specifically in versions through 1.0.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.

2.0
Jan 16, 2025

WordPress Simple Project Manager Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Simple Project Manager plugin, specifically in versions through 1.2.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts that are stored and executed later.

2.0
Jan 16, 2025

WordPress Universal Analytics Injector Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Universal Analytics Injector plugin, specifically in versions through 1.0.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.

2.0
Jan 16, 2025

WordPress My-Related-Posts Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress My-Related-Posts plugin, specifically in versions through 1.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

WordPress ECT Add to Cart Button Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress ECT Add to Cart Button plugin, affecting versions through 1.4. This vulnerability allows for Stored Cross-Site Scripting, where an attacker could trick users with higher privileges into performing actions that could lead to the execution of malicious scripts.

2.0
Jan 16, 2025

WordPress Visit Site Link Enhanced Plugin CSRF Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Visit Site Link Enhanced plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

WordPress RSS News Scroller Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress RSS News Scroller plugin, specifically in versions through 2.0.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 16, 2025

WordPress MD Custom Content Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress MD Custom Content plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the content.

2.0
Jan 16, 2025

WordPress EmailShroud Plugin Cross-Site Request Forgery Vulnerability Allowing Reflected Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress EmailShroud plugin, specifically in versions through 2.2.1. This vulnerability allows for Reflected Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts.

2.0
Jan 16, 2025

WordPress WP VTiger Synchronization Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP VTiger Synchronization plugin, specifically in versions through 1.1.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts that are permanently stored and executed later.

2.0
Jan 16, 2025

Myriad Solutionz Stars SMTP Mailer Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Myriad Solutionz Stars SMTP Mailer plugin for WordPress, affecting versions through 1.7. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 16, 2025

EditionGuard for WooCommerce Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the EditionGuard for WooCommerce – eBook Sales with DRM plugin, affecting versions through 3.4.2. This vulnerability allows for improper neutralization of input, enabling the injection of malicious scripts that could be executed when users visit the affected site.

2.0
Jan 16, 2025

Scott Swezey Easy Tynt WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Scott Swezey Easy Tynt WordPress plugin, affecting versions through 0.2.5.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 16, 2025

WordPress Scroll Top Advanced Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Scroll Top Advanced plugin, affecting versions through 2.5. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that are executed when users visit the site.

1.7
Jan 16, 2025

WordPress Shockingly Big IE6 Warning Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Shockingly Big IE6 Warning plugin, affecting versions through 1.6.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.

2.0
Jan 16, 2025

MarvinLabs WP PT-Viewer Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the MarvinLabs WP PT-Viewer WordPress plugin, affecting versions through 2.0.2. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 16, 2025

Capa Wp-Scribd-List Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Capa Wp-Scribd-List plugin for WordPress, specifically in versions through 1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0