CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Incredible Font Awesome Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress plugin Incredible Font Awesome, affecting versions through 1.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
TC Ajax WP Query Search Filter Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the TC Ajax WP Query Search Filter plugin for WordPress, affecting versions through 1.0.7. This vulnerability arises from improper input sanitization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the affected site.
WordPress Feedburner Optin Form Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Feedburner Optin Form plugin, affecting versions through 0.2.8. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WP Photo Sphere Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Photo Sphere WordPress plugin, affecting versions through 3.8. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress iSpring Embedder Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress iSpring Embedder plugin, specifically in versions through 1.0. This vulnerability allows attackers to upload a web shell to a web server by exploiting the CSRF flaw.
WordPress Slides and Presentations Plugin Code Injection Vulnerability
A cross-site scripting (XSS) vulnerability allowing code injection has been identified in the WordPress Slides & Presentations plugin, versions through 0.0.39. This vulnerability arises from improper neutralization of script-related HTML tags, which could enable a malicious actor to inject content into pages and posts, potentially including phishing materials.
Chamber Dashboard Business Directory Missing Authorization Vulnerability Allowing Broken Access Control
A broken access control vulnerability has been identified in the Chamber Dashboard Business Directory WordPress plugin, affecting versions through 3.3.10. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileged users.
Nuanced Media WP Meetup Missing Authorization Vulnerability Allowing Access Control Misconfiguration
A missing authorization vulnerability exists in the Nuanced Media WP Meetup plugin, affecting versions through 2.3.0. This vulnerability allows for exploitation of improperly configured access control security levels, potentially leading to unauthorized changes in settings.
Roninwp FAT Event Lite Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the Roninwp FAT Event Lite WordPress plugin, affecting versions through 1.1. This vulnerability arises from improper control of filenames in include or require statements, allowing for PHP remote file inclusion. Exploitation of this issue could enable a malicious actor to include local files from the target website and display their contents, potentially leading to a database takeover if sensitive information such as database credentials is accessed.
WordPress Google Map Professional SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WordPress Google Map Professional plugin, affecting versions through 1.0. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact directly with the database.
Typomedia Foundation WordPress Custom Sidebar SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the Typomedia Foundation WordPress Custom Sidebar plugin, affecting versions through 2.3. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing for unauthorized database manipulation.
Solidres WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the Solidres – Hotel Booking plugin for WordPress, affecting versions through 0.9.4. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact directly with the database.
Common Ninja Compare Ninja Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Common Ninja Compare Ninja plugin for WordPress, affecting versions through 2.1.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Pastebin Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Pastebin Plugin, affecting versions through 1.5. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Social Ninja Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Social Ninja plugin, specifically in versions through 0.2. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.
WordPress Error Notification Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Error Notification plugin, specifically in versions through 0.2.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Oliver Schaal GravatarLocalCache WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Oliver Schaal GravatarLocalCache WordPress plugin, affecting versions through 1.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Genkisan Genki Announcement Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Genkisan Genki Announcement WordPress plugin, affecting versions through 1.4.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
BnB Select Bookalet Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the BnB Select Ltd Bookalet WordPress plugin, affecting versions through 1.0.3. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Apply with LinkedIn Buttons Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Apply with LinkedIn Buttons plugin, specifically in versions through 2.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts.
Ivo Brett ApplyMetrics WordPress Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Apply with LinkedIn buttons plugin, affecting versions through 2.3. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
WordPress Mindmeister Shortcode Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Mindmeister Shortcode plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
WordPress Add RSS Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Add RSS plugin, specifically in versions through 1.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.
WordPress GMap Shortcode Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress GMap Shortcode plugin, affecting versions through 2.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
WordPress Progress Tracker Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Progress Tracker plugin, affecting versions through 0.9.3. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts or HTML payloads on the affected site.
WordPress Yet Another Countdown Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Yet Another Countdown plugin, affecting versions through 1.0.1. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
WordPress Easy Tweet Embed Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Easy Tweet Embed plugin, affecting versions through 1.7. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
WordPress Blog Summary Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Blog Summary plugin, specifically in versions through 0.1.2 β. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Annie Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Annie plugin, affecting versions through 2.1.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Annie Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Annie plugin, affecting versions through 2.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress amr personalise Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress amr personalise plugin, affecting versions through 2.10. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Post-to-Post Links Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Post-to-Post Links plugin, affecting versions through 4.2. This issue arises from improper input sanitization during web page generation, allowing malicious users to inject scripts that are executed when other users visit the affected page.
Nite Themes Nite Shortcodes Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Nite Shortcodes WordPress plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the site.
Jens Remus WP krpano Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress WP krpano plugin, affecting versions through 1.2.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Better Protected Pages Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Better Protected Pages plugin, affecting versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.
Anshi Solutions Category D3 Tree Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Anshi Solutions Category D3 Tree plugin for WordPress, affecting versions through 1.1. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
PayForm WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the PayForm WordPress plugin, affecting versions through 2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.
LSD Google Maps Embedder CSRF Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the LSD Google Maps Embedder WordPress plugin, affecting versions through 1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Copyright Safeguard Footer Notice Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Copyright Safeguard Footer Notice plugin, affecting versions through 3.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.
WordPress CJ Custom Content Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress CJ Custom Content plugin, specifically in versions through 2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts that are stored and executed later.
WordPress Chess Tempo Viewer Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Chess Tempo Viewer plugin, affecting versions through 0.9.5. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Winning Portfolio Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Winning Portfolio plugin, affecting versions through 1.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WP Code Snippets WCS QR Code Generator Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Code Snippets WCS QR Code Generator plugin, affecting versions through 1.0. This vulnerability allows for the injection of malicious scripts that are executed when users visit the affected site.
WordPress Rollover Tab Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Rollover Tab plugin, affecting versions through 1.3.2. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Contact Form 7 Anti Spambot Missing Authorization Vulnerability
A broken access control vulnerability has been identified in the WordPress Contact Form 7 Anti Spambot plugin, affecting versions through 1.0.1. This vulnerability arises from missing authorization checks, which can be exploited by users to perform actions that require higher privileges.
Katz Web Services Debt Calculator WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Katz Web Services Debt Calculator WordPress plugin, specifically in versions through 1.0.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Eyouth Charity-Thermometer Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Eyouth Charity-Thermometer WordPress plugin, affecting versions through 1.1.2. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Daily Proverb Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Daily Proverb plugin, affecting versions through 2.0.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Alessandro Staniscia Simple Vertical Timeline DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Simple Vertical Timeline plugin, affecting versions through 0.1. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
YesStreaming.com Shoutcast and Icecast Web Radio Player Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com, affecting versions through 3.3. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.
