CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 16, 2025

Incredible Font Awesome Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress plugin Incredible Font Awesome, affecting versions through 1.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.6
Jan 16, 2025

TC Ajax WP Query Search Filter Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the TC Ajax WP Query Search Filter plugin for WordPress, affecting versions through 1.0.7. This vulnerability arises from improper input sanitization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the affected site.

1.7
Jan 16, 2025

WordPress Feedburner Optin Form Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Feedburner Optin Form plugin, affecting versions through 0.2.8. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.7
Jan 16, 2025

WP Photo Sphere Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WP Photo Sphere WordPress plugin, affecting versions through 3.8. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.7
Jan 16, 2025

WordPress iSpring Embedder Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress iSpring Embedder plugin, specifically in versions through 1.0. This vulnerability allows attackers to upload a web shell to a web server by exploiting the CSRF flaw.

2.2
Jan 16, 2025

WordPress Slides and Presentations Plugin Code Injection Vulnerability

A cross-site scripting (XSS) vulnerability allowing code injection has been identified in the WordPress Slides & Presentations plugin, versions through 0.0.39. This vulnerability arises from improper neutralization of script-related HTML tags, which could enable a malicious actor to inject content into pages and posts, potentially including phishing materials.

1.6
Jan 16, 2025

Chamber Dashboard Business Directory Missing Authorization Vulnerability Allowing Broken Access Control

A broken access control vulnerability has been identified in the Chamber Dashboard Business Directory WordPress plugin, affecting versions through 3.3.10. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileged users.

2.2
Jan 16, 2025

Nuanced Media WP Meetup Missing Authorization Vulnerability Allowing Access Control Misconfiguration

A missing authorization vulnerability exists in the Nuanced Media WP Meetup plugin, affecting versions through 2.3.0. This vulnerability allows for exploitation of improperly configured access control security levels, potentially leading to unauthorized changes in settings.

1.7
Jan 16, 2025

Roninwp FAT Event Lite Local File Inclusion Vulnerability

A local file inclusion vulnerability has been identified in the Roninwp FAT Event Lite WordPress plugin, affecting versions through 1.1. This vulnerability arises from improper control of filenames in include or require statements, allowing for PHP remote file inclusion. Exploitation of this issue could enable a malicious actor to include local files from the target website and display their contents, potentially leading to a database takeover if sensitive information such as database credentials is accessed.

1.7
Jan 16, 2025

WordPress Google Map Professional SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the WordPress Google Map Professional plugin, affecting versions through 1.0. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact directly with the database.

1.8
Jan 16, 2025

Typomedia Foundation WordPress Custom Sidebar SQL Injection Vulnerability

A blind SQL injection vulnerability has been identified in the Typomedia Foundation WordPress Custom Sidebar plugin, affecting versions through 2.3. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing for unauthorized database manipulation.

1.7
Jan 16, 2025

Solidres WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Solidres – Hotel Booking plugin for WordPress, affecting versions through 0.9.4. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact directly with the database.

3.1
Jan 16, 2025

Common Ninja Compare Ninja Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Common Ninja Compare Ninja plugin for WordPress, affecting versions through 2.1.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.6
Jan 16, 2025

WordPress Pastebin Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Pastebin Plugin, affecting versions through 1.5. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.6
Jan 16, 2025

WordPress Social Ninja Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Social Ninja plugin, specifically in versions through 0.2. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.

1.6
Jan 16, 2025

WordPress Error Notification Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Error Notification plugin, specifically in versions through 0.2.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 16, 2025

Oliver Schaal GravatarLocalCache WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Oliver Schaal GravatarLocalCache WordPress plugin, affecting versions through 1.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 16, 2025

Genkisan Genki Announcement Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Genkisan Genki Announcement WordPress plugin, affecting versions through 1.4.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 16, 2025

BnB Select Bookalet Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the BnB Select Ltd Bookalet WordPress plugin, affecting versions through 1.0.3. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7
Jan 16, 2025

WordPress Apply with LinkedIn Buttons Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Apply with LinkedIn Buttons plugin, specifically in versions through 2.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts.

2.0
Jan 16, 2025

Ivo Brett ApplyMetrics WordPress Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress Apply with LinkedIn buttons plugin, affecting versions through 2.3. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 16, 2025

WordPress Mindmeister Shortcode Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress Mindmeister Shortcode plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.7
Jan 16, 2025

WordPress Add RSS Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Add RSS plugin, specifically in versions through 1.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

WordPress GMap Shortcode Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress GMap Shortcode plugin, affecting versions through 2.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.7
Jan 16, 2025

WordPress Progress Tracker Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress Progress Tracker plugin, affecting versions through 0.9.3. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts or HTML payloads on the affected site.

1.6
Jan 16, 2025

WordPress Yet Another Countdown Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress Yet Another Countdown plugin, affecting versions through 1.0.1. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 16, 2025

WordPress Easy Tweet Embed Plugin DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress Easy Tweet Embed plugin, affecting versions through 1.7. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 16, 2025

WordPress Blog Summary Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Blog Summary plugin, specifically in versions through 0.1.2 β. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.7
Jan 16, 2025

WordPress Annie Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Annie plugin, affecting versions through 2.1.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.6
Jan 16, 2025

WordPress Annie Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Annie plugin, affecting versions through 2.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 16, 2025

WordPress amr personalise Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress amr personalise plugin, affecting versions through 2.10. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 16, 2025

WordPress Post-to-Post Links Plugin Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Post-to-Post Links plugin, affecting versions through 4.2. This issue arises from improper input sanitization during web page generation, allowing malicious users to inject scripts that are executed when other users visit the affected page.

1.5
Jan 16, 2025

Nite Themes Nite Shortcodes Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Nite Shortcodes WordPress plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the site.

1.7
Jan 16, 2025

Jens Remus WP krpano Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress WP krpano plugin, affecting versions through 1.2.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.6
Jan 16, 2025

WordPress Better Protected Pages Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Better Protected Pages plugin, affecting versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.

2.0
Jan 16, 2025

Anshi Solutions Category D3 Tree Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Anshi Solutions Category D3 Tree plugin for WordPress, affecting versions through 1.1. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.6
Jan 16, 2025

PayForm WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the PayForm WordPress plugin, affecting versions through 2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.

2.0
Jan 16, 2025

LSD Google Maps Embedder CSRF Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the LSD Google Maps Embedder WordPress plugin, affecting versions through 1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 16, 2025

WordPress Copyright Safeguard Footer Notice Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Copyright Safeguard Footer Notice plugin, affecting versions through 3.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.

2.0
Jan 16, 2025

WordPress CJ Custom Content Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress CJ Custom Content plugin, specifically in versions through 2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts that are stored and executed later.

2.0
Jan 16, 2025

WordPress Chess Tempo Viewer Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Chess Tempo Viewer plugin, affecting versions through 0.9.5. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.6
Jan 16, 2025

WordPress Winning Portfolio Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Winning Portfolio plugin, affecting versions through 1.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.7
Jan 16, 2025

WP Code Snippets WCS QR Code Generator Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WP Code Snippets WCS QR Code Generator plugin, affecting versions through 1.0. This vulnerability allows for the injection of malicious scripts that are executed when users visit the affected site.

1.6
Jan 16, 2025

WordPress Rollover Tab Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Rollover Tab plugin, affecting versions through 1.3.2. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7
Jan 16, 2025

WordPress Contact Form 7 Anti Spambot Missing Authorization Vulnerability

A broken access control vulnerability has been identified in the WordPress Contact Form 7 Anti Spambot plugin, affecting versions through 1.0.1. This vulnerability arises from missing authorization checks, which can be exploited by users to perform actions that require higher privileges.

2.6
Jan 16, 2025

Katz Web Services Debt Calculator WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Katz Web Services Debt Calculator WordPress plugin, specifically in versions through 1.0.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 16, 2025

Eyouth Charity-Thermometer Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Eyouth Charity-Thermometer WordPress plugin, affecting versions through 1.1.2. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.7
Jan 16, 2025

WordPress Daily Proverb Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Daily Proverb plugin, affecting versions through 2.0.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.7
Jan 16, 2025

Alessandro Staniscia Simple Vertical Timeline DOM-Based Cross-Site Scripting Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in the WordPress Simple Vertical Timeline plugin, affecting versions through 0.1. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.

1.6
Jan 16, 2025

YesStreaming.com Shoutcast and Icecast Web Radio Player Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com, affecting versions through 3.3. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.

1.6