CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
CHR Designer Responsive jQuery Slider Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the CHR Designer Responsive jQuery Slider plugin for WordPress, affecting versions through 1.1.1. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Gallery and Lightbox Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Gallery and Lightbox plugin, affecting versions through 1.0.14. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Thorsten Krug Multilang Contact Form Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Thorsten Krug Multilang Contact Form plugin, affecting versions through 1.5. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
Bold Bold Pagos En Linea DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the Bold Pagos En Linea WordPress plugin, affecting versions through 3.1.4. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
Codexpert CoDesigner WooCommerce Builder for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Codexpert CoDesigner WooCommerce Builder for Elementor, affecting versions through 4.7.17.2. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
bPlugins LLC Button Block Missing Authorization Vulnerability Allowing Broken Access Control
A broken access control vulnerability has been identified in the bPlugins LLC Button Block WordPress plugin, affecting versions through 1.1.5. This vulnerability allows users to access functionalities that are not properly restricted by access control lists (ACLs), potentially leading to unauthorized actions.
ElementInvader Addons for Elementor Local File Inclusion Vulnerability
A path traversal vulnerability allowing PHP local file inclusion has been identified in the ElementInvader Addons for Elementor plugin, affecting versions through 1.2.6. This vulnerability could enable a malicious actor to include local files from the target website and display their contents, potentially leading to a complete database takeover if sensitive files containing database credentials are accessed.
ComMotion Course Booking System SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the ComMotion Course Booking System, affecting versions through 6.0.5. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling malicious actors to manipulate database queries and potentially access or modify database information.
WordPress Background Control Plugin Cross-Site Request Forgery Vulnerability Allowing Path Traversal
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Background Control plugin, specifically in versions through 1.0.5. This vulnerability allows for path traversal, potentially leading to arbitrary file deletion.
Web Ready Now WR Price List Manager For WooCommerce Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Web Ready Now WR Price List Manager for WooCommerce, affecting versions through 1.0.8. This vulnerability allows unrestricted upload of files with dangerous types, such as web shells, which can be executed on the web server.
Nativery Developer Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the Nativery Developer WordPress plugin, affecting versions through 0.1.6. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the affected site.
WordPress wp-pano Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress wp-pano plugin, affecting versions through 1.17. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that are executed when users visit the affected site.
WordPress WP News Sliders Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WordPress WP News Sliders plugin, affecting versions through 1.0. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileged users.
Lijit Networks and Crowd Favorite Lijit Search Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Lijit Search WordPress plugin, specifically in versions through 1.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress WP Bulletin Board Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress WP Bulletin Board plugin, affecting versions through 1.1.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.
WPChill Htaccess File Editor Broken Authentication Vulnerability
A broken authentication vulnerability has been identified in the WPChill Htaccess File Editor plugin, affecting versions through 1.0.19. This vulnerability allows attackers to exploit improperly configured access control, potentially performing actions reserved for higher-privileged users.
Creative Brahma Multifox Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Creative Brahma Multifox WordPress theme, affecting versions through 1.3.7. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Zarinpal Paid Download Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Zarinpal Paid Download WordPress plugin, affecting versions through 2.3. This issue allows attackers to inject malicious scripts that could be executed when users visit the affected site.
WP Order By Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WP Order By WordPress plugin, affecting versions through 1.4.2. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress WP Post Corrector Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress WP Post Corrector plugin, specifically in versions through 1.0.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.
Octrace Studio WordPress HelpDesk & Support Ticket System Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress HelpDesk & Support Ticket System Plugin – Octrace Support, affecting versions through 1.2.7. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Ajax Contact Form Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Ajax Contact Form plugin, specifically in versions through 1.2.5.1. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
CodeBard WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the CodeBard Help Desk WordPress plugin, affecting versions through 1.1.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
BoldGrid Post and Page Builder Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the BoldGrid Post and Page Builder plugin, specifically in versions through 1.27.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Elementor AI Addons DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Elementor AI Addons plugin, affecting versions through 2.2.1. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute scripts on the affected site.
WordPress WP Headmaster Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress WP Headmaster plugin, specifically in versions through 0.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Amber Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Amber plugin, specifically in versions through 1.4.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.
WordPress turboSMTP Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress turboSMTP plugin, affecting versions through 4.6. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
GSheetConnector for Forminator Forms Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the GSheetConnector for Forminator Forms WordPress plugin, affecting versions through 1.0.11. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
Mighty Digital Partners WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Mighty Digital Partners WordPress plugin, affecting versions through 0.2.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Post Carousel & Slider Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Post Carousel & Slider plugin, affecting versions through 1.0.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
AwoThemes Social Media Engine Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the AwoThemes Social Media Engine plugin for WordPress, affecting versions through 1.0.2. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
SetMore Appointments WordPress Theme Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the SetMore Appointments WordPress theme, specifically in the Custom Post Types version range prior to and including 1.1. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Tor Foundation Columns Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Tor Foundation Columns WordPress plugin, affecting versions through 0.8. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
HireHive Job Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the HireHive Job Plugin for WordPress, affecting versions through 2.9.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Navigation Du Lapin Blanc Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Navigation Du Lapin Blanc plugin, affecting versions through 1.1.1. This vulnerability arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the website.
Rob von Bothmer S-DEV SEO Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the S-DEV SEO WordPress plugin, affecting versions through 1.88. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Twitter Bootstrap Collapse Shortcode DOM-Based Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the WordPress Twitter Bootstrap Collapse (Accordion) Shortcode plugin, specifically in versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing for DOM-based XSS attacks. Malicious scripts could be injected and executed in the context of the user's browser.
WordPress WP ViewSTL Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress WP ViewSTL plugin, affecting versions through 1.0. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
TechnoWich WP ULike Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the TechnoWich WP ULike WordPress plugin, affecting versions through 4.7.6. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
MagePeople WpTravelly Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the MagePeople WpTravelly plugin, affecting versions through 1.8.5. This vulnerability allows users to access functionalities that are not properly restricted by access control lists (ACLs), potentially leading to unauthorized actions.
WPExperts User Management Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the WPExperts User Management plugin for WordPress, affecting versions through 1.2. This vulnerability allows users with low privileges to escalate their rights, potentially leading to full control of the website.
WordPress Posts Footer Manager Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Posts Footer Manager plugin, affecting versions through 2.1.0. This issue allows for improper neutralization of input, enabling the injection of malicious scripts that could be executed when users visit the site.
WordPress Build Private Store For WooCommerce Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Build Private Store For WooCommerce plugin, specifically in versions through 1.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Infomaniak VOD Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Infomaniak VOD WordPress plugin, specifically in versions through 1.5.9. This vulnerability allows unprivileged users to exploit improperly configured access control, potentially leading to unauthorized actions that require higher privileges.
MojofyWP Product Carousel For WooCommerce – WoorouSell Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the MojofyWP Product Carousel For WooCommerce – WoorouSell plugin, affecting versions through 1.1.0. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when guests visit the site.
WordPress SEO Bulk Editor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress SEO Bulk Editor plugin, affecting versions through 1.1.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Faizaan Gagan Course Migration for LearnDash Server-Side Request Forgery Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in the Faizaan Gagan Course Migration for LearnDash plugin, specifically in version 1.0.2. This vulnerability allows attackers to make the server perform requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.
AGILELOGIX Free Google Maps Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the AGILELOGIX Free Google Maps WordPress plugin, affecting versions through 1.0.1. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
Gallery Ape Photo Gallery Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Gallery Ape Photo Gallery WordPress plugin, affecting versions through 2.2.8. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
