CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 2, 2025

WPKoi Templates for Elementor Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WPKoi Templates for Elementor plugin, affecting versions through 3.1.3. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.7
Jan 2, 2025

Pronamic Google Maps Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Pronamic Google Maps WordPress plugin, affecting versions through 2.3.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.7
Jan 2, 2025

Themify Audio Dock Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Themify Audio Dock WordPress plugin, affecting versions through 2.0.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.7
Jan 2, 2025

QunatumCloud Floating Action Buttons Missing Authorization Vulnerability Allowing Broken Access Control

A broken access control vulnerability has been identified in the QunatumCloud Floating Action Buttons plugin for WordPress, affecting versions through 0.9.1. This vulnerability allows users to access functionalities that are not properly restricted by access control lists (ACLs), potentially leading to unauthorized actions.

2.5
Jan 2, 2025

WordPress Contest Gallery Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Contest Gallery plugin, affecting versions through 24.0.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

3.0
Jan 2, 2025

Hestia Nginx Cache Missing Authorization Vulnerability Allowing Broken Access Control

A broken access control vulnerability has been identified in the Hestia Nginx Cache WordPress plugin, affecting versions through 2.4.0. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.

2.6
Jan 2, 2025

WordPress Simple Proxy Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Simple Proxy plugin, affecting versions through 1.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 2, 2025

AdWork Media EZ Content Locker Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the AdWork Media EZ Content Locker WordPress plugin, affecting versions through 3.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 2, 2025

DuoGeek Custom Dashboard Widget Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the DuoGeek Custom Dashboard Widget for WordPress, affecting versions through 1.0.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 2, 2025

Perfect Solution WP eCommerce Quickpay Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Perfect Solution WP eCommerce Quickpay plugin, affecting versions through 1.1.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 2, 2025

WordPress Preloader by WordPress Monsters Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress Preloader plugin by WordPress Monsters, affecting versions through 1.2.3. This issue allows attackers to inject malicious scripts that could be executed when users visit the affected site.

2.0
Jan 2, 2025

Boston University WordPress Plugin BU Section Editing Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress BU Section Editing plugin, affecting versions through 0.9.9. This issue allows for improper neutralization of input during web page generation, which could be exploited to inject malicious scripts that are executed when users visit the affected page.

2.0
Jan 2, 2025

Till Krüss Email Address Encoder Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Till Krüss Email Address Encoder WordPress plugin, affecting versions through 1.0.23. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

4.1
Jan 2, 2025

Smartsupp Live Chat Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Smartsupp live chat, chatbots, AI, and lead generation WordPress plugin, affecting versions through 3.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

Marco Milesi Telegram Bot & Channel Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Marco Milesi Telegram Bot & Channel plugin for WordPress, affecting versions through 3.8.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Matomo Analytics WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Matomo Analytics WordPress plugin, affecting versions through 5.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

WordPress Oceanic Theme Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Oceanic theme, specifically in versions through 1.0.48. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

WordPress Popularis Verse Theme Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Popularis Verse theme, affecting versions through 1.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

The Events Calendar Event Tickets Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in The Events Calendar Event Tickets plugin, affecting versions through 5.11.0.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Tagbox WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Tagbox WordPress plugin, specifically in versions through 3.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

4.1
Jan 2, 2025

WordPress Animated Rotating Words Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Animated Rotating Words plugin, affecting versions through 5.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

WordPress Google Adsense & Banner Ads by AdsforWP Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Google Adsense & Banner Ads by AdsforWP plugin, affecting versions through 1.9.28. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

MBE Worldwide MBE eShip WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the MBE eShip WordPress plugin, specifically in versions through 2.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

Metorik Reports and Email Automation for WooCommerce Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Metorik Reports and Email Automation for WooCommerce plugin, affecting versions through 1.7.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Rara Business Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Business theme for WordPress, specifically in versions through 1.2.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

WordPress Ultimate Auction Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Ultimate Auction plugin, affecting versions through 4.2.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Leaky Paywall Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Leaky Paywall WordPress plugin, affecting versions through 4.21.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 2, 2025

The Events Calendar Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in The Events Calendar WordPress plugin, affecting versions through 6.5.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

4.6
Jan 2, 2025

SWTE Swift Performance Lite Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the SWTE Swift Performance Lite plugin for WordPress, affecting versions through 2.3.6.20. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Construction Landing Page Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Construction Landing Page, specifically in versions through 1.3.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Lawyer Landing Page Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Lawyer Landing Page, specifically in versions through 1.2.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

SKT Themes Posterity Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the SKT Themes Posterity WordPress theme, affecting versions through 3.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 2, 2025

Apollo13Themes Rife Free Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Apollo13Themes Rife Free WordPress theme, affecting versions through 2.4.18. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

3.4
Jan 2, 2025

WP Royal Bard Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Royal Bard theme, specifically in versions through 2.210. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

WP Royal Ashe Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Royal Ashe theme, specifically in versions through 2.233. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

BlazeThemes Trendy News Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the BlazeThemes Trendy News WordPress theme, affecting versions through 1.0.15. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

CreativeThemes Blocksy Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the CreativeThemes Blocksy WordPress theme, affecting versions through 2.0.22. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

4.1
Jan 2, 2025

ThemeIsle Hestia Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeIsle Hestia WordPress theme, specifically in versions through 3.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

ExtendThemes Highlight Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ExtendThemes Highlight WordPress theme, specifically in versions through 1.0.29. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Travel Agency Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Travel Agency, specifically in versions through 1.4.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Benevolent Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Benevolent, specifically in versions through 1.3.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

FameThemes OnePress Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the FameThemes OnePress WordPress theme, affecting versions through 2.3.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

DesertThemes NewsMash Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the DesertThemes NewsMash WordPress theme, specifically in versions through 1.0.34. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Perfect Portfolio Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Perfect Portfolio, affecting versions through 1.2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

WordPress Mesmerize Theme Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Mesmerize theme, specifically in versions through 1.6.120. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

4.1
Jan 2, 2025

Rara Theme Elegant Pink Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Elegant Pink, affecting versions through 1.3.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

Rara Theme JobScout Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme JobScout, specifically in versions through 1.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Coachify WordPress Theme Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Coachify WordPress theme, specifically in versions through 1.0.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Preschool and Kindergarten Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme for WordPress, specifically in versions through 1.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Blossom Themes Blossom Shop Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Blossom Shop WordPress theme, affecting versions through 1.1.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0