CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
WPKoi Templates for Elementor Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WPKoi Templates for Elementor plugin, affecting versions through 3.1.3. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Pronamic Google Maps Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Pronamic Google Maps WordPress plugin, affecting versions through 2.3.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Themify Audio Dock Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Themify Audio Dock WordPress plugin, affecting versions through 2.0.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
QunatumCloud Floating Action Buttons Missing Authorization Vulnerability Allowing Broken Access Control
A broken access control vulnerability has been identified in the QunatumCloud Floating Action Buttons plugin for WordPress, affecting versions through 0.9.1. This vulnerability allows users to access functionalities that are not properly restricted by access control lists (ACLs), potentially leading to unauthorized actions.
WordPress Contest Gallery Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Contest Gallery plugin, affecting versions through 24.0.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Hestia Nginx Cache Missing Authorization Vulnerability Allowing Broken Access Control
A broken access control vulnerability has been identified in the Hestia Nginx Cache WordPress plugin, affecting versions through 2.4.0. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
WordPress Simple Proxy Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Simple Proxy plugin, affecting versions through 1.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
AdWork Media EZ Content Locker Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the AdWork Media EZ Content Locker WordPress plugin, affecting versions through 3.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
DuoGeek Custom Dashboard Widget Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the DuoGeek Custom Dashboard Widget for WordPress, affecting versions through 1.0.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Perfect Solution WP eCommerce Quickpay Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Perfect Solution WP eCommerce Quickpay plugin, affecting versions through 1.1.0. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Preloader by WordPress Monsters Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress Preloader plugin by WordPress Monsters, affecting versions through 1.2.3. This issue allows attackers to inject malicious scripts that could be executed when users visit the affected site.
Boston University WordPress Plugin BU Section Editing Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WordPress BU Section Editing plugin, affecting versions through 0.9.9. This issue allows for improper neutralization of input during web page generation, which could be exploited to inject malicious scripts that are executed when users visit the affected page.
Till Krüss Email Address Encoder Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Till Krüss Email Address Encoder WordPress plugin, affecting versions through 1.0.23. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Smartsupp Live Chat Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Smartsupp live chat, chatbots, AI, and lead generation WordPress plugin, affecting versions through 3.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Marco Milesi Telegram Bot & Channel Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Marco Milesi Telegram Bot & Channel plugin for WordPress, affecting versions through 3.8.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Matomo Analytics WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Matomo Analytics WordPress plugin, affecting versions through 5.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Oceanic Theme Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Oceanic theme, specifically in versions through 1.0.48. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Popularis Verse Theme Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Popularis Verse theme, affecting versions through 1.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
The Events Calendar Event Tickets Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in The Events Calendar Event Tickets plugin, affecting versions through 5.11.0.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Tagbox WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Tagbox WordPress plugin, specifically in versions through 3.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Animated Rotating Words Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Animated Rotating Words plugin, affecting versions through 5.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Google Adsense & Banner Ads by AdsforWP Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Google Adsense & Banner Ads by AdsforWP plugin, affecting versions through 1.9.28. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
MBE Worldwide MBE eShip WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the MBE eShip WordPress plugin, specifically in versions through 2.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Metorik Reports and Email Automation for WooCommerce Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Metorik Reports and Email Automation for WooCommerce plugin, affecting versions through 1.7.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Rara Business Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Business theme for WordPress, specifically in versions through 1.2.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Ultimate Auction Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Ultimate Auction plugin, affecting versions through 4.2.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Leaky Paywall Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Leaky Paywall WordPress plugin, affecting versions through 4.21.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
The Events Calendar Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in The Events Calendar WordPress plugin, affecting versions through 6.5.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
SWTE Swift Performance Lite Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the SWTE Swift Performance Lite plugin for WordPress, affecting versions through 2.3.6.20. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Construction Landing Page Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Construction Landing Page, specifically in versions through 1.3.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Lawyer Landing Page Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Lawyer Landing Page, specifically in versions through 1.2.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
SKT Themes Posterity Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the SKT Themes Posterity WordPress theme, affecting versions through 3.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Apollo13Themes Rife Free Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Apollo13Themes Rife Free WordPress theme, affecting versions through 2.4.18. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WP Royal Bard Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Royal Bard theme, specifically in versions through 2.210. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WP Royal Ashe Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Royal Ashe theme, specifically in versions through 2.233. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
BlazeThemes Trendy News Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the BlazeThemes Trendy News WordPress theme, affecting versions through 1.0.15. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
CreativeThemes Blocksy Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the CreativeThemes Blocksy WordPress theme, affecting versions through 2.0.22. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
ThemeIsle Hestia Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeIsle Hestia WordPress theme, specifically in versions through 3.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
ExtendThemes Highlight Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the ExtendThemes Highlight WordPress theme, specifically in versions through 1.0.29. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Travel Agency Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Travel Agency, specifically in versions through 1.4.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Benevolent Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Benevolent, specifically in versions through 1.3.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
FameThemes OnePress Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the FameThemes OnePress WordPress theme, affecting versions through 2.3.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
DesertThemes NewsMash Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the DesertThemes NewsMash WordPress theme, specifically in versions through 1.0.34. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Perfect Portfolio Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Perfect Portfolio, affecting versions through 1.2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Mesmerize Theme Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Mesmerize theme, specifically in versions through 1.6.120. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Elegant Pink Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Elegant Pink, affecting versions through 1.3.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme JobScout Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme JobScout, specifically in versions through 1.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Coachify WordPress Theme Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Coachify WordPress theme, specifically in versions through 1.0.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Preschool and Kindergarten Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme for WordPress, specifically in versions through 1.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Blossom Themes Blossom Shop Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Blossom Shop WordPress theme, affecting versions through 1.1.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
