CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2025-1289

    Last Modified: 1 Aug 2025

    The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    6.1
    Medium

    CVE-2025-1288

    Last Modified: 12 Jun 2025

    The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make an unauthenticated user vulnerable to reflected XSS via a CSRF attack.

    Published: 15 May 2025
    6.1
    Medium

    CVE-2025-1286

    Last Modified: 12 Jun 2025

    The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2025-1033

    Last Modified: 12 Jun 2025

    The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    6.1
    Medium

    CVE-2025-0688

    Last Modified: 28 May 2025

    The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

    Published: 15 May 2025
    6.1
    Medium

    CVE-2025-0687

    Last Modified: 28 May 2025

    The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2025-0329

    Last Modified: 12 Jun 2025

    The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-9882

    Last Modified: 12 Jun 2025

    The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9879

    Last Modified: 12 Jun 2025

    The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9838

    Last Modified: 12 Jun 2025

    The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 15 May 2025
    7.2
    High

    CVE-2024-9831

    Last Modified: 12 Jun 2025

    The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 15 May 2025
    6.5
    Medium

    CVE-2024-9765

    Last Modified: 28 May 2025

    The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9711

    Last Modified: 28 May 2025

    The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9709

    Last Modified: 28 May 2025

    The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9663

    Last Modified: 12 Jun 2025

    The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9662

    Last Modified: 12 Jun 2025

    The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9645

    Last Modified: 4 Jun 2025

    The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9599

    Last Modified: 4 Jun 2025

    The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    6.5
    Medium

    CVE-2024-9450

    Last Modified: 23 Jan 2026

    The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-9390

    Last Modified: 4 Jun 2025

    The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9238

    Last Modified: 12 Jun 2025

    The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-9236

    Last Modified: 12 Jun 2025

    The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-9233

    Last Modified: 4 Jun 2025

    The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-9227

    Last Modified: 5 Jun 2025

    The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-9182

    Last Modified: 12 Jun 2025

    The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-8854

    Last Modified: 4 Jun 2025

    The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-8851

    Last Modified: 4 Jun 2025

    The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8759

    Last Modified: 12 Jun 2025

    The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    6.1
    Medium

    CVE-2024-8703

    Last Modified: 28 May 2025

    The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks when accessing share URLs.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8702

    Last Modified: 12 Jun 2025

    The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8701

    Last Modified: 12 Jun 2025

    The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    7.5
    High

    CVE-2024-8700

    Last Modified: 27 Aug 2025

    The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.

    Published: 15 May 2025
    7.2
    High

    CVE-2024-8699

    Last Modified: 28 May 2025

    The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

    Published: 15 May 2025
    9.1
    Critical

    CVE-2024-8673

    Last Modified: 28 May 2025

    The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8670

    Last Modified: 4 Jun 2025

    The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8620

    Last Modified: 4 Jun 2025

    The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8619

    Last Modified: 4 Jun 2025

    The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8618

    Last Modified: 27 May 2025

    The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8617

    Last Modified: 4 Jun 2025

    The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8542

    Last Modified: 4 Jun 2025

    The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8493

    Last Modified: 4 Jun 2025

    The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8492

    Last Modified: 12 Jun 2025

    The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8426

    Last Modified: 27 May 2025

    The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-8398

    Last Modified: 12 Jun 2025

    The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-8397

    Last Modified: 12 Jun 2025

    The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.

    Published: 15 May 2025
    6.5
    Medium

    CVE-2024-8286

    Last Modified: 12 Jun 2025

    The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8284

    Last Modified: 12 Jun 2025

    The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-8245

    Last Modified: 12 Jun 2025

    The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8187

    Last Modified: 27 May 2025

    The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    6.1
    Medium

    CVE-2024-8095

    Last Modified: 27 May 2025

    The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 15 May 2025