CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-9662

    Last Modified: 12 Jun 2025

    The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9645

    Last Modified: 4 Jun 2025

    The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9599

    Last Modified: 4 Jun 2025

    The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    6.5
    Medium

    CVE-2024-9450

    Last Modified: 23 Jan 2026

    The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-9390

    Last Modified: 4 Jun 2025

    The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-9238

    Last Modified: 12 Jun 2025

    The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-9236

    Last Modified: 12 Jun 2025

    The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-9233

    Last Modified: 4 Jun 2025

    The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-9227

    Last Modified: 5 Jun 2025

    The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-9182

    Last Modified: 12 Jun 2025

    The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-8854

    Last Modified: 4 Jun 2025

    The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-8851

    Last Modified: 4 Jun 2025

    The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8759

    Last Modified: 12 Jun 2025

    The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    6.1
    Medium

    CVE-2024-8703

    Last Modified: 28 May 2025

    The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks when accessing share URLs.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8702

    Last Modified: 12 Jun 2025

    The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8701

    Last Modified: 12 Jun 2025

    The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    7.5
    High

    CVE-2024-8700

    Last Modified: 27 Aug 2025

    The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.

    Published: 15 May 2025
    7.2
    High

    CVE-2024-8699

    Last Modified: 28 May 2025

    The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

    Published: 15 May 2025
    9.1
    Critical

    CVE-2024-8673

    Last Modified: 28 May 2025

    The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8670

    Last Modified: 4 Jun 2025

    The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8620

    Last Modified: 4 Jun 2025

    The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8619

    Last Modified: 4 Jun 2025

    The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8618

    Last Modified: 27 May 2025

    The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8617

    Last Modified: 4 Jun 2025

    The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8542

    Last Modified: 4 Jun 2025

    The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8493

    Last Modified: 4 Jun 2025

    The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8492

    Last Modified: 12 Jun 2025

    The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8426

    Last Modified: 27 May 2025

    The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-8398

    Last Modified: 12 Jun 2025

    The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-8397

    Last Modified: 12 Jun 2025

    The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.

    Published: 15 May 2025
    6.5
    Medium

    CVE-2024-8286

    Last Modified: 12 Jun 2025

    The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8284

    Last Modified: 12 Jun 2025

    The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-8245

    Last Modified: 12 Jun 2025

    The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-8187

    Last Modified: 27 May 2025

    The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    6.1
    Medium

    CVE-2024-8095

    Last Modified: 27 May 2025

    The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 15 May 2025
    6.5
    Medium

    CVE-2024-8094

    Last Modified: 27 May 2025

    The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    6.1
    Medium

    CVE-2024-8090

    Last Modified: 27 May 2025

    The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 15 May 2025
    6.1
    Medium

    CVE-2024-8085

    Last Modified: 12 Jun 2025

    The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-8082

    Last Modified: 12 Jun 2025

    The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-8050

    Last Modified: 12 Jun 2025

    The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    6.1
    Medium

    CVE-2024-8032

    Last Modified: 12 Jun 2025

    The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 15 May 2025
    6.5
    Medium

    CVE-2024-8031

    Last Modified: 12 Jun 2025

    The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php.

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-7984

    Last Modified: 11 Jun 2025

    The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-7769

    Last Modified: 11 Jun 2025

    The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    3.7
    Low

    CVE-2024-7762

    Last Modified: 2 Oct 2025

    The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes

    Published: 15 May 2025
    6.1
    Medium

    CVE-2024-7761

    Last Modified: 11 Jun 2025

    In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-7759

    Last Modified: 11 Jun 2025

    The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-7758

    Last Modified: 4 Jun 2025

    The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-7556

    Last Modified: 11 Jun 2025

    The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    9.8
    Critical

    CVE-2024-6809

    Last Modified: 5 Jun 2025

    The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

    Published: 15 May 2025