CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2025-22564

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faaiq Pretty Url pretty-url allows Reflected XSS.This issue affects Pretty Url: from n/a through <= 1.5.4.

    Published: 31 Jan 2025
    7.1
    High

    CVE-2025-22341

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in parswp Hide Login+ hide-login allows Reflected XSS.This issue affects Hide Login+: from n/a through <= 3.5.1.

    Published: 31 Jan 2025
    7.1
    High

    CVE-2025-22332

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanaver CloudFlare(R) Cache Purge cloudflare-cache-purge allows Reflected XSS.This issue affects CloudFlare(R) Cache Purge: from n/a through <= 1.2.

    Published: 31 Jan 2025
    6.5
    Medium

    CVE-2025-22265

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in mgplugin EMI Calculator emi-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EMI Calculator: from n/a through <= 1.1.

    Published: 31 Jan 2025
    5.4
    Medium

    CVE-2024-44055

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in brandexponents Oshine Modules oshine-modules.This issue affects Oshine Modules: from n/a through < 3.3.8.

    Published: 31 Jan 2025
    6.4
    Medium

    CVE-2024-13566

    Last Modified: 15 Apr 2026

    The WP DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 0.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jan 2025
    6.4
    Medium

    CVE-2024-13157

    Last Modified: 15 Apr 2026

    The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast RSS Feed in all versions up to, and including, 5.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jan 2025
    4.3
    Medium

    CVE-2024-13530

    Last Modified: 15 Apr 2026

    The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in , Sign out plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the lps_handle_delete_all_logs(), lps_handle_delete_login_log(), and lps_handle_end_session() functions in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete login logs and end user sessions.

    Published: 31 Jan 2025
    5.9
    Medium

    CVE-2024-13623

    Last Modified: 15 Apr 2026

    The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.24 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can contain exported order information. The plugin is only vulnerable when 'Order data storage' is set to 'WordPress posts storage (legacy)', and cannot be exploited when the default option of 'High-performance order storage' is enabled.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-13219

    Last Modified: 9 Jan 2026

    The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    5.4
    Medium

    CVE-2025-22216

    Last Modified: 15 Apr 2026

    A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.

    Published: 31 Jan 2025
    4.3
    Medium

    CVE-2024-13424

    Last Modified: 15 Apr 2026

    The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'niwoosc_ajax' AJAX endpoint in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins settings and modify commission amounts.

    Published: 31 Jan 2025
    4.3
    Medium

    CVE-2024-13415

    Last Modified: 15 Apr 2026

    The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's settings.

    Published: 31 Jan 2025
    7.2
    High

    CVE-2024-13504

    Last Modified: 15 Apr 2026

    The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the dfxp file. This issue affects only Apache-based environments, where dfxp files are handled by default.

    Published: 31 Jan 2025
    4.3
    Medium

    CVE-2024-13717

    Last Modified: 15 Apr 2026

    The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to enabled and disable widgets.

    Published: 31 Jan 2025
    6.4
    Medium

    CVE-2024-11886

    Last Modified: 15 Apr 2026

    The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler ' shortcode in all versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jan 2025
    7.2
    High

    CVE-2025-0809

    Last Modified: 22 Apr 2026

    The Link Fixer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via broken links in all versions up to, and including, 3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jan 2025
    4.3
    Medium

    CVE-2024-13216

    Last Modified: 15 Apr 2026

    The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.

    Published: 31 Jan 2025
    5.4
    Medium

    CVE-2024-10867

    Last Modified: 8 Apr 2026

    The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 31 Jan 2025
    9.8
    Critical

    CVE-2025-0493

    Last Modified: 22 Apr 2026

    The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the tabname parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included

    Published: 31 Jan 2025
    6.4
    Medium

    CVE-2025-0507

    Last Modified: 15 Apr 2026

    The Ticketmeo – Sell Tickets – Event Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2025-0470

    Last Modified: 21 Apr 2026

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the title parameter in all versions up to, and including, 1.38.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 31 Jan 2025
    6.4
    Medium

    CVE-2024-13463

    Last Modified: 15 Apr 2026

    The SeatReg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'seatreg' shortcode in all versions up to, and including, 1.56.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jan 2025
    7.8
    High

    CVE-2024-47900

    Last Modified: 15 Apr 2026

    Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.

    Published: 31 Jan 2025
    7.8
    High

    CVE-2024-47899

    Last Modified: 15 Apr 2026

    Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

    Published: 31 Jan 2025
    7.8
    High

    CVE-2024-47898

    Last Modified: 15 Apr 2026

    Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

    Published: 31 Jan 2025
    7.8
    High

    CVE-2024-47891

    Last Modified: 15 Apr 2026

    Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

    Published: 31 Jan 2025
    7.8
    High

    CVE-2024-46974

    Last Modified: 15 Apr 2026

    Software installed and run as a non-privileged user may conduct improper read/write operations on imported/exported DMA buffers.

    Published: 31 Jan 2025
    —
    Unknown

    CVE-2025-0925

    Last Modified: 12 Feb 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-0818. Reason: This candidate is a reservation duplicate of CVE-2025-0818. Notes: All CVE users should reference CVE-2025-0818 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 31 Jan 2025
    6.4
    Medium

    CVE-2024-13397

    Last Modified: 15 Apr 2026

    The WPRadio – WordPress Radio Streaming Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpradio_player' shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jan 2025
    6.4
    Medium

    CVE-2024-13396

    Last Modified: 15 Apr 2026

    The Frictionless plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'frictionless_form' shortcode[s] in all versions up to, and including, 0.0.23 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jan 2025
    8.1
    High

    CVE-2024-13767

    Last Modified: 15 Apr 2026

    The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

    Published: 31 Jan 2025
    6.4
    Medium

    CVE-2024-13399

    Last Modified: 15 Apr 2026

    The Gosign – Posts Slider Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'posts-slider-block' block in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-13226

    Last Modified: 13 May 2025

    The A5 Custom Login Page WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-13225

    Last Modified: 13 May 2025

    The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-13224

    Last Modified: 12 May 2025

    The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-13223

    Last Modified: 12 May 2025

    The Tabulate WordPress plugin through 2.10.3 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-13222

    Last Modified: 13 May 2025

    The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-13221

    Last Modified: 12 May 2025

    The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-13220

    Last Modified: 12 May 2025

    The WordPress Google Map Professional (Map In Your Language) WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-13218

    Last Modified: 12 May 2025

    The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-13112

    Last Modified: 11 May 2025

    The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    5.4
    Medium

    CVE-2024-13101

    Last Modified: 11 May 2025

    The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-13100

    Last Modified: 23 May 2025

    The OPSI Israel Domestic Shipments WordPress plugin through 2.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    4.8
    Medium

    CVE-2024-12872

    Last Modified: 23 May 2025

    The Zalomení WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 31 Jan 2025
    5.4
    Medium

    CVE-2024-12772

    Last Modified: 28 Mar 2025

    The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, leading to a Cross Site Scripting vulnerability.

    Published: 31 Jan 2025
    6.1
    Medium

    CVE-2024-12275

    Last Modified: 13 May 2025

    The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 31 Jan 2025
    4.9
    Medium

    CVE-2023-0092

    Last Modified: 26 Aug 2025

    An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.

    Published: 31 Jan 2025
    —
    Unknown

    CVE-2025-0919

    Last Modified: 12 Feb 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-0818. Reason: This candidate is a reservation duplicate of CVE-2025-0818. Notes: All CVE users should reference CVE-2025-0818 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 31 Jan 2025
    3.1
    Low

    CVE-2020-11936

    Last Modified: 26 Aug 2025

    gdbus setgid privilege escalation

    Published: 31 Jan 2025