CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-45803

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Nikolay Strikhar WordPress Form Builder Plugin – Gutenberg Forms.This issue affects WordPress Form Builder Plugin – Gutenberg Forms: from n/a through 2.2.8.3.

    Published: 21 Jun 2024
    7.7
    High

    CVE-2024-6240

    Last Modified: 21 Nov 2024

    Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.

    Published: 21 Jun 2024
    8.8
    High

    CVE-2022-43453

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41.

    Published: 21 Jun 2024
    4.3
    Medium

    CVE-2024-35770

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Dave Kiss Vimeography: Vimeo Video Gallery WordPress Plugin.This issue affects Vimeography: Vimeo Video Gallery WordPress Plugin: from n/a through 2.4.1.

    Published: 21 Jun 2024
    4.3
    Medium

    CVE-2024-35771

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Customizr.This issue affects Customizr: from n/a through 4.4.21.

    Published: 21 Jun 2024
    4.3
    Medium

    CVE-2024-35772

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Hueman.This issue affects Hueman: from n/a through 3.7.24.

    Published: 21 Jun 2024
    5.3
    Medium

    CVE-2024-35776

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.

    Published: 21 Jun 2024
    5.3
    Medium

    CVE-2024-5059

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.This issue affects Event Management Tickets Booking: from n/a through 1.4.0.

    Published: 21 Jun 2024
    5.9
    Medium

    CVE-2024-35757

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 5 Star Plugins Easy Age Verify allows Stored XSS.This issue affects Easy Age Verify: from n/a through 1.8.2.

    Published: 21 Jun 2024
    6.5
    Medium

    CVE-2024-35758

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Horse Interface allows Stored XSS.This issue affects Interface: from n/a through 3.1.0.

    Published: 21 Jun 2024
    5.9
    Medium

    CVE-2024-35759

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue affects WP Job Portal: from n/a through <= 2.1.3.

    Published: 21 Jun 2024
    5.9
    Medium

    CVE-2024-35760

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpjobportal WP Job Portal wp-job-portal allows DOM-Based XSS.This issue affects WP Job Portal: from n/a through <= 2.1.3.

    Published: 21 Jun 2024
    6.5
    Medium

    CVE-2024-35761

    Last Modified: 20 Feb 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allows Stored XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.0.

    Published: 21 Jun 2024
    6.5
    Medium

    CVE-2024-35762

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cryout Creations Serious Slider allows Stored XSS.This issue affects Serious Slider: from n/a through 1.2.4.

    Published: 21 Jun 2024
    6.5
    Medium

    CVE-2024-35763

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Freesia Excellent allows Stored XSS.This issue affects Excellent: from n/a through 1.2.9.

    Published: 21 Jun 2024
    6.5
    Medium

    CVE-2024-35764

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.4.

    Published: 21 Jun 2024
    7.1
    High

    CVE-2024-35766

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ollybach WPPizza allows Reflected XSS.This issue affects WPPizza: from n/a through 3.18.13.

    Published: 21 Jun 2024
    5.9
    Medium

    CVE-2024-35768

    Last Modified: 21 Sept 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Composer: from n/a through 2.1.22.

    Published: 21 Jun 2024
    5.9
    Medium

    CVE-2024-35769

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in John West Slideshow SE allows Stored XSS.This issue affects Slideshow SE: from n/a through 2.5.17.

    Published: 21 Jun 2024
    6.5
    Medium

    CVE-2024-35774

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in D’arteweb DImage 360 allows Stored XSS.This issue affects DImage 360: from n/a through 2.0.

    Published: 21 Jun 2024
    6.5
    Medium

    CVE-2024-35779

    Last Modified: 27 Feb 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.

    Published: 21 Jun 2024
    6.5
    Medium

    CVE-2024-5058

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Typing Text allows Stored XSS.This issue affects Typing Text: from n/a through 1.2.5.

    Published: 21 Jun 2024
    6.9
    Medium

    CVE-2024-3036

    Last Modified: 19 Dec 2025

    Improper Input Validation vulnerability in ABB 800xA Base. An attacker who successfully exploited this vulnerability could cause services to crash by sending specifically crafted messages. This issue affects 800xA Base: from 6.0.0 through 6.1.1-2.

    Published: 21 Jun 2024
    9.8
    Critical

    CVE-2024-6027

    Last Modified: 8 Apr 2026

    The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘conditions’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 21 Jun 2024
    7.8
    High

    CVE-2024-31890

    Last Modified: 17 Jul 2025

    IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: 288171.

    Published: 21 Jun 2024
    6.1
    Medium

    CVE-2024-5859

    Last Modified: 8 Apr 2026

    The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘d’ parameter in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 21 Jun 2024
    6.4
    Medium

    CVE-2024-5945

    Last Modified: 8 Apr 2026

    The WP SVG Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all versions up to, and including, 4.3 due to insufficient input sanitization. This makes it possible for authenticated attackers, with Author-level access and above, who have permissions to upload sanitized files, to bypass SVG sanitization and inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A bypass to the patch in version 4.3 was discovered and fixed completely in version 4.4.

    Published: 21 Jun 2024
    4.4
    Medium

    CVE-2024-6225

    Last Modified: 8 Apr 2026

    The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.5 (and 7.5.1 for the Pro version) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 21 Jun 2024
    7.3
    High

    CVE-2024-2003

    Last Modified: 15 Apr 2026

    Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.

    Published: 21 Jun 2024
    6.4
    Medium

    CVE-2024-5191

    Last Modified: 8 Apr 2026

    The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_types’ parameter in all versions up to, and including, 3.4.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 21 Jun 2024
    4.3
    Medium

    CVE-2024-5639

    Last Modified: 8 Apr 2026

    The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to update the profile picture of any user.

    Published: 21 Jun 2024
    5.4
    Medium

    CVE-2024-5448

    Last Modified: 21 Nov 2024

    The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 21 Jun 2024
    4.8
    Medium

    CVE-2024-5447

    Last Modified: 21 Nov 2024

    The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 21 Jun 2024
    4.8
    Medium

    CVE-2024-4970

    Last Modified: 18 Mar 2025

    The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 21 Jun 2024
    4.3
    Medium

    CVE-2024-4969

    Last Modified: 21 Nov 2024

    The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attackers to make logged in admin enable/disable widgets via a CSRF attack

    Published: 21 Jun 2024
    4.8
    Medium

    CVE-2024-4755

    Last Modified: 21 Nov 2024

    The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 21 Jun 2024
    6.1
    Medium

    CVE-2024-4616

    Last Modified: 21 Nov 2024

    The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users

    Published: 21 Jun 2024
    5.4
    Medium

    CVE-2024-4477

    Last Modified: 21 Nov 2024

    The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting

    Published: 21 Jun 2024
    4.3
    Medium

    CVE-2024-4475

    Last Modified: 21 Nov 2024

    The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers to make a logged in admin clear the logs them via a CSRF attack

    Published: 21 Jun 2024
    4.3
    Medium

    CVE-2024-4474

    Last Modified: 21 Nov 2024

    The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 21 Jun 2024
    4.8
    Medium

    CVE-2024-4384

    Last Modified: 21 Nov 2024

    The CSSable Countdown WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 21 Jun 2024
    6.5
    Medium

    CVE-2024-4382

    Last Modified: 26 Mar 2025

    The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks

    Published: 21 Jun 2024
    4.8
    Medium

    CVE-2024-4381

    Last Modified: 13 Mar 2025

    The CB (legacy) WordPress plugin through 0.9.4.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 21 Jun 2024
    5.4
    Medium

    CVE-2024-4377

    Last Modified: 21 Nov 2024

    The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 21 Jun 2024
    9.8
    Critical

    CVE-2024-5756

    Last Modified: 8 Apr 2026

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 21 Jun 2024
    5.3
    Medium

    CVE-2024-3961

    Last Modified: 8 Apr 2026

    The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to subscribe users to tags. Financial damages may occur to site owners if their API quota is exceeded.

    Published: 21 Jun 2024
    8.8
    High

    CVE-2024-5455

    Last Modified: 8 Apr 2026

    The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.5.4 via the 'magazine_style' parameter within the Dynamic Smart Showcase widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 21 Jun 2024
    4.3
    Medium

    CVE-2023-3352

    Last Modified: 15 Apr 2026

    The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability check on the delete_resmush_list() function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to delete the resmush list for Nextgen or the Media Library.

    Published: 21 Jun 2024
    4.3
    Medium

    CVE-2024-1955

    Last Modified: 8 Apr 2026

    The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'warning_notices_settings' function in all versions up to, and including, 1.3. This makes it possible for authenticated attackers, with contributor access and above, to modify the plugin's settings.

    Published: 21 Jun 2024
    6.5
    Medium

    CVE-2024-1639

    Last Modified: 8 Apr 2026

    The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions in all versions up to, and including, 3.0.6. This makes it possible for authenticated attackers, with admin dashboard access (contributors by default due to WooCommerce) to view arbitrary decrypted license keys. The functions contain a referrer nonce check. However, these can be retrieved via the dashboard through the "license" JS variable. Please note that the version in trunk is patched, however, the 3.0.7 tagged version is not.

    Published: 21 Jun 2024