CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0761
8.1 HIGH

The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in …

Feb 5, 2024
CVE-2024-0709
9.8 CRITICAL

The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to …

Feb 5, 2024
CVE-2024-0701
5.3 MEDIUM

The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the use …

Feb 5, 2024
CVE-2024-0699
6.6 MEDIUM

The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation …

Feb 5, 2024
CVE-2024-0691
5.5 MEDIUM

The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all versions up to, and including, 5.5.8.1 due to …

Feb 5, 2024
CVE-2024-0678
6.5 MEDIUM

The Order Delivery Date for WP e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'available-days-tf' parameter in all versions up to, …

Feb 5, 2024
CVE-2024-0668
6.6 MEDIUM

The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted …

Feb 5, 2024
CVE-2024-0660
6.1 MEDIUM

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in …

Feb 5, 2024
CVE-2024-0659
5.5 MEDIUM

The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 5, 2024
CVE-2024-0630
4.4 MEDIUM

The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, …

Feb 5, 2024
CVE-2024-0612
4.4 MEDIUM

The Content Views – Post Grid, Slider, Accordion (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in …

Feb 5, 2024
CVE-2024-0597
4.4 MEDIUM

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including …

Feb 5, 2024
CVE-2024-0586
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 5, 2024
CVE-2024-0585
5.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 5, 2024
CVE-2024-0509
6.1 MEDIUM

The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘request’ parameter in all versions up …

Feb 5, 2024
CVE-2024-0508
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table Elementor Widget in all versions up …

Feb 5, 2024
CVE-2024-0448
6.4 MEDIUM

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget URL parameters in all versions up to, …

Feb 5, 2024
CVE-2024-0428
7.1 HIGH

The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.3. This is due to missing …

Feb 5, 2024
CVE-2024-0384
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Notes in all versions up to, and including, 9.1.0 due …

Feb 5, 2024
CVE-2024-0382
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 …

Feb 5, 2024
CVE-2024-0380
5.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 9.1.0 via the 'icon' attribute used …

Feb 5, 2024
CVE-2024-0374
4.3 MEDIUM

The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Feb 5, 2024
CVE-2024-0373
4.3 MEDIUM

The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Feb 5, 2024
CVE-2024-0372
4.3 MEDIUM

The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized access of data due …

Feb 5, 2024
CVE-2024-0371
4.3 MEDIUM

The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 5, 2024
CVE-2024-0370
4.3 MEDIUM

The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 5, 2024
CVE-2024-0366
4.3 MEDIUM

The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Feb 5, 2024
CVE-2024-0324
8.2 HIGH

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data …

Feb 5, 2024
CVE-2024-0255
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text-share' shortcode in all versions up to, and including, …

Feb 5, 2024
CVE-2024-0254
6.4 MEDIUM

The (Simply) Guest Author Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post meta in all versions up to, and …

Feb 5, 2024
CVE-2024-0221
9.1 CRITICAL

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.19 …

Feb 5, 2024
CVE-2023-7029
6.4 MEDIUM

The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including …

Feb 5, 2024
CVE-2023-7014
5.3 MEDIUM

The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Feb 5, 2024
CVE-2023-6996
8.8 HIGH

The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data …

Feb 5, 2024
CVE-2023-6989
9.8 CRITICAL

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, …

Feb 5, 2024
CVE-2023-6985
6.5 MEDIUM

The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Feb 5, 2024
CVE-2023-6983
4.3 MEDIUM

The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

Feb 5, 2024
CVE-2023-6982
6.4 MEDIUM

The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Feb 5, 2024
CVE-2023-6963
5.3 MEDIUM

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for …

Feb 5, 2024
CVE-2023-6959
4.3 MEDIUM

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function …

Feb 5, 2024
CVE-2023-6953
4.9 MEDIUM

The PDF Generator For Fluent Forms – The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the header, PDF body …

Feb 5, 2024
CVE-2023-6933
8.8 HIGH

The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted …

Feb 5, 2024
CVE-2023-6925
7.2 HIGH

The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'importZipFile' …

Feb 5, 2024
CVE-2023-6884
6.4 MEDIUM

This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient …

Feb 5, 2024
CVE-2023-6846
8.8 HIGH

The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX …

Feb 5, 2024
CVE-2023-6808
6.4 MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions …

Feb 5, 2024
CVE-2023-6807
6.4 MEDIUM

The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta output in all versions up to, and including, …

Feb 5, 2024
CVE-2023-6701
6.4 MEDIUM

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and …

Feb 5, 2024
CVE-2023-6700
8.8 HIGH

The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check on its …

Feb 5, 2024
CVE-2023-6635
7.2 HIGH

The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'import_styles' function in versions up to, …

Feb 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.