CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8620
4.8 MEDIUM

The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8619
4.8 MEDIUM

The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8618
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8617
4.8 MEDIUM

The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to …

May 15, 2025
CVE-2024-8542
4.8 MEDIUM

The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-8493
4.8 MEDIUM

The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-8492
4.8 MEDIUM

The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to …

May 15, 2025
CVE-2024-8426
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8398
4.3 MEDIUM

The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make …

May 15, 2025
CVE-2024-8397
5.4 MEDIUM

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting …

May 15, 2025
CVE-2024-8286
6.5 MEDIUM

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform …

May 15, 2025
CVE-2024-8284
4.8 MEDIUM

The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors …

May 15, 2025
CVE-2024-8245
4.3 MEDIUM

The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

May 15, 2025
CVE-2024-8187
4.8 MEDIUM

The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8095
6.1 MEDIUM

The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

May 15, 2025
CVE-2024-8094
6.5 MEDIUM

The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 15, 2025
CVE-2024-8090
6.1 MEDIUM

The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

May 15, 2025
CVE-2024-8085
6.1 MEDIUM

The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

May 15, 2025
CVE-2024-8082
4.3 MEDIUM

The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 15, 2025
CVE-2024-8050
4.3 MEDIUM

The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make …

May 15, 2025
CVE-2024-8032
6.1 MEDIUM

The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

May 15, 2025
CVE-2024-8031
6.5 MEDIUM

The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, …

May 15, 2025
CVE-2024-8009
4.3 MEDIUM

The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

May 15, 2025
CVE-2024-7984
4.3 MEDIUM

The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to …

May 15, 2025
CVE-2024-7769
4.8 MEDIUM

The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-7761
6.1 MEDIUM

In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on …

May 15, 2025
CVE-2024-7759
4.8 MEDIUM

The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-7758
4.8 MEDIUM

The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor …

May 15, 2025
CVE-2024-7556
4.8 MEDIUM

The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-6798
4.8 MEDIUM

The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-6797
4.8 MEDIUM

The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-6718
5.4 MEDIUM

The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

May 15, 2025
CVE-2024-6713
4.8 MEDIUM

The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-6712
6.1 MEDIUM

The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

May 15, 2025
CVE-2024-6708
4.8 MEDIUM

The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows …

May 15, 2025
CVE-2024-6693
4.8 MEDIUM

The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-6690
6.1 MEDIUM

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

May 15, 2025
CVE-2024-6668
5.4 MEDIUM

The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role …

May 15, 2025
CVE-2024-6667
6.1 MEDIUM

The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading …

May 15, 2025
CVE-2024-6665
4.8 MEDIUM

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users …

May 15, 2025
CVE-2024-6478
4.8 MEDIUM

The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-6462
4.8 MEDIUM

The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-6335
4.8 MEDIUM

The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-5440
5.4 MEDIUM

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a …

May 15, 2025
CVE-2024-5026
4.8 MEDIUM

The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-4665
6.4 MEDIUM

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature …

May 15, 2025
CVE-2024-3901
6.8 MEDIUM

The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed …

May 15, 2025
CVE-2024-3062
4.8 MEDIUM

The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, which could allow high privilege …

May 15, 2025
CVE-2024-2869
4.8 MEDIUM

The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-2643
4.8 MEDIUM

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some …

May 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.