Vulnerabilities (CVE)

Total 298704 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24566 1 Pluginus 1 Fox - Currency Switcher Professional For Woocommerce 2025-06-11 N/A 8.8 HIGH
The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.
CVE-2021-24432 1 Berocket 1 Advanced Ajax Product Filters 2025-06-11 N/A 6.1 MEDIUM
The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue.
CVE-2024-12739 1 Annabansaghi 1 Mobile Contact Bar 2025-06-11 N/A 4.8 MEDIUM
The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-6584 1 Automattic 1 Jetpack Boost 2025-06-11 N/A 9.1 CRITICAL
The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.
CVE-2024-6693 1 Wp-buy 1 Wp Content Copy Protection \& No Right Click 2025-06-11 N/A 4.8 MEDIUM
The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-6712 1 Acugis 1 Mapfig Studio 2025-06-11 N/A 6.1 MEDIUM
The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
CVE-2024-6713 1 Freebiesdownload 1 Pvn Auth Popup 2025-06-11 N/A 4.8 MEDIUM
The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-7556 1 Missionmike 1 Simple Share 2025-06-11 N/A 4.8 MEDIUM
The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-7759 1 Magazine3 1 Pwa For Wp \& Amp 2025-06-11 N/A 4.8 MEDIUM
The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-7761 1 Presstigers 1 Simple Job Board 2025-06-11 N/A 6.1 MEDIUM
In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
CVE-2024-7769 1 Clicksold 1 Clicksold Idx 2025-06-11 N/A 4.8 MEDIUM
The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-7984 1 Ultimatewpsms 1 Joy Of Text 2025-06-11 N/A 4.3 MEDIUM
The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2025-46548 2025-06-11 N/A 6.5 MEDIUM
If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. Akka was affected by the same issue and has released the fix in version 1.6.1.
CVE-2024-0748 1 Mozilla 1 Firefox 2025-06-11 N/A 4.3 MEDIUM
A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.
CVE-2024-8009 1 Automattic 1 Sensei Lms 2025-06-11 N/A 7.5 HIGH
The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page
CVE-2024-5440 1 If-so 1 Dynamic Content Personalization 2025-06-11 N/A 5.4 MEDIUM
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2024-6159 1 Pnfpb 1 Push Notification For Post And Buddypress 2025-06-11 N/A 9.8 CRITICAL
The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
CVE-2024-6335 1 Data443 1 Tracking Code Manager 2025-06-11 N/A 4.8 MEDIUM
The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-42009 1 Roundcube 1 Webmail 2025-06-11 N/A 9.3 CRITICAL
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
CVE-2024-6462 1 Dyadyalesha 1 Dl Yandex Metrika 2025-06-11 N/A 4.8 MEDIUM
The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)