| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-0691 | FileBird <= 5.6.0 - Authenticated(Administrator+) Stored Cross-Site Scripting via Folder Import | ninjateam | FileBird – WordPress Media Library Folders & File Manager | Medium | 5.5 | 2024-02-05 21:21:43 | Deep Dive |
| CVE-2023-6526 | Meta Box – WordPress Custom Fields Framework <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | metabox | Meta Box | Medium | 6.4 | 2024-02-05 21:21:38 | Deep Dive |
| CVE-2024-0791 | WOLF – WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Missing Authorization | realmag777 | WOLF – WordPress Posts Bulk Editor and Manager Professional | Medium | 4.3 | 2024-02-05 21:21:34 | Deep Dive |
| CVE-2024-0685 | Ninja Forms Contact Form <= 3.7.1 - Unauthenticated Second Order SQL Injection | kstover | Ninja Forms – The Contact Form Builder That Grows With You | Medium | 5.9 | 2024-02-02 04:32:35 | Deep Dive |
| CVE-2023-51506 | WordPress WPCS Plugin <= 1.2.0 is vulnerable to Cross Site Scripting (XSS) | realmag777 | WPCS – WordPress Currency Switcher Professional | Medium | 5.5 | 2024-02-01 11:22:38 | Deep Dive |
| CVE-2023-51532 | WordPress Icegram Plugin <= 3.1.19 is vulnerable to Cross Site Scripting (XSS) | Icegram | Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building | Medium | 6.5 | 2024-02-01 11:00:08 | Deep Dive |
| CVE-2023-51536 | WordPress CRM Perks Forms Plugin <= 1.1.2 is vulnerable to Cross Site Scripting (XSS) | CRM Perks | CRM Perks Forms – WordPress Form Builder | Medium | 5.9 | 2024-02-01 10:25:54 | Deep Dive |
| CVE-2024-22150 | WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS) | PWR Plugins | Portfolio & Image Gallery for WordPress | PowerFolio | Medium | 6.5 | 2024-01-31 18:18:31 | Deep Dive |
| CVE-2024-22159 | WordPress WOLF Plugin <= 1.0.8 is vulnerable to Cross Site Scripting (XSS) | realmag777 | WOLF – WordPress Posts Bulk Editor and Manager Professional | High | 7.1 | 2024-01-31 18:12:04 | Deep Dive |
| CVE-2024-23508 | WordPress PDF Poster - PDF Embedder Plugin for WordPress Plugin <= 2.1.17 is vulnerable to Cross Site Scripting (XSS) | bPlugins | PDF Poster – PDF Embedder Plugin for WordPress | High | 7.1 | 2024-01-31 15:21:17 | Deep Dive |
| CVE-2024-22304 | WordPress FreshMail For WordPress Plugin <= 2.3.2 is vulnerable to Cross Site Request Forgery (CSRF) | Borbis Media | FreshMail For WordPress | Medium | 5.4 | 2024-01-31 12:15:37 | Deep Dive |
| CVE-2024-22305 | WordPress Contact Form builder with drag & drop - Kali Forms Plugin <= 2.3.36 is vulnerable to Insecure Direct Object References (IDOR) | ali Forms | Contact Form builder with drag & drop for WordPress – Kali Forms | High | 7.5 | 2024-01-31 11:49:29 | Deep Dive |
| CVE-2024-0836 | WordPress Review & Structure Data Schema Plugin – Review Schema <= 2.1.14 - Missing Authorization to Arbitrary Review Update | techlabpro1 | Review Schema – Review & Structure Data Schema Plugin | Medium | 4.3 | 2024-01-31 07:33:07 | Deep Dive |
| CVE-2023-2439 | WordPress plugin UserPro 安全漏洞 | - | UserPro - Community and User Profile WordPress Plugin | Medium | 6.4 | 2024-01-31 02:35:10 | Deep Dive |
| CVE-2023-7225 | MapPress <= 2.88.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings | chrisvrichardson | MapPress Maps for WordPress | Medium | 6.4 | 2024-01-30 07:34:39 | Deep Dive |
| CVE-2023-6390 | WordPress Users <= 1.4 - Settings Update via CSRF | Unknown | WordPress Users | 高危 | - | 2024-01-29 14:44:29 | Deep Dive |
| CVE-2023-6946 | Autotitle for WordPress <= 1.0.3 - Settings Update to Stored XSS via CSRF | Unknown | Autotitle for WordPress | 高危 | - | 2024-01-29 14:44:22 | Deep Dive |
| CVE-2023-7204 | WP STAGING WordPress Backup Plugin < 3.2.0 - Unauthorized Sensitive Data Exposure | Unknown | WP STAGING WordPress Backup Plugin | 高危 | - | 2024-01-29 14:44:21 | Deep Dive |
| CVE-2023-6389 | WordPress Toolbar <= 2.2.6 - Open Redirect | Unknown | WordPress Toolbar | 中危 | - | 2024-01-29 14:44:16 | Deep Dive |
| CVE-2024-0212 | Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users) | Cloudflare | Cloudflare-WordPress | High | 8.1 | 2024-01-29 09:13:45 | Deep Dive |