plugin

24Liveblog Vulnerabilities

2 known security issues reported for the 24Liveblog WordPress plugin. Most recent disclosed Jun 23, 2026.

2 medium

Running 24Liveblog on your site? Check whether your installed version is affected.

Scan your site free

24liveblog <= 2.2 - Missing Authorization to Authenticated (Author+) Settings Modification via update_lb24_token AJAX action

medium

The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX function in versions up to, and including, 2.2. The handler only verifies the 'lb24' nonce (which is generated and localized to any user with block ed...

CVSS:
4.3
Affected:
up to 2.2
Fix:
No patched version reported
Disclosed:
Jun 23, 2026

CVE-2026-9184 on NVD →

24liveblog <= 2.2 - Authenticated (Contributor+) Exposure of Sensitive Information via Block Editor Script Localization

medium

The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block_enqueue_scripts() function being hooked to enqueue_block_editor_assets and, for any non-administrator user, falling back to loading the administrat...

CVSS:
4.3
Affected:
up to 2.2
Fix:
No patched version reported
Disclosed:
Jun 23, 2026

CVE-2026-9183 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database