Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 241-260 of 837 records
Threat Entry Updated 2024-11-21

CVE-2023-6295 - Before 1 Plugin

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

PLUGIN Before 1

CVE-2023-6295

HIGH CVSS 7.2 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6272 - Before 1 Plugin

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

PLUGIN Before 1

CVE-2023-6272

CRITICAL CVSS 9.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-5886 - Before 1 Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.

PLUGIN Before 1

CVE-2023-5886

HIGH CVSS 8.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-5882 - Before 1 Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.

PLUGIN Before 1

CVE-2023-5882

HIGH CVSS 8.8 2023-12-18
Threat Entry Updated 2025-05-20

CVE-2023-4724 - Before 1 Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server

PLUGIN Before 1

CVE-2023-4724

HIGH CVSS 7.2 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-5955 - Before 1 Plugin

The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2023-5955

MEDIUM CVSS 4.8 2023-12-11
Threat Entry Updated 2024-11-21

CVE-2023-6063 - Before 1 Plugin

The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

PLUGIN Before 1

CVE-2023-6063

HIGH CVSS 7.5 2023-12-04
Threat Entry Updated 2024-11-21

CVE-2023-5762 - Before 1 Plugin

The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execute commands and fully compromise the server on behalf of a user with Author-level privileges.

PLUGIN Before 1

CVE-2023-5762

HIGH CVSS 8.8 2023-12-04
Threat Entry Updated 2024-11-21

CVE-2023-5906 - Before 1 Plugin

The Job Manager & Career WordPress plugin before 1.4.4 contains a vulnerability in the Directory Listings system, which allows an unauthorized user to view and download private files of other users. This vulnerability poses a serious security threat because it allows an attacker to gain access to confidential data and files of other users without their permission.

PLUGIN Before 1

CVE-2023-5906

HIGH CVSS 7.5 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5641 - Before 1 Plugin

The Martins Free & Easy SEO BackLink Link Building Network WordPress plugin before 1.2.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2023-5641

MEDIUM CVSS 6.1 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5942 - Before 1 Plugin

The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-5942

MEDIUM CVSS 5.4 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5738 - Before 1 Plugin

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-5738

MEDIUM CVSS 5.4 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5737 - Before 1 Plugin

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.

PLUGIN Before 1

CVE-2023-5737

MEDIUM CVSS 4.3 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5119 - Before 1 Plugin

The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).

PLUGIN Before 1

CVE-2023-5119

MEDIUM CVSS 4.8 2023-11-20
Threat Entry Updated 2025-03-25

CVE-2023-5601 - Before 1 Plugin

The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.

PLUGIN Before 1

CVE-2023-5601

CRITICAL CVSS 9.8 2023-11-06
Threat Entry Updated 2024-11-21

CVE-2023-5605 - Before 1 Plugin

The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2023-5605

MEDIUM CVSS 4.8 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-5082 - Before 1 Plugin

The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.

PLUGIN Before 1

CVE-2023-5082

HIGH CVSS 7.2 2023-11-06
Threat Entry Updated 2024-11-21

CVE-2023-5360 - Before 1 Plugin

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

PLUGIN Before 1

CVE-2023-5360

CRITICAL CVSS 9.8 2023-10-31
Threat Entry Updated 2025-04-22

CVE-2023-5237 - Before 1 Plugin

The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

PLUGIN Before 1

CVE-2023-5237

MEDIUM CVSS 5.4 2023-10-31
Threat Entry Updated 2025-04-23

CVE-2023-5229 - Before 1 Plugin

The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2023-5229

MEDIUM CVSS 4.8 2023-10-31
Scroll to top