Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 281-300 of 837 records
Threat Entry Updated 2025-03-06

CVE-2023-4151 - Before 1 Plugin

The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2023-4151

MEDIUM CVSS 6.1 2023-09-04
Threat Entry Updated 2025-04-23

CVE-2023-4298 - Before 1 Plugin

The 123.chat WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2023-4298

MEDIUM CVSS 4.8 2023-09-04
Threat Entry Updated 2025-04-23

CVE-2023-4269 - Before 1 Plugin

The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.

PLUGIN Before 1

CVE-2023-4269

MEDIUM CVSS 4.3 2023-09-04
Threat Entry Updated 2025-04-23

CVE-2023-4216 - Before 1 Plugin

The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however limited to the first line of the file.

PLUGIN Before 1

CVE-2023-4216

LOW CVSS 2.7 2023-09-04
Threat Entry Updated 2024-11-21

CVE-2023-2813 - Before 1 Theme

All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite WordPress theme before 2.1, Cafe Bistro WordPress theme before 1.1.4, College WordPress theme before 1.5.1, Connections Reloaded WordPress theme through 3.1, Counterpoint WordPress theme through 1.8.1, Digitally WordPress theme through 1.0.8, Directory WordPress theme before 3.0.2, Drop WordPress theme before 1.22, Everse WordPress theme before 1.2.4, Fashionable…

THEME Before 1

CVE-2023-2813

MEDIUM CVSS 6.1 2023-09-04
Threat Entry Updated 2025-05-05

CVE-2023-3720 - Before 1 Plugin

The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload files (including HTML containing JS code for users with the unfiltered_html capability) on their behalf.

PLUGIN Before 1

CVE-2023-3720

MEDIUM CVSS 6.5 2023-08-30
Threat Entry Updated 2025-04-23

CVE-2023-4035 - Before 1 Plugin

The Simple Blog Card WordPress plugin before 1.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-4035

MEDIUM CVSS 5.4 2023-08-30
Threat Entry Updated 2025-04-23

CVE-2023-3501 - Before 1 Plugin

The FormCraft WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2023-3501

MEDIUM CVSS 4.8 2023-08-30
Threat Entry Updated 2025-05-02

CVE-2023-4036 - Before 1 Plugin

The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones

PLUGIN Before 1

CVE-2023-4036

MEDIUM CVSS 4.3 2023-08-30
Threat Entry Updated 2024-11-21

CVE-2023-3356 - Before 1 Plugin

The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

PLUGIN Before 1

CVE-2023-3356

MEDIUM CVSS 4.3 2023-08-30
Threat Entry Updated 2025-05-05

CVE-2023-3954 - Before 1 Plugin

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2023-3954

MEDIUM CVSS 6.1 2023-08-21
Threat Entry Updated 2026-01-16

CVE-2023-3604 - Before 1 Plugin

The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered.

PLUGIN Before 1

CVE-2023-3604

HIGH CVSS 7.5 2023-08-21
Threat Entry Updated 2025-05-05

CVE-2023-3667 - Before 1 Plugin

The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2023-3667

MEDIUM CVSS 4.8 2023-08-21
Threat Entry Updated 2024-11-21

CVE-2023-3366 - Before 1 Plugin

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack

PLUGIN Before 1

CVE-2023-3366

MEDIUM CVSS 4.3 2023-08-21
Threat Entry Updated 2024-11-21

CVE-2023-2122 - Before 1 Plugin

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.

PLUGIN Before 1

CVE-2023-2122

MEDIUM CVSS 6.1 2023-08-16
Threat Entry Updated 2024-11-21

CVE-2023-2254 - Before 1 Plugin

The Ko-fi Button WordPress plugin before 1.3.3 does not properly some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup), and we consider it a low risk.

PLUGIN Before 1

CVE-2023-2254

MEDIUM CVSS 4.8 2023-08-16
Threat Entry Updated 2024-11-21

CVE-2023-3435 - Before 1 Plugin

The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

PLUGIN Before 1

CVE-2023-3435

CRITICAL CVSS 9.8 2023-08-14
Threat Entry Updated 2024-11-21

CVE-2023-3328 - Before 1 Plugin

The Custom Field For WP Job Manager WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2023-3328

MEDIUM CVSS 4.8 2023-08-14
Threat Entry Updated 2024-11-21

CVE-2023-3365 - Before 1 Plugin

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment

PLUGIN Before 1

CVE-2023-3365

HIGH CVSS 8.1 2023-08-07
Threat Entry Updated 2025-05-05

CVE-2023-3671 - Before 1 Plugin

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2023-3671

MEDIUM CVSS 6.1 2023-08-07
Scroll to top