Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total808
Critical39
High132
Medium616
Reset
Showing 321-340 of 808 records
Threat Entry Updated 2025-02-11

CVE-2023-0893 - Before 1 Plugin

The Time Sheets WordPress plugin before 1.29.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2023-0893

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0605 - Before 1 Plugin

The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2023-0605

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0423 - Before 1 Plugin

The WordPress Amazon S3 Plugin WordPress plugin before 1.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2023-0423

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-14

CVE-2023-1330 - Before 1 Plugin

The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.

PLUGIN Before 1

CVE-2023-1330

MEDIUM CVSS 6.5 2023-04-03
Threat Entry Updated 2025-02-14

CVE-2023-0820 - Before 1 Plugin

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.

PLUGIN Before 1

CVE-2023-0820

HIGH CVSS 8.8 2023-04-03
Threat Entry Updated 2025-02-19

CVE-2023-1089 - Before 1 Plugin

The Coupon Zen WordPress plugin before 1.0.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-1089

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-1088 - Before 1 Plugin

The WP Plugin Manager WordPress plugin before 1.1.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-1088

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-1087 - Before 1 Plugin

The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-1087

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-1086 - Before 1 Plugin

The Preview Link Generator WordPress plugin before 1.0.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-1086

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0500 - Before 1 Plugin

The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0500

MEDIUM CVSS 6.5 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0503 - Before 1 Plugin

The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0503

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0499 - Before 1 Plugin

The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0499

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0498 - Before 1 Plugin

The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0498

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-26

CVE-2023-0497 - Before 1 Plugin

The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0497

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-14

CVE-2023-0496 - Before 1 Plugin

The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0496

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0495 - Before 1 Plugin

The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0495

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0484 - Before 1 Plugin

The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0484

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-27

CVE-2023-0037 - Before 1 Plugin

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN Before 1

CVE-2023-0037

CRITICAL CVSS 9.8 2023-03-13
Threat Entry Updated 2025-02-27

CVE-2023-0538 - Before 1 Plugin

The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0538

MEDIUM CVSS 5.4 2023-03-13
Threat Entry Updated 2025-02-27

CVE-2023-0172 - Before 1 Plugin

The Juicer WordPress plugin before 1.11 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0172

MEDIUM CVSS 5.4 2023-03-13
Scroll to top