Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 321-340 of 837 records
Threat Entry Updated 2024-11-21

CVE-2023-2744 - Before 1 Plugin

The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Before 1

CVE-2023-2744

HIGH CVSS 7.2 2023-06-27
Threat Entry Updated 2025-05-05

CVE-2023-2743 - Before 1 Plugin

The ERP WordPress plugin before 1.12.4 does not sanitise and escape the employee_name parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 1

CVE-2023-2743

MEDIUM CVSS 6.1 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2326 - Before 1 Plugin

The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

PLUGIN Before 1

CVE-2023-2326

MEDIUM CVSS 6.5 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-1891 - Before 1 Plugin

The Accordion & FAQ WordPress plugin before 1.9.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2023-1891

MEDIUM CVSS 6.1 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2580 - Before 1 Plugin

The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

PLUGIN Before 1

CVE-2023-2580

MEDIUM CVSS 4.8 2023-06-27
Threat Entry Updated 2024-12-12

CVE-2023-2654 - Before 1 Plugin

The Conditional Menus WordPress plugin before 1.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2023-2654

MEDIUM CVSS 6.1 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2399 - Before 1 Plugin

The QuBot WordPress plugin before 1.1.6 doesn't filter user input on chat, leading to bad code inserted on it be reflected on the user dashboard.

PLUGIN Before 1

CVE-2023-2399

MEDIUM CVSS 6.1 2023-06-19
Threat Entry Updated 2025-04-23

CVE-2023-2600 - Before 1 Plugin

The Custom Base Terms WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2023-2600

MEDIUM CVSS 4.8 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2527 - Before 1 Plugin

The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

PLUGIN Before 1

CVE-2023-2527

MEDIUM CVSS 4.8 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2401 - Before 1 Plugin

The QuBot WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2023-2401

MEDIUM CVSS 4.8 2023-06-19
Threat Entry Updated 2024-11-21

CVE-2023-2718 - Before 1 Plugin

The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.

PLUGIN Before 1

CVE-2023-2718

MEDIUM CVSS 5.4 2023-06-12
Threat Entry Updated 2025-05-05

CVE-2023-2362 - Before 1 Plugin

The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back in an attribute, leading to…

PLUGIN Before 1

CVE-2023-2362

MEDIUM CVSS 6.1 2023-06-12
Threat Entry Updated 2025-01-08

CVE-2023-2503 - Before 1 Plugin

The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2023-2503

MEDIUM CVSS 6.1 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-2224 - Before 1 Plugin

The SEO by 10Web WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2023-2224

MEDIUM CVSS 4.8 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-0545 - Before 1 Plugin

The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2023-0545

MEDIUM CVSS 4.8 2023-06-05
Threat Entry Updated 2025-01-10

CVE-2023-2296 - Before 1 Plugin

The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2023-2296

MEDIUM CVSS 6.1 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-1938 - Before 1 Plugin

The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate user input before using it in the wp_remote_get() function, leading to a Blind SSRF issue

PLUGIN Before 1

CVE-2023-1938

HIGH CVSS 8.8 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-0443 - Before 1 Plugin

The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.

PLUGIN Before 1

CVE-2023-0443

MEDIUM CVSS 5.3 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2117 - Before 1 Plugin

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

PLUGIN Before 1

CVE-2023-2117

LOW CVSS 2.7 2023-05-30
Threat Entry Updated 2025-01-24

CVE-2023-1207 - Before 1 Plugin

This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability.

PLUGIN Before 1

CVE-2023-1207

HIGH CVSS 7.2 2023-05-15
Scroll to top