Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 341-360 of 837 records
Threat Entry Updated 2025-01-24

CVE-2023-1915 - Before 1 Plugin

The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting vulnerability which could be used against high privilege users such as admin.

PLUGIN Before 1

CVE-2023-1915

MEDIUM CVSS 6.1 2023-05-15
Threat Entry Updated 2025-01-24

CVE-2023-1890 - Before 1 Plugin

The Tablesome WordPress plugin before 1.0.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2023-1890

MEDIUM CVSS 6.1 2023-05-15
Threat Entry Updated 2025-01-30

CVE-2023-1614 - Before 1 Plugin

The WP Custom Author URL WordPress plugin before 1.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2023-1614

MEDIUM CVSS 4.8 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1911 - Before 1 Plugin

The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example

PLUGIN Before 1

CVE-2023-1911

MEDIUM CVSS 4.3 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1125 - Before 1 Plugin

The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.

PLUGIN Before 1

CVE-2023-1125

MEDIUM CVSS 6.5 2023-05-02
Threat Entry Updated 2025-02-04

CVE-2023-1623 - Before 1 Plugin

The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to make a logged in admin send such information to an arbitrary email address via a CSRF attack.

PLUGIN Before 1

CVE-2023-1623

MEDIUM CVSS 6.5 2023-04-24
Threat Entry Updated 2025-02-06

CVE-2023-1331 - Before 1 Plugin

The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.

PLUGIN Before 1

CVE-2023-1331

MEDIUM CVSS 6.5 2023-04-17
Threat Entry Updated 2025-02-06

CVE-2023-1427 - Before 1 Plugin

- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.

PLUGIN Before 1

CVE-2023-1427

MEDIUM CVSS 4.9 2023-04-17
Threat Entry Updated 2025-02-11

CVE-2023-0363 - Before 1 Plugin

The Scheduled Announcements Widget WordPress plugin before 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0363

MEDIUM CVSS 5.4 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0893 - Before 1 Plugin

The Time Sheets WordPress plugin before 1.29.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2023-0893

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0605 - Before 1 Plugin

The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2023-0605

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0423 - Before 1 Plugin

The WordPress Amazon S3 Plugin WordPress plugin before 1.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2023-0423

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-14

CVE-2023-1330 - Before 1 Plugin

The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.

PLUGIN Before 1

CVE-2023-1330

MEDIUM CVSS 6.5 2023-04-03
Threat Entry Updated 2025-02-14

CVE-2023-0820 - Before 1 Plugin

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.

PLUGIN Before 1

CVE-2023-0820

HIGH CVSS 8.8 2023-04-03
Threat Entry Updated 2025-02-19

CVE-2023-1089 - Before 1 Plugin

The Coupon Zen WordPress plugin before 1.0.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-1089

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-1088 - Before 1 Plugin

The WP Plugin Manager WordPress plugin before 1.1.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-1088

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-1087 - Before 1 Plugin

The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-1087

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-1086 - Before 1 Plugin

The Preview Link Generator WordPress plugin before 1.0.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-1086

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0500 - Before 1 Plugin

The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0500

MEDIUM CVSS 6.5 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0503 - Before 1 Plugin

The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0503

MEDIUM CVSS 4.3 2023-03-27
Scroll to top