Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 361-380 of 837 records
Threat Entry Updated 2025-02-19

CVE-2023-0499 - Before 1 Plugin

The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0499

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0498 - Before 1 Plugin

The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0498

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-26

CVE-2023-0497 - Before 1 Plugin

The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0497

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-14

CVE-2023-0496 - Before 1 Plugin

The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0496

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0495 - Before 1 Plugin

The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0495

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0484 - Before 1 Plugin

The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0484

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-27

CVE-2023-0037 - Before 1 Plugin

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN Before 1

CVE-2023-0037

CRITICAL CVSS 9.8 2023-03-13
Threat Entry Updated 2025-02-27

CVE-2023-0538 - Before 1 Plugin

The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0538

MEDIUM CVSS 5.4 2023-03-13
Threat Entry Updated 2025-02-27

CVE-2023-0172 - Before 1 Plugin

The Juicer WordPress plugin before 1.11 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0172

MEDIUM CVSS 5.4 2023-03-13
Threat Entry Updated 2024-11-21

CVE-2023-0076 - Before 1 Plugin

The Download Attachments WordPress plugin before 1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0076

MEDIUM CVSS 5.4 2023-03-06
Threat Entry Updated 2024-11-21

CVE-2023-0539 - Before 1 Plugin

The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0539

MEDIUM CVSS 5.4 2023-02-27
Threat Entry Updated 2025-03-14

CVE-2023-0559 - Before 1 Plugin

The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0559

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0541 - Before 1 Plugin

The GS Books Showcase WordPress plugin before 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0541

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-13

CVE-2023-0540 - Before 1 Plugin

The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0540

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-14

CVE-2023-0492 - Before 1 Plugin

The GS Products Slider for WooCommerce WordPress plugin before 1.5.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0492

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0442 - Before 1 Plugin

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a crafted URL.

PLUGIN Before 1

CVE-2023-0442

MEDIUM CVSS 6.1 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0419 - Before 1 Plugin

The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0419

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-13

CVE-2023-0371 - Before 1 Plugin

The EmbedSocial WordPress plugin before 1.1.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0371

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0366 - Before 1 Plugin

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0366

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-14

CVE-2023-0271 - Before 1 Plugin

The WP Font Awesome WordPress plugin before 1.7.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0271

MEDIUM CVSS 5.4 2023-02-21
Scroll to top