Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 381-400 of 837 records
Threat Entry Updated 2025-03-12

CVE-2023-0059 - Before 1 Plugin

The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0059

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-21

CVE-2023-0379 - Before 1 Plugin

The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0379

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0373 - Before 1 Plugin

The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0373

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0362 - Before 1 Plugin

Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0362

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0405 - Before 1 Plugin

The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts.

PLUGIN Before 1

CVE-2023-0405

MEDIUM CVSS 4.3 2023-02-13
Threat Entry Updated 2025-03-20

CVE-2023-0360 - Before 1 Plugin

The Location Weather WordPress plugin before 1.3.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0360

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2024-11-21

CVE-2023-0159 - Before 1 Plugin

The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains.

PLUGIN Before 1

CVE-2023-0159

HIGH CVSS 7.5 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0166 - Before 1 Plugin

The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0166

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0061 - Before 1 Plugin

The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0061

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-01-14

CVE-2023-0034 - Before 1 Plugin

The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0034

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-25

CVE-2023-0234 - Before 1 Plugin

The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.

PLUGIN Before 1

CVE-2023-0234

HIGH CVSS 8.8 2023-02-06
Threat Entry Updated 2025-03-26

CVE-2023-0282 - Before 1 Plugin

The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0282

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-26

CVE-2023-0178 - Before 1 Plugin

The Annual Archive WordPress plugin before 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0178

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0176 - Before 1 Plugin

The Giveaways and Contests by RafflePress WordPress plugin before 1.11.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0176

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0154 - Before 1 Plugin

The GamiPress WordPress plugin before 1.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0154

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0150 - Before 1 Plugin

The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0150

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0096 - Before 1 Plugin

The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0096

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0070 - Before 1 Plugin

The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0070

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-27

CVE-2023-0033 - Before 1 Plugin

The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

PLUGIN Before 1

CVE-2023-0033

MEDIUM CVSS 5.4 2023-01-30
Threat Entry Updated 2025-05-06

CVE-2022-3334 - Before 1 Plugin

The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

PLUGIN Before 1

CVE-2022-3334

HIGH CVSS 7.2 2022-10-31
Scroll to top