Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 401-420 of 837 records
Threat Entry Updated 2025-05-06

CVE-2022-3419 - Before 1 Plugin

The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator

PLUGIN Before 1

CVE-2022-3419

MEDIUM CVSS 6.5 2022-10-31
Threat Entry Updated 2025-05-07

CVE-2022-2190 - Before 1 Plugin

The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

PLUGIN Before 1

CVE-2022-2190

MEDIUM CVSS 6.1 2022-10-31
Threat Entry Updated 2025-05-07

CVE-2022-3395 - Before 1 Plugin

The WP All Export Pro WordPress plugin before 1.7.9 uses the contents of the cc_sql POST parameter directly as a database query, allowing users which has been given permission to run exports to execute arbitrary SQL statements, leading to a SQL Injection vulnerability. By default only users with the Administrator role can perform exports, but this can be delegated to lower privileged users as well.

PLUGIN Before 1

CVE-2022-3395

HIGH CVSS 8.8 2022-10-25
Threat Entry Updated 2025-05-07

CVE-2022-3394 - Before 1 Plugin

The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only administrators can run exports, but the privilege can be delegated to lower privileged users.

PLUGIN Before 1

CVE-2022-3394

HIGH CVSS 7.2 2022-10-25
Threat Entry Updated 2025-05-09

CVE-2022-3335 - Before 1 Plugin

The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

PLUGIN Before 1

CVE-2022-3335

HIGH CVSS 7.2 2022-10-25
Threat Entry Updated 2025-05-09

CVE-2022-3300 - Before 1 Plugin

The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

PLUGIN Before 1

CVE-2022-3300

HIGH CVSS 7.2 2022-10-25
Threat Entry Updated 2025-05-07

CVE-2022-3097 - Before 1 Plugin

The Plugin LBstopattack WordPress plugin before 1.1.3 does not use nonces when saving its settings, making it possible for attackers to conduct CSRF attacks. This could allow attackers to disable the plugin's protections.

PLUGIN Before 1

CVE-2022-3097

MEDIUM CVSS 6.5 2022-10-25
Threat Entry Updated 2025-05-14

CVE-2022-3139 - Before 1 Plugin

The We’re Open! WordPress plugin before 1.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2022-3139

MEDIUM CVSS 4.8 2022-10-17
Threat Entry Updated 2025-05-13

CVE-2022-3282 - Before 1 Plugin

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.

PLUGIN Before 1

CVE-2022-3282

MEDIUM CVSS 4.3 2022-10-17
Threat Entry Updated 2025-05-13

CVE-2022-2574 - Before 1 Plugin

The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2022-2574

MEDIUM CVSS 4.8 2022-10-17
Threat Entry Updated 2024-11-21

CVE-2022-3154 - Before 1 Plugin

The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin's license

PLUGIN Before 1

CVE-2022-3154

HIGH CVSS 7.1 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-3137 - Before 1 Plugin

The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file

PLUGIN Before 1

CVE-2022-3137

MEDIUM CVSS 5.4 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-3220 - Before 1 Plugin

The Advanced Comment Form WordPress plugin before 1.2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2022-3220

MEDIUM CVSS 4.8 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-3136 - Before 1 Plugin

The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2022-3136

MEDIUM CVSS 4.8 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-3132 - Before 1 Plugin

The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2022-3132

MEDIUM CVSS 4.8 2022-10-03
Threat Entry Updated 2025-05-21

CVE-2022-2404 - Before 1 Plugin

The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-2404

MEDIUM CVSS 6.1 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2022-2405 - Before 1 Plugin

The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup

PLUGIN Before 1

CVE-2022-2405

MEDIUM CVSS 4.3 2022-09-26
Threat Entry Updated 2024-11-21

CVE-2022-2710 - Before 1 Plugin

The Scroll To Top WordPress plugin before 1.4.1 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2022-2710

MEDIUM CVSS 4.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-2567 - Before 1 Plugin

The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2022-2567

MEDIUM CVSS 4.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-1580 - Before 1 Plugin

The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature.

PLUGIN Before 1

CVE-2022-1580

MEDIUM CVSS 4.3 2022-09-19
Scroll to top