Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 421-440 of 837 records
Threat Entry Updated 2024-11-21

CVE-2022-2887 - Before 1 Plugin

The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2022-2887

MEDIUM CVSS 4.8 2022-09-16
Threat Entry Updated 2025-06-03

CVE-2022-2913 - Before 1 Plugin

The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.

PLUGIN Before 1

CVE-2022-2913

MEDIUM CVSS 4.3 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-1194 - Before 1 Plugin

The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.

PLUGIN Before 1

CVE-2022-1194

HIGH CVSS 8.8 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2575 - Before 1 Plugin

The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2022-2575

MEDIUM CVSS 4.8 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2775 - Before 1 Plugin

The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2022-2775

MEDIUM CVSS 5.5 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2559 - Before 1 Plugin

The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users

PLUGIN Before 1

CVE-2022-2559

HIGH CVSS 7.2 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2538 - Before 1 Plugin

The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an attribute of a backend page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-2538

MEDIUM CVSS 6.1 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2373 - Before 1 Plugin

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address

PLUGIN Before 1

CVE-2022-2373

MEDIUM CVSS 5.3 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2374 - Before 1 Plugin

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2022-2374

MEDIUM CVSS 4.8 2022-08-29
Threat Entry Updated 2026-02-02

CVE-2022-2551 - Before 1 Plugin

The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.

PLUGIN Before 1

CVE-2022-2551

HIGH CVSS 7.5 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2544 - Before 1 Plugin

The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.

PLUGIN Before 1

CVE-2022-2544

HIGH CVSS 7.5 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2593 - Before 1 Plugin

The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before inserting it into a SQL query, which could allow high privilege users to perform SQL Injection attacks

PLUGIN Before 1

CVE-2022-2593

HIGH CVSS 7.2 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2392 - Before 1 Plugin

The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.

PLUGIN Before 1

CVE-2022-2392

MEDIUM CVSS 6.5 2022-08-22
Threat Entry Updated 2026-02-02

CVE-2022-2552 - Before 1 Plugin

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

PLUGIN Before 1

CVE-2022-2552

MEDIUM CVSS 5.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-25812 - Before 1 Plugin

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allow allowing high privilege users such as admin to perform RCE

PLUGIN Before 1

CVE-2022-25812

HIGH CVSS 7.2 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2375 - Before 1 Plugin

The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues

PLUGIN Before 1

CVE-2022-2375

MEDIUM CVSS 5.4 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2312 - Before 1 Plugin

The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site scripting

PLUGIN Before 1

CVE-2022-2312

MEDIUM CVSS 5.4 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2276 - Before 1 Plugin

The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow unauthenticated attackers to delete arbitrary posts/pages from the blog

PLUGIN Before 1

CVE-2022-2276

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2275 - Before 1 Plugin

The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make a logged in admin delete arbitrary posts/pages from the blog via a CSRF attack

PLUGIN Before 1

CVE-2022-2275

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2021-24910 - Before 1 Plugin

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24910

MEDIUM CVSS 6.1 2022-08-22
Scroll to top