Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 521-540 of 837 records
Threat Entry Updated 2024-11-21

CVE-2022-0873 - Before 1 Plugin

The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed

PLUGIN Before 1

CVE-2022-0873

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1013 - Before 1 Plugin

The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.

PLUGIN Before 1

CVE-2022-1013

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-1047 - Before 1 Plugin

The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability.

PLUGIN Before 1

CVE-2022-1047

MEDIUM CVSS 6.1 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0424 - Before 1 Plugin

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

PLUGIN Before 1

CVE-2022-0424

MEDIUM CVSS 5.3 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-1104 - Before 1 Plugin

The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2022-1104

MEDIUM CVSS 4.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-1282 - Before 1 Plugin

The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, which is reflected back to the users when executing the editimage_bwg AJAX action.

PLUGIN Before 1

CVE-2022-1282

MEDIUM CVSS 6.1 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0952 - Before 1 Plugin

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

PLUGIN Before 1

CVE-2022-0952

HIGH CVSS 8.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0191 - Before 1 Plugin

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans

PLUGIN Before 1

CVE-2022-0191

MEDIUM CVSS 6.5 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1269 - Before 1 Plugin

The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-1269

MEDIUM CVSS 6.1 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1250 - Before 1 Plugin

The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirmation page before outputting them back in the page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2022-1250

MEDIUM CVSS 6.1 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1255 - Before 1 Plugin

The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues

PLUGIN Before 1

CVE-2022-1255

MEDIUM CVSS 4.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2021-25002 - Before 1 Plugin

The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL

PLUGIN Before 1

CVE-2021-25002

HIGH CVSS 7.5 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1391 - Before 1 Plugin

The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.

PLUGIN Before 1

CVE-2022-1391

CRITICAL CVSS 9.8 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2022-1228 - Before 1 Plugin

The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" field, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2022-1228

MEDIUM CVSS 4.8 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2022-1027 - Before 1 Plugin

The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that will only affect administrator users.

PLUGIN Before 1

CVE-2022-1027

MEDIUM CVSS 4.8 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2022-0657 - Before 1 Plugin

The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections.

PLUGIN Before 1

CVE-2022-0657

CRITICAL CVSS 9.8 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2021-46782 - Before 1 Plugin

The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2021-46782

MEDIUM CVSS 6.1 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2021-46781 - Before 1 Plugin

The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2021-46781

MEDIUM CVSS 6.1 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2021-46780 - Before 1 Plugin

The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2021-46780

MEDIUM CVSS 6.1 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2021-25111 - Before 1 Plugin

The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue

PLUGIN Before 1

CVE-2021-25111

MEDIUM CVSS 6.1 2022-04-25
Scroll to top