Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 561-580 of 837 records
Threat Entry Updated 2024-11-21

CVE-2022-0640 - Before 1 Plugin

The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Before 1

CVE-2022-0640

MEDIUM CVSS 6.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0627 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Before 1

CVE-2022-0627

MEDIUM CVSS 6.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0423 - Before 1 Plugin

The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook.

PLUGIN Before 1

CVE-2022-0423

MEDIUM CVSS 5.4 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0616 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack

PLUGIN Before 1

CVE-2022-0616

MEDIUM CVSS 4.3 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2021-24905 - Before 1 Plugin

The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php allows attackers to trigger WordPress setup again, gain administrator privileges and execute arbitrary code or display arbitrary content to the users.

PLUGIN Before 1

CVE-2021-24905

HIGH CVSS 8.0 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0593 - Before 1 Plugin

The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a potential Denial of Service situation.

PLUGIN Before 1

CVE-2022-0593

MEDIUM CVSS 6.5 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0648 - Before 1 Plugin

The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Before 1

CVE-2022-0648

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0700 - Before 1 Plugin

The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2022-0700

MEDIUM CVSS 4.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0169 - Before 1 Plugin

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

PLUGIN Before 1

CVE-2022-0169

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0399 - Before 1 Plugin

The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-0399

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0327 - Before 1 Plugin

The Master Addons for Elementor WordPress plugin before 1.8.5 does not sanitise and escape the error_message parameter before outputting it back in the response of the jltma_restrict_content AJAX action, available to unauthenticated and authenticated users, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-0327

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0248 - Before 1 Plugin

The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting attacks against admins viewing the malicious submission

PLUGIN Before 1

CVE-2022-0248

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0161 - Before 1 Plugin

The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-0161

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-25026 - Before 1 Plugin

The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-25026

MEDIUM CVSS 5.5 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24958 - Before 1 Plugin

The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_business_selected_account AJAX action, available to any authenticated user, and does not escape some of the settings. As a result, any authenticated user, such as subscriber could update the plugin's settings and put Cross-Site Scripting payloads in them

PLUGIN Before 1

CVE-2021-24958

MEDIUM CVSS 5.4 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24895 - Before 1 Plugin

The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24895

MEDIUM CVSS 4.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0347 - Before 1 Plugin

The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-0347

MEDIUM CVSS 6.1 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0535 - Before 1 Plugin

The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2022-0535

MEDIUM CVSS 4.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0448 - Before 1 Plugin

The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

PLUGIN Before 1

CVE-2022-0448

MEDIUM CVSS 4.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0389 - Before 1 Plugin

The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2022-0389

MEDIUM CVSS 4.8 2022-03-07
Scroll to top