Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 581-600 of 837 records
Threat Entry Updated 2024-11-21

CVE-2022-0442 - Before 1 Plugin

The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

PLUGIN Before 1

CVE-2022-0442

MEDIUM CVSS 4.3 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24821 - Before 1 Plugin

The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), as well as the Text Preview field of a Project (injected on the edit project page)

PLUGIN Before 1

CVE-2021-24821

MEDIUM CVSS 5.4 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24777 - Before 1 Plugin

The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leading to an SQL injection.

PLUGIN Before 1

CVE-2021-24777

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0412 - Before 1 Plugin

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

PLUGIN Before 1

CVE-2022-0412

CRITICAL CVSS 9.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25081 - Before 1 Plugin

The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack

PLUGIN Before 1

CVE-2021-25081

MEDIUM CVSS 6.5 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25011 - Before 1 Plugin

The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.

PLUGIN Before 1

CVE-2021-25011

MEDIUM CVSS 5.7 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0345 - Before 1 Plugin

The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).

PLUGIN Before 1

CVE-2022-0345

MEDIUM CVSS 4.3 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24730 - Before 1 Plugin

The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change title, description, alt text, and URL of arbitrary uploaded media.

PLUGIN Before 1

CVE-2021-24730

MEDIUM CVSS 4.3 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0234 - Before 1 Plugin

The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-0234

MEDIUM CVSS 6.1 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-25075 - Before 1 Plugin

The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issues

PLUGIN Before 1

CVE-2021-25075

LOW CVSS 3.5 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0190 - Before 1 Plugin

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action.

PLUGIN Before 1

CVE-2022-0190

HIGH CVSS 8.8 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0214 - Before 1 Plugin

The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog

PLUGIN Before 1

CVE-2022-0214

HIGH CVSS 7.5 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0206 - Before 1 Plugin

The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 1

CVE-2022-0206

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2025-04-15

CVE-2022-0176 - Before 1 Plugin

The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-0176

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0200 - Before 1 Plugin

Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-0200

MEDIUM CVSS 5.4 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25107 - Before 1 Plugin

The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back in the created entry, allowing unauthenticated attacker to perform Cross-Site Scripting attacks against admin

PLUGIN Before 1

CVE-2021-25107

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25033 - Before 1 Plugin

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue

PLUGIN Before 1

CVE-2021-25033

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25050 - Before 1 Plugin

The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

PLUGIN Before 1

CVE-2021-25050

MEDIUM CVSS 4.8 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25109 - Before 1 Plugin

The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high privilege users to extract data from the database as well as used to perform Cross-Site Scripting (XSS) against logged in admins by making send open a malicious link.

PLUGIN Before 1

CVE-2021-25109

LOW CVSS 2.7 2022-02-14
Scroll to top