Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 201-220 of 664 records
Threat Entry Updated 2025-03-28

CVE-2024-1279 - Before 2 Plugin

The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

PLUGIN Before 2

CVE-2024-1279

MEDIUM CVSS 4.3 2024-03-11
Threat Entry Updated 2025-05-01

CVE-2023-7165 - Before 2 Plugin

The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.

PLUGIN Before 2

CVE-2023-7165

HIGH CVSS 7.5 2024-02-27
Threat Entry Updated 2025-05-01

CVE-2023-6585 - Before 2 Plugin

The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server

PLUGIN Before 2

CVE-2023-6585

HIGH CVSS 7.5 2024-02-27
Threat Entry Updated 2025-05-01

CVE-2023-6584 - Before 2 Plugin

The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.

PLUGIN Before 2

CVE-2023-6584

HIGH CVSS 7.5 2024-02-27
Threat Entry Updated 2025-04-08

CVE-2023-7203 - Before 2 Plugin

The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as subscriber to call them and perform unauthorised actions such as deleting entries. The plugin also lacks CSRF checks in some places which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as deleting entries.

PLUGIN Before 2

CVE-2023-7203

MEDIUM CVSS 6.1 2024-02-27
Threat Entry Updated 2024-11-21

CVE-2024-0420 - Before 2 Plugin

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2024-0420

MEDIUM CVSS 5.4 2024-02-12
Threat Entry Updated 2025-05-07

CVE-2024-0421 - Before 2 Plugin

The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.

PLUGIN Before 2

CVE-2024-0421

MEDIUM CVSS 5.3 2024-02-12
Threat Entry Updated 2025-05-07

CVE-2024-0248 - Before 2 Plugin

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.

PLUGIN Before 2

CVE-2024-0248

MEDIUM CVSS 4.3 2024-02-12
Threat Entry Updated 2025-06-20

CVE-2023-6278 - Before 2 Plugin

The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-6278

MEDIUM CVSS 6.1 2024-01-29
Threat Entry Updated 2025-05-29

CVE-2023-7199 - Before 2 Plugin

The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request

PLUGIN Before 2

CVE-2023-7199

MEDIUM CVSS 5.3 2024-01-29
Threat Entry Updated 2025-05-30

CVE-2023-7170 - Before 2 Plugin

The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-7170

MEDIUM CVSS 6.1 2024-01-22
Threat Entry Updated 2025-06-11

CVE-2023-5006 - Before 2 Plugin

The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request.

PLUGIN Before 2

CVE-2023-5006

MEDIUM CVSS 6.5 2024-01-17
Threat Entry Updated 2025-06-02

CVE-2024-0238 - Before 2 Plugin

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

PLUGIN Before 2

CVE-2024-0238

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2024-0233 - Before 2 Plugin

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2024-0233

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2024-0237 - Before 2 Plugin

The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc

PLUGIN Before 2

CVE-2024-0237

MEDIUM CVSS 5.3 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2024-0236 - Before 2 Plugin

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)

PLUGIN Before 2

CVE-2024-0236

MEDIUM CVSS 5.3 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2024-0235 - Before 2 Plugin

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

PLUGIN Before 2

CVE-2024-0235

MEDIUM CVSS 5.3 2024-01-16
Threat Entry Updated 2025-06-11

CVE-2023-6373 - Before 2 Plugin

The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the lack of CSRF check, the issue could also be exploited via a CSRF against a logged editor (or above)

PLUGIN Before 2

CVE-2023-6373

HIGH CVSS 8.8 2024-01-16
Threat Entry Updated 2025-06-13

CVE-2023-6046 - Before 2 Plugin

The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2023-6046

MEDIUM CVSS 4.8 2024-01-16
Scroll to top