Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 261-280 of 664 records
Threat Entry Updated 2025-04-23

CVE-2023-4823 - Before 2 Plugin

The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.

PLUGIN Before 2

CVE-2023-4823

MEDIUM CVSS 5.4 2023-10-31
Threat Entry Updated 2025-04-03

CVE-2023-4836 - Before 2 Plugin

The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced

PLUGIN Before 2

CVE-2023-4836

MEDIUM CVSS 4.3 2023-10-31
Threat Entry Updated 2025-04-23

CVE-2023-5133 - Before 2 Plugin

This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

PLUGIN Before 2

CVE-2023-5133

HIGH CVSS 7.5 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-5167 - Before 2 Plugin

The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-5167

MEDIUM CVSS 5.4 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-4776 - Before 2 Plugin

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

PLUGIN Before 2

CVE-2023-4776

HIGH CVSS 8.8 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-4805 - Before 2 Plugin

The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2023-4805

MEDIUM CVSS 5.4 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-4290 - Before 2 Plugin

The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting it in attributes, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-4290

MEDIUM CVSS 6.1 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-4289 - Before 2 Plugin

The WP Matterport Shortcode WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2023-4289

MEDIUM CVSS 5.4 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-4388 - Before 2 Plugin

The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2023-4388

MEDIUM CVSS 4.8 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-4521 - Before 2 Plugin

The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

PLUGIN Before 2

CVE-2023-4521

CRITICAL CVSS 9.8 2023-09-25
Threat Entry Updated 2025-04-23

CVE-2023-4490 - Before 2 Plugin

The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

PLUGIN Before 2

CVE-2023-4490

CRITICAL CVSS 9.8 2023-09-25
Threat Entry Updated 2025-04-23

CVE-2023-4300 - Before 2 Plugin

The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution.

PLUGIN Before 2

CVE-2023-4300

HIGH CVSS 7.2 2023-09-25
Threat Entry Updated 2025-04-22

CVE-2023-4238 - Before 2 Plugin

The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

PLUGIN Before 2

CVE-2023-4238

HIGH CVSS 7.2 2023-09-25
Threat Entry Updated 2025-04-23

CVE-2023-4281 - Before 2 Plugin

This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

PLUGIN Before 2

CVE-2023-4281

MEDIUM CVSS 5.3 2023-09-25
Threat Entry Updated 2025-04-23

CVE-2023-4376 - Before 2 Plugin

The Serial Codes Generator and Validator with WooCommerce Support WordPress plugin before 2.4.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2023-4376

MEDIUM CVSS 4.8 2023-09-19
Threat Entry Updated 2025-04-23

CVE-2023-4314 - Before 2 Plugin

The wpDataTables WordPress plugin before 2.1.66 does not validate the "Serialized PHP array" input data before deserializing the data. This allows admins to deserialize arbitrary data which may lead to remote code execution if a suitable gadget chain is present on the server. This is impactful in environments where admin users should not be allowed to execute arbitrary code, such as multisite.

PLUGIN Before 2

CVE-2023-4314

HIGH CVSS 7.2 2023-09-11
Threat Entry Updated 2025-03-06

CVE-2023-4284 - Before 2 Plugin

The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-4284

MEDIUM CVSS 6.1 2023-09-04
Threat Entry Updated 2024-11-21

CVE-2023-2813 - Before 2 Theme

All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite WordPress theme before 2.1, Cafe Bistro WordPress theme before 1.1.4, College WordPress theme before 1.5.1, Connections Reloaded WordPress theme through 3.1, Counterpoint WordPress theme through 1.8.1, Digitally WordPress theme through 1.0.8, Directory WordPress theme before 3.0.2, Drop WordPress theme before 1.22, Everse WordPress theme before 1.2.4, Fashionable…

THEME Before 2

CVE-2023-2813

MEDIUM CVSS 6.1 2023-09-04
Threat Entry Updated 2024-11-21

CVE-2023-1977 - Before 2 Plugin

The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.

PLUGIN Before 2

CVE-2023-1977

HIGH CVSS 8.8 2023-08-16
Threat Entry Updated 2024-11-21

CVE-2023-2123 - Before 2 Plugin

The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

PLUGIN Before 2

CVE-2023-2123

MEDIUM CVSS 6.1 2023-08-16
Scroll to top