Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 281-300 of 664 records
Threat Entry Updated 2024-11-21

CVE-2023-1110 - Before 2 Plugin

The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2023-1110

MEDIUM CVSS 5.4 2023-08-16
Threat Entry Updated 2026-01-14

CVE-2023-0274 - Before 2 Plugin

The URL Params WordPress plugin before 2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0274

MEDIUM CVSS 5.4 2023-08-16
Threat Entry Updated 2025-05-05

CVE-2023-3721 - Before 2 Plugin

The WP-EMail WordPress plugin before 2.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2023-3721

MEDIUM CVSS 4.8 2023-08-14
Threat Entry Updated 2024-11-21

CVE-2023-3645 - Before 2 Plugin

The Contact Form Builder by Bit Form WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2023-3645

MEDIUM CVSS 4.8 2023-08-14
Threat Entry Updated 2024-11-21

CVE-2023-2606 - Before 2 Plugin

The WP Brutal AI WordPress plugin before 2.06 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 2

CVE-2023-2606

MEDIUM CVSS 4.8 2023-08-14
Threat Entry Updated 2025-05-05

CVE-2023-3601 - Before 2 Plugin

The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.

PLUGIN Before 2

CVE-2023-3601

MEDIUM CVSS 4.3 2023-08-14
Threat Entry Updated 2025-05-05

CVE-2023-3524 - Before 2 Plugin

The WPCode WordPress plugin before 2.0.13.1 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2023-3524

MEDIUM CVSS 6.1 2023-08-07
Threat Entry Updated 2025-04-23

CVE-2023-3508 - Before 2 Plugin

The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete or cancel via CSRF attacks

PLUGIN Before 2

CVE-2023-3508

MEDIUM CVSS 6.5 2023-07-31
Threat Entry Updated 2025-04-23

CVE-2023-3507 - Before 2 Plugin

The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack

PLUGIN Before 2

CVE-2023-3507

MEDIUM CVSS 6.5 2023-07-31
Threat Entry Updated 2024-11-21

CVE-2023-3292 - Before 2 Plugin

The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-3292

MEDIUM CVSS 6.1 2023-07-31
Threat Entry Updated 2024-11-21

CVE-2023-2309 - Before 2 Plugin

The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.

PLUGIN Before 2

CVE-2023-2309

MEDIUM CVSS 6.1 2023-07-24
Threat Entry Updated 2025-04-23

CVE-2023-3248 - Before 2 Plugin

The All-in-one Floating Contact Form WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2023-3248

MEDIUM CVSS 4.8 2023-07-24
Threat Entry Updated 2025-06-04

CVE-2023-3179 - Before 2 Plugin

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability resend an email to an arbitrary address (for example a password reset email could be resent to an attacker controlled email, and allow them to take over an account).

PLUGIN Before 2

CVE-2023-3179

HIGH CVSS 8.8 2023-07-17
Threat Entry Updated 2024-11-21

CVE-2023-2701 - Before 2 Plugin

The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.

PLUGIN Before 2

CVE-2023-2701

MEDIUM CVSS 6.1 2023-07-17
Threat Entry Updated 2024-11-21

CVE-2023-3219 - Before 2 Plugin

The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.

PLUGIN Before 2

CVE-2023-3219

MEDIUM CVSS 5.3 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-2493 - Before 2 Plugin

The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Before 2

CVE-2023-2493

HIGH CVSS 7.2 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-2796 - Before 2 Plugin

The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.

PLUGIN Before 2

CVE-2023-2796

MEDIUM CVSS 5.3 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-1597 - Before 2 Plugin

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.

PLUGIN Before 2

CVE-2023-1597

HIGH CVSS 8.8 2023-07-10
Threat Entry Updated 2025-01-06

CVE-2023-1119 - Before 2 Plugin

The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.

PLUGIN Before 2

CVE-2023-1119

MEDIUM CVSS 6.1 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-3460 - Before 2 Plugin

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

PLUGIN Before 2

CVE-2023-3460

CRITICAL CVSS 9.8 2023-07-04
Scroll to top