Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 301-320 of 664 records
Threat Entry Updated 2024-11-21

CVE-2023-3133 - Before 2 Plugin

The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.

PLUGIN Before 2

CVE-2023-3133

HIGH CVSS 7.5 2023-07-04
Threat Entry Updated 2024-11-21

CVE-2023-2842 - Before 2 Plugin

The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack

PLUGIN Before 2

CVE-2023-2842

HIGH CVSS 8.1 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2601 - Before 2 Plugin

The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin via CSRF.

PLUGIN Before 2

CVE-2023-2601

CRITICAL CVSS 9.8 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2605 - Before 2 Plugin

The wpbrutalai WordPress plugin before 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

PLUGIN Before 2

CVE-2023-2605

MEDIUM CVSS 6.1 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-0588 - Before 2 Plugin

The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin.

PLUGIN Before 2

CVE-2023-0588

MEDIUM CVSS 6.1 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2178 - Before 2 Plugin

The Aajoda Testimonials WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 2

CVE-2023-2178

MEDIUM CVSS 4.8 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-0873 - Before 2 Plugin

The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2023-0873

MEDIUM CVSS 4.8 2023-06-27
Threat Entry Updated 2024-12-11

CVE-2023-2684 - Before 2 Plugin

The File Renaming on Upload WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2023-2684

MEDIUM CVSS 4.8 2023-06-19
Threat Entry Updated 2025-05-05

CVE-2023-2362 - Before 2 Plugin

The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back in an attribute, leading to…

PLUGIN Before 2

CVE-2023-2362

MEDIUM CVSS 6.1 2023-06-12
Threat Entry Updated 2025-01-08

CVE-2023-2337 - Before 2 Plugin

The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-2337

MEDIUM CVSS 6.1 2023-06-05
Threat Entry Updated 2025-01-10

CVE-2023-2288 - Before 2 Plugin

The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.

PLUGIN Before 2

CVE-2023-2288

HIGH CVSS 8.8 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2223 - Before 2 Plugin

The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 2

CVE-2023-2223

MEDIUM CVSS 4.8 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2287 - Before 2 Plugin

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

PLUGIN Before 2

CVE-2023-2287

MEDIUM CVSS 4.3 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2111 - Before 2 Plugin

The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL query without escaping it first in the plugin's report API endpoint, which could allow administrators in multi-site configuration to leak sensitive information from the site's database.

PLUGIN Before 2

CVE-2023-2111

MEDIUM CVSS 4.9 2023-05-30
Threat Entry Updated 2025-01-24

CVE-2023-1549 - Before 2 Plugin

The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

PLUGIN Before 2

CVE-2023-1549

HIGH CVSS 7.2 2023-05-15
Threat Entry Updated 2025-05-05

CVE-2023-1806 - Before 2 Plugin

The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.

PLUGIN Before 2

CVE-2023-1806

MEDIUM CVSS 6.1 2023-05-08
Threat Entry Updated 2025-01-29

CVE-2023-1905 - Before 2 Plugin

The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page shortcode before outputting it back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. This is due to an insufficient fix of CVE-2023-24003

PLUGIN Before 2

CVE-2023-1905

MEDIUM CVSS 5.4 2023-05-08
Threat Entry Updated 2025-02-04

CVE-2023-0948 - Before 2 Plugin

The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2023-0948

MEDIUM CVSS 6.1 2023-05-08
Threat Entry Updated 2025-01-30

CVE-2023-1805 - Before 2 Plugin

The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-1805

MEDIUM CVSS 6.1 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1804 - Before 2 Plugin

The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.

PLUGIN Before 2

CVE-2023-1804

MEDIUM CVSS 6.1 2023-05-02
Scroll to top