Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total632
Critical40
High107
Medium472
Reset
Showing 321-340 of 632 records
Threat Entry Updated 2025-03-21

CVE-2023-0151 - Before 2 Plugin

The uTubeVideo Gallery WordPress plugin before 2.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0151

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0060 - Before 2 Plugin

The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0060

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-25

CVE-2023-0236 - Before 2 Plugin

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-0236

MEDIUM CVSS 6.1 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0173 - Before 2 Plugin

The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0173

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0171 - Before 2 Plugin

The jQuery T(-) Countdown Widget WordPress plugin before 2.3.24 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0171

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0170 - Before 2 Plugin

The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0170

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0095 - Before 2 Plugin

The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0095

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0072 - Before 2 Plugin

The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0072

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-04-21

CVE-2023-0097 - Before 2 Plugin

The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0097

MEDIUM CVSS 5.4 2023-01-30
Threat Entry Updated 2025-03-27

CVE-2023-0074 - Before 2 Plugin

The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0074

MEDIUM CVSS 5.4 2023-01-30
Threat Entry Updated 2025-03-27

CVE-2023-0071 - Before 2 Plugin

The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0071

MEDIUM CVSS 5.4 2023-01-30
Threat Entry Updated 2025-04-25

CVE-2021-25059 - Before 2 Plugin

The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.

PLUGIN Before 2

CVE-2021-25059

MEDIUM CVSS 4.3 2022-11-28
Threat Entry Updated 2025-05-06

CVE-2022-3374 - Before 2 Plugin

The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.

PLUGIN Before 2

CVE-2022-3374

HIGH CVSS 7.2 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3366 - Before 2 Plugin

The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.

PLUGIN Before 2

CVE-2022-3366

HIGH CVSS 7.2 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3440 - Before 2 Plugin

The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-3440

MEDIUM CVSS 6.1 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3441 - Before 2 Plugin

The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2022-3441

MEDIUM CVSS 4.8 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3237 - Before 2 Plugin

The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2022-3237

MEDIUM CVSS 4.8 2022-10-31
Threat Entry Updated 2025-05-08

CVE-2022-2762 - Before 2 Plugin

The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make a logged in admin update their notes via a CSRF attack

PLUGIN Before 2

CVE-2022-2762

MEDIUM CVSS 6.5 2022-10-25
Threat Entry Updated 2025-05-13

CVE-2022-3082 - Before 2 Plugin

The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example

PLUGIN Before 2

CVE-2022-3082

MEDIUM CVSS 6.5 2022-10-17
Threat Entry Updated 2025-05-13

CVE-2022-2563 - Before 2 Plugin

The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2022-2563

MEDIUM CVSS 4.8 2022-10-17
Scroll to top