Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 341-360 of 664 records
Threat Entry Updated 2024-11-21

CVE-2023-0219 - Before 2 Plugin

The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML.

PLUGIN Before 2

CVE-2023-0219

MEDIUM CVSS 5.4 2023-03-13
Threat Entry Updated 2025-02-27

CVE-2023-0844 - Before 2 Plugin

The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 2

CVE-2023-0844

MEDIUM CVSS 4.8 2023-03-13
Threat Entry Updated 2025-03-06

CVE-2023-0328 - Before 2 Plugin

The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).

PLUGIN Before 2

CVE-2023-0328

MEDIUM CVSS 4.3 2023-03-06
Threat Entry Updated 2025-03-10

CVE-2023-0487 - Before 2 Plugin

The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement when deleting messages, leading to a SQL injection exploitable by high privilege users such as admin

PLUGIN Before 2

CVE-2023-0487

HIGH CVSS 7.2 2023-02-27
Threat Entry Updated 2025-03-10

CVE-2023-0535 - Before 2 Plugin

The Donation Block For PayPal WordPress plugin before 2.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0535

MEDIUM CVSS 5.4 2023-02-27
Threat Entry Updated 2025-03-10

CVE-2023-0548 - Before 2 Plugin

The Namaste! LMS WordPress plugin before 2.5.9.4 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 2

CVE-2023-0548

MEDIUM CVSS 4.8 2023-02-27
Threat Entry Updated 2025-03-11

CVE-2023-0543 - Before 2 Plugin

The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2023-0543

MEDIUM CVSS 4.8 2023-02-27
Threat Entry Updated 2025-03-10

CVE-2023-0278 - Before 2 Plugin

The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Before 2

CVE-2023-0278

HIGH CVSS 7.2 2023-02-27
Threat Entry Updated 2025-03-12

CVE-2023-0232 - Before 2 Plugin

The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.

PLUGIN Before 2

CVE-2023-0232

CRITICAL CVSS 9.8 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0231 - Before 2 Plugin

The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0231

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2024-11-21

CVE-2023-0067 - Before 2 Plugin

The Timed Content WordPress plugin before 2.73 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0067

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-21

CVE-2023-0220 - Before 2 Plugin

The Pinpoint Booking System WordPress plugin before 2.9.9.2.9 does not validate and escape one of its shortcode attributes before using it in a SQL statement, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.

PLUGIN Before 2

CVE-2023-0220

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0151 - Before 2 Plugin

The uTubeVideo Gallery WordPress plugin before 2.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0151

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0060 - Before 2 Plugin

The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0060

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-25

CVE-2023-0236 - Before 2 Plugin

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-0236

MEDIUM CVSS 6.1 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0173 - Before 2 Plugin

The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0173

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0171 - Before 2 Plugin

The jQuery T(-) Countdown Widget WordPress plugin before 2.3.24 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0171

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0170 - Before 2 Plugin

The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0170

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0095 - Before 2 Plugin

The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0095

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0072 - Before 2 Plugin

The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0072

MEDIUM CVSS 5.4 2023-02-06
Scroll to top