Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 381-400 of 664 records
Threat Entry Updated 2024-11-21

CVE-2022-2799 - Before 2 Plugin

The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2022-2799

MEDIUM CVSS 4.8 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2798 - Before 2 Plugin

The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data

PLUGIN Before 2

CVE-2022-2798

HIGH CVSS 8.0 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2655 - Before 2 Plugin

The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-2655

MEDIUM CVSS 6.1 2022-09-16
Threat Entry Updated 2025-06-05

CVE-2022-2654 - Before 2 Theme

The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting

THEME Before 2

CVE-2022-2654

MEDIUM CVSS 6.1 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2737 - Before 2 Plugin

The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2022-2737

MEDIUM CVSS 4.8 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2351 - Before 2 Plugin

The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2022-2351

MEDIUM CVSS 4.8 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2543 - Before 2 Plugin

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts

PLUGIN Before 2

CVE-2022-2543

MEDIUM CVSS 6.1 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2597 - Before 2 Plugin

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts

PLUGIN Before 2

CVE-2022-2597

MEDIUM CVSS 5.4 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2267 - Before 2 Plugin

The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

PLUGIN Before 2

CVE-2022-2267

MEDIUM CVSS 4.3 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2556 - Before 2 Plugin

The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

PLUGIN Before 2

CVE-2022-2556

LOW CVSS 2.7 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2558 - Before 2 Plugin

The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing of uploaded resumes in certain configurations.

PLUGIN Before 2

CVE-2022-2558

MEDIUM CVSS 5.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2388 - Before 2 Plugin

The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack

PLUGIN Before 2

CVE-2022-2388

MEDIUM CVSS 6.5 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2389 - Before 2 Plugin

The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to create automations

PLUGIN Before 2

CVE-2022-2389

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2382 - Before 2 Plugin

The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.

PLUGIN Before 2

CVE-2022-2382

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-0446 - Before 2 Plugin

The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2022-0446

MEDIUM CVSS 4.8 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2354 - Before 2 Plugin

The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.

PLUGIN Before 2

CVE-2022-2354

HIGH CVSS 7.2 2022-08-15
Threat Entry Updated 2024-11-21

CVE-2022-2152 - Before 2 Plugin

The Duplicate Page and Post WordPress plugin before 2.8 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2022-2152

MEDIUM CVSS 4.8 2022-08-15
Threat Entry Updated 2024-11-21

CVE-2022-2372 - Before 2 Plugin

The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2022-2372

MEDIUM CVSS 4.8 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2371 - Before 2 Plugin

The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.

PLUGIN Before 2

CVE-2022-2371

MEDIUM CVSS 5.4 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2370 - Before 2 Plugin

The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them

PLUGIN Before 2

CVE-2022-2370

MEDIUM CVSS 6.5 2022-08-01
Scroll to top