Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 401-420 of 664 records
Threat Entry Updated 2024-11-21

CVE-2022-2369 - Before 2 Plugin

The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin

PLUGIN Before 2

CVE-2022-2369

MEDIUM CVSS 4.3 2022-08-01
Threat Entry Updated 2024-11-21

CVE-2022-2260 - Before 2 Plugin

The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dates, which could allow attackers to make a logged in admin DoS the web server via a CSRF attack as the plugin will try to retrieve data from the database many times which leads to overwhelm the target's CPU.

PLUGIN Before 2

CVE-2022-2260

MEDIUM CVSS 6.5 2022-08-01
Threat Entry Updated 2024-11-21

CVE-2022-2215 - Before 2 Plugin

The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2022-2215

MEDIUM CVSS 4.8 2022-08-01
Threat Entry Updated 2024-11-21

CVE-2022-2219 - Before 2 Plugin

The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-2219

HIGH CVSS 7.2 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-2115 - Before 2 Plugin

The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-2115

MEDIUM CVSS 6.1 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-2239 - Before 2 Plugin

The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2022-2239

MEDIUM CVSS 4.8 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-2194 - Before 2 Plugin

The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2022-2194

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2021-24655 - Before 2 Plugin

The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.

PLUGIN Before 2

CVE-2021-24655

HIGH CVSS 7.5 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2090 - Before 2 Plugin

The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back in an attribute of the plugin's discount rule page, leading to Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-2090

MEDIUM CVSS 6.1 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2092 - Before 2 Plugin

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks.

PLUGIN Before 2

CVE-2022-2092

MEDIUM CVSS 6.1 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-2050 - Before 2 Plugin

The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when unfiltered_html is disallowed

PLUGIN Before 2

CVE-2022-2050

MEDIUM CVSS 4.8 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1599 - Before 2 Plugin

The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.

PLUGIN Before 2

CVE-2022-1599

MEDIUM CVSS 6.5 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1576 - Before 2 Plugin

The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack

PLUGIN Before 2

CVE-2022-1576

MEDIUM CVSS 6.5 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1951 - Before 2 Plugin

The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputting them back in a response of an AJAX action, available to both unauthenticated and authenticated users when a premium theme from the vendor is active, leading to a Reflected Cross-Site Scripting.

PLUGIN Before 2

CVE-2022-1951

MEDIUM CVSS 6.1 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1910 - Before 2 Plugin

The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-1910

MEDIUM CVSS 6.1 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1757 - Before 2 Plugin

The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation in some of them, it could also lead to Stored XSS issues

PLUGIN Before 2

CVE-2022-1757

MEDIUM CVSS 5.4 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1946 - Before 2 Plugin

The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2022-1946

MEDIUM CVSS 6.1 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2022-0250 - Before 2 Plugin

The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-0250

MEDIUM CVSS 6.1 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2022-1301 - Before 2 Plugin

The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Before 2

CVE-2022-1301

MEDIUM CVSS 4.8 2022-07-04
Threat Entry Updated 2025-01-16

CVE-2022-2041 - Before 2 Plugin

The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2022-2041

MEDIUM CVSS 5.4 2022-06-27
Scroll to top