Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 441-460 of 664 records
Threat Entry Updated 2024-11-21

CVE-2022-1465 - Before 2 Plugin

The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.

PLUGIN Before 2

CVE-2022-1465

MEDIUM CVSS 6.1 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1303 - Before 2 Plugin

The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow high privilege users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Before 2

CVE-2022-1303

MEDIUM CVSS 4.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-1273 - Before 2 Plugin

The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE

PLUGIN Before 2

CVE-2022-1273

HIGH CVSS 7.2 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0783 - Before 2 Plugin

The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections

PLUGIN Before 2

CVE-2022-0783

CRITICAL CVSS 9.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0876 - Before 2 Plugin

The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 2

CVE-2022-0876

MEDIUM CVSS 4.8 2022-04-25
Threat Entry Updated 2025-10-17

CVE-2022-1092 - Before 2 Plugin

The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog

PLUGIN Before 2

CVE-2022-1092

MEDIUM CVSS 4.3 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2022-0541 - Before 2 Plugin

The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.

PLUGIN Before 2

CVE-2022-0541

CRITICAL CVSS 9.8 2022-04-25
Threat Entry Updated 2025-10-17

CVE-2022-0363 - Before 2 Plugin

The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts.

PLUGIN Before 2

CVE-2022-0363

MEDIUM CVSS 4.3 2022-04-25
Threat Entry Updated 2025-10-17

CVE-2022-0287 - Before 2 Plugin

The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog

PLUGIN Before 2

CVE-2022-0287

MEDIUM CVSS 4.3 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2022-0765 - Before 2 Plugin

The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.

PLUGIN Before 2

CVE-2022-0765

MEDIUM CVSS 5.4 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1054 - Before 2 Plugin

The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user registered for events

PLUGIN Before 2

CVE-2022-1054

MEDIUM CVSS 5.3 2022-04-18
Threat Entry Updated 2025-02-07

CVE-2022-0706 - Before 2 Plugin

The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

PLUGIN Before 2

CVE-2022-0706

MEDIUM CVSS 4.8 2022-04-18
Threat Entry Updated 2025-02-07

CVE-2022-0707 - Before 2 Plugin

The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes, which could allow attackers to make a logged admin insert arbitrary notes via a CSRF attack

PLUGIN Before 2

CVE-2022-0707

MEDIUM CVSS 4.3 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-0447 - Before 2 Plugin

The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-0447

MEDIUM CVSS 6.4 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2021-25090 - Before 2 Plugin

The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform Cross-Site Scripting attacks on pages where a Portfolio is embed

PLUGIN Before 2

CVE-2021-25090

MEDIUM CVSS 5.4 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0728 - Before 2 Plugin

The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 2

CVE-2022-0728

MEDIUM CVSS 4.8 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2021-24986 - Before 2 Plugin

The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form

PLUGIN Before 2

CVE-2021-24986

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-1167 - Before 2 Theme

There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme before 2.3.1, via the filter parameters.

THEME Before 2

CVE-2022-1167

MEDIUM CVSS 6.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0958 - Before 2 Plugin

The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 2

CVE-2022-0958

MEDIUM CVSS 4.8 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0537 - Before 2 Plugin

The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet directory, and a .php file extension is added. No validation is performed on the content of the file, triggering an RCE vulnerability by uploading a web shell. Further the name parameter is not sanitized, allowing the payload to be uploaded to any directory to which the server has write…

PLUGIN Before 2

CVE-2022-0537

HIGH CVSS 7.2 2022-04-04
Scroll to top