Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 221-240 of 472 records
Threat Entry Updated 2024-11-21

CVE-2023-3650 - Before 3 Plugin

The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

PLUGIN Before 3

CVE-2023-3650

MEDIUM CVSS 4.8 2023-08-07
Threat Entry Updated 2025-04-23

CVE-2023-3245 - Before 3 Plugin

The Floating Chat Widget WordPress plugin before 3.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2023-3245

MEDIUM CVSS 4.8 2023-07-17
Threat Entry Updated 2024-11-21

CVE-2023-3182 - Before 3 Plugin

The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2023-3182

MEDIUM CVSS 6.1 2023-07-17
Threat Entry Updated 2024-11-21

CVE-2023-3131 - Before 3 Plugin

The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.

PLUGIN Before 3

CVE-2023-3131

MEDIUM CVSS 4.3 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-3209 - Before 3 Plugin

The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.

PLUGIN Before 3

CVE-2023-3209

LOW CVSS 3.5 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-3077 - Before 3 Plugin

The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins' pro features, and uses the woocommerce-appointments plugin.

PLUGIN Before 3

CVE-2023-3077

CRITICAL CVSS 9.8 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-3076 - Before 3 Plugin

The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.

PLUGIN Before 3

CVE-2023-3076

CRITICAL CVSS 9.8 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-2578 - Before 3 Plugin

The Buy Me a Coffee WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2023-2578

MEDIUM CVSS 4.8 2023-07-10
Threat Entry Updated 2025-01-06

CVE-2023-1119 - Before 3 Plugin

The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.

PLUGIN Before 3

CVE-2023-1119

MEDIUM CVSS 6.1 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-2321 - Before 3 Plugin

The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2023-2321

MEDIUM CVSS 6.1 2023-07-04
Threat Entry Updated 2024-11-21

CVE-2023-2628 - Before 3 Plugin

The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc, create/update various users (patients, doctors etc)

PLUGIN Before 3

CVE-2023-2628

HIGH CVSS 8.8 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2624 - Before 3 Plugin

The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator

PLUGIN Before 3

CVE-2023-2624

MEDIUM CVSS 6.1 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2627 - Before 3 Plugin

The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings

PLUGIN Before 3

CVE-2023-2627

MEDIUM CVSS 4.3 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2032 - Before 3 Plugin

The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Injection vulnerabilities.

PLUGIN Before 3

CVE-2023-2032

CRITICAL CVSS 9.8 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2592 - Before 3 Plugin

The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Before 3

CVE-2023-2592

HIGH CVSS 7.2 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2623 - Before 3 Plugin

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users

PLUGIN Before 3

CVE-2023-2623

MEDIUM CVSS 6.5 2023-06-27
Threat Entry Updated 2024-12-12

CVE-2023-2719 - Before 3 Plugin

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.

PLUGIN Before 3

CVE-2023-2719

HIGH CVSS 8.8 2023-06-19
Threat Entry Updated 2024-11-21

CVE-2023-2805 - Before 3 Plugin

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Before 3

CVE-2023-2805

HIGH CVSS 7.2 2023-06-19
Threat Entry Updated 2024-11-21

CVE-2023-2812 - Before 3 Plugin

The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2023-2812

MEDIUM CVSS 4.8 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2221 - Before 3 Plugin

The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

PLUGIN Before 3

CVE-2023-2221

HIGH CVSS 7.2 2023-06-19
Scroll to top