Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 241-260 of 472 records
Threat Entry Updated 2024-11-21

CVE-2023-2398 - Before 3 Plugin

The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2023-2398

MEDIUM CVSS 6.1 2023-06-12
Threat Entry Updated 2025-05-05

CVE-2023-2362 - Before 3 Plugin

The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back in an attribute, leading to…

PLUGIN Before 3

CVE-2023-2362

MEDIUM CVSS 6.1 2023-06-12
Threat Entry Updated 2025-01-08

CVE-2023-2572 - Before 3 Plugin

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2023-2572

MEDIUM CVSS 6.1 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-2472 - Before 3 Plugin

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2023-2472

MEDIUM CVSS 6.1 2023-06-05
Threat Entry Updated 2025-04-23

CVE-2023-0329 - Before 3 Plugin

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

PLUGIN Before 3

CVE-2023-0329

HIGH CVSS 7.2 2023-05-30
Threat Entry Updated 2025-03-21

CVE-2023-1524 - Before 3 Plugin

The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.

PLUGIN Before 3

CVE-2023-1524

MEDIUM CVSS 6.5 2023-05-30
Threat Entry Updated 2025-01-09

CVE-2023-2023 - Before 3 Plugin

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

PLUGIN Before 3

CVE-2023-2023

MEDIUM CVSS 6.1 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2113 - Before 3 Plugin

The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export, allowing high privileged users (such as an administrator) to inject arbitrary javascript into the admin panel, even when the unfiltered_html capability is disabled, such as in a multisite setup.

PLUGIN Before 3

CVE-2023-2113

MEDIUM CVSS 4.8 2023-05-30
Threat Entry Updated 2025-01-14

CVE-2023-1835 - Before 3 Plugin

The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2023-1835

MEDIUM CVSS 6.1 2023-05-15
Threat Entry Updated 2025-01-30

CVE-2023-1730 - Before 3 Plugin

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

PLUGIN Before 3

CVE-2023-1730

CRITICAL CVSS 9.8 2023-05-02
Threat Entry Updated 2024-11-21

CVE-2023-1274 - Before 3 Plugin

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks

PLUGIN Before 3

CVE-2023-1274

MEDIUM CVSS 6.5 2023-04-17
Threat Entry Updated 2025-03-03

CVE-2023-0367 - Before 3 Plugin

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2023-0367

MEDIUM CVSS 5.4 2023-04-17
Threat Entry Updated 2025-02-11

CVE-2023-1478 - Before 3 Plugin

The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

PLUGIN Before 3

CVE-2023-1478

CRITICAL CVSS 9.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-1406 - Before 3 Plugin

The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.

PLUGIN Before 3

CVE-2023-1406

HIGH CVSS 8.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0874 - Before 3 Plugin

The Klaviyo WordPress plugin before 3.0.10 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2023-0874

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-14

CVE-2023-0399 - Before 3 Plugin

The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 3

CVE-2023-0399

MEDIUM CVSS 5.4 2023-04-03
Threat Entry Updated 2025-02-19

CVE-2023-0660 - Before 3 Plugin

The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2023-0660

MEDIUM CVSS 5.4 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0441 - Before 3 Plugin

The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a default administrator user role.

PLUGIN Before 3

CVE-2023-0441

HIGH CVSS 8.1 2023-03-27
Threat Entry Updated 2024-11-21

CVE-2023-0477 - Before 3 Plugin

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.

PLUGIN Before 3

CVE-2023-0477

HIGH CVSS 8.8 2023-03-13
Threat Entry Updated 2024-11-21

CVE-2023-0377 - Before 3 Plugin

The Scriptless Social Sharing WordPress plugin before 3.2.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 3

CVE-2023-0377

MEDIUM CVSS 5.4 2023-03-06
Scroll to top