Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 261-280 of 472 records
Threat Entry Updated 2025-03-10

CVE-2023-0334 - Before 3 Plugin

The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin

PLUGIN Before 3

CVE-2023-0334

MEDIUM CVSS 6.1 2023-02-27
Threat Entry Updated 2025-03-18

CVE-2023-0552 - Before 3 Plugin

The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability

PLUGIN Before 3

CVE-2023-0552

MEDIUM CVSS 5.4 2023-02-27
Threat Entry Updated 2025-03-10

CVE-2023-0279 - Before 3 Plugin

The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Before 3

CVE-2023-0279

HIGH CVSS 7.2 2023-02-27
Threat Entry Updated 2025-03-12

CVE-2023-0428 - Before 3 Plugin

The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 3

CVE-2023-0428

MEDIUM CVSS 6.1 2023-02-21
Threat Entry Updated 2025-03-14

CVE-2023-0380 - Before 3 Plugin

The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 3

CVE-2023-0380

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0375 - Before 3 Plugin

The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 3

CVE-2023-0375

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0429 - Before 3 Plugin

The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2023-0429

MEDIUM CVSS 4.8 2023-02-21
Threat Entry Updated 2025-03-21

CVE-2023-0262 - Before 3 Plugin

The WP Airbnb Review Slider WordPress plugin before 3.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

PLUGIN Before 3

CVE-2023-0262

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0333 - Before 3 Plugin

The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using them to generate an HTML tag, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2023-0333

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0169 - Before 3 Plugin

The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 3

CVE-2023-0169

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-25

CVE-2023-0252 - Before 3 Plugin

The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2023-0252

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-26

CVE-2023-0144 - Before 3 Plugin

The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 3

CVE-2023-0144

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-04-02

CVE-2021-24881 - Before 3 Plugin

The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.

PLUGIN Before 3

CVE-2021-24881

HIGH CVSS 7.5 2023-01-23
Threat Entry Updated 2024-11-21

CVE-2021-24837 - Before 3 Plugin

The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

PLUGIN Before 3

CVE-2021-24837

MEDIUM CVSS 5.4 2023-01-23
Threat Entry Updated 2025-04-30

CVE-2021-24649 - Before 3 Plugin

The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary file access issue for example, or if the blog is using the default keys) to create an account with any role they want, such as admin

PLUGIN Before 3

CVE-2021-24649

CRITICAL CVSS 9.8 2022-11-21
Threat Entry Updated 2025-05-06

CVE-2022-3357 - Before 3 Plugin

The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues when a user import (intentionally or not) a malicious file, and a suitable gadget chain is present on the site.

PLUGIN Before 3

CVE-2022-3357

HIGH CVSS 8.8 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3420 - Before 3 Plugin

The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 3

CVE-2022-3420

MEDIUM CVSS 4.8 2022-10-31
Threat Entry Updated 2025-05-14

CVE-2022-3150 - Before 3 Plugin

The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin

PLUGIN Before 3

CVE-2022-3150

HIGH CVSS 7.2 2022-10-17
Threat Entry Updated 2025-05-14

CVE-2022-3149 - Before 3 Plugin

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could also lead to Stored Cross-Site Scripting

PLUGIN Before 3

CVE-2022-3149

MEDIUM CVSS 6.1 2022-10-17
Threat Entry Updated 2025-05-14

CVE-2022-3206 - Before 3 Plugin

The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

PLUGIN Before 3

CVE-2022-3206

MEDIUM CVSS 5.9 2022-10-17
Scroll to top