Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 281-300 of 472 records
Threat Entry Updated 2025-05-14

CVE-2022-3151 - Before 3 Plugin

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.

PLUGIN Before 3

CVE-2022-3151

MEDIUM CVSS 4.3 2022-10-17
Threat Entry Updated 2024-11-21

CVE-2022-2823 - Before 3 Plugin

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its Gallery Image parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2022-2823

MEDIUM CVSS 4.8 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-2629 - Before 3 Plugin

The Top Bar WordPress plugin before 3.0.4 does not sanitise and escape some of its settings before outputting them in frontend pages, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2022-2629

MEDIUM CVSS 4.8 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-2839 - Before 3 Plugin

The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.

PLUGIN Before 3

CVE-2022-2839

MEDIUM CVSS 5.4 2022-10-03
Threat Entry Updated 2025-05-21

CVE-2022-3119 - Before 3 Plugin

The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address

PLUGIN Before 3

CVE-2022-3119

HIGH CVSS 7.5 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-2987 - Before 3 Plugin

The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers could set their own LDAP server to be used to authenticated users, therefore bypassing the current authentication

PLUGIN Before 3

CVE-2022-2987

HIGH CVSS 7.5 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2022-2903 - Before 3 Plugin

The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

PLUGIN Before 3

CVE-2022-2903

HIGH CVSS 7.2 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2022-2926 - Before 3 Plugin

The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory

PLUGIN Before 3

CVE-2022-2926

MEDIUM CVSS 4.9 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-3070 - Before 3 Plugin

The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2022-3070

MEDIUM CVSS 4.8 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-3069 - Before 3 Plugin

The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2022-3069

MEDIUM CVSS 4.8 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2021-24890 - Before 3 Plugin

The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file

PLUGIN Before 3

CVE-2021-24890

HIGH CVSS 8.8 2022-09-26
Threat Entry Updated 2024-11-21

CVE-2022-2840 - Before 3 Plugin

The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections

PLUGIN Before 3

CVE-2022-2840

CRITICAL CVSS 9.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-2958 - Before 3 Plugin

The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections

PLUGIN Before 3

CVE-2022-2958

HIGH CVSS 8.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-2635 - Before 3 Plugin

The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2022-2635

MEDIUM CVSS 4.8 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2657 - Before 3 Plugin

The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by WPScan when verifying the issue) for example. Other unauthenticated attacks are also possible, either directly or via CSRF

PLUGIN Before 3

CVE-2022-2657

MEDIUM CVSS 4.3 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2261 - Before 3 Plugin

The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.

PLUGIN Before 3

CVE-2022-2261

HIGH CVSS 7.2 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2537 - Before 3 Plugin

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.

PLUGIN Before 3

CVE-2022-2537

MEDIUM CVSS 6.1 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-1123 - Before 3 Plugin

The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitize some parameters before inserting them into SQL queries. As a result, high privilege users could perform SQL injection attacks.

PLUGIN Before 3

CVE-2022-1123

HIGH CVSS 7.2 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2532 - Before 3 Plugin

The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 3

CVE-2022-2532

MEDIUM CVSS 6.1 2022-08-22
Threat Entry Updated 2025-03-21

CVE-2022-2362 - Before 3 Plugin

The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.

PLUGIN Before 3

CVE-2022-2362

HIGH CVSS 7.5 2022-08-22
Scroll to top