Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 341-360 of 472 records
Threat Entry Updated 2024-11-21

CVE-2022-1165 - Before 3 Plugin

The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots. This could also be abused by competitors to cause damage related to visibility in search engines, can be used to bypass arbitrary blocks caused by this plugin, block any visitor or even the administrator and even more.

PLUGIN Before 3

CVE-2022-1165

CRITICAL CVSS 9.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0887 - Before 3 Plugin

The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.

PLUGIN Before 3

CVE-2022-0887

HIGH CVSS 7.2 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0884 - Before 3 Plugin

The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 3

CVE-2022-0884

MEDIUM CVSS 4.8 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0641 - Before 3 Plugin

The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Before 3

CVE-2022-0641

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0833 - Before 3 Plugin

The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible temporary file generated by the plugin in order to disclose the final backup filename, which can then be fetched by the attacker to download the backup of the plugin's DB data

PLUGIN Before 3

CVE-2022-0833

MEDIUM CVSS 4.3 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2021-24746 - Before 3 Plugin

The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.

PLUGIN Before 3

CVE-2021-24746

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0450 - Before 3 Plugin

The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber can update the settings or arbitrary menu and put Cross-Site Scripting payloads in them which will be triggered in the related menu in the frontend

PLUGIN Before 3

CVE-2022-0450

MEDIUM CVSS 5.4 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0628 - Before 3 Plugin

The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Before 3

CVE-2022-0628

MEDIUM CVSS 6.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0591 - Before 3 Plugin

The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

PLUGIN Before 3

CVE-2022-0591

CRITICAL CVSS 9.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0684 - Before 3 Plugin

The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 3

CVE-2022-0684

MEDIUM CVSS 4.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0478 - Before 3 Plugin

The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks

PLUGIN Before 3

CVE-2022-0478

HIGH CVSS 8.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0321 - Before 3 Plugin

The WP Voting Contest WordPress plugin before 3.0 does not sanitise and escape the post_id parameter before outputting it back in the response via the wpvc_social_share_icons AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 3

CVE-2022-0321

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24692 - Before 3 Plugin

The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

PLUGIN Before 3

CVE-2021-24692

MEDIUM CVSS 6.5 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0533 - Before 3 Plugin

The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

PLUGIN Before 3

CVE-2022-0533

MEDIUM CVSS 6.1 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0384 - Before 3 Plugin

The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog

PLUGIN Before 3

CVE-2022-0384

MEDIUM CVSS 4.3 2022-03-07
Threat Entry Updated 2025-03-21

CVE-2021-25087 - Before 3 Plugin

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

PLUGIN Before 3

CVE-2021-25087

HIGH CVSS 7.5 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24810 - Before 3 Plugin

The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 3

CVE-2021-24810

MEDIUM CVSS 4.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-25010 - Before 3 Plugin

The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues

PLUGIN Before 3

CVE-2021-25010

CRITICAL CVSS 9.6 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24971 - Before 3 Plugin

The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authenticated, such as subscriber could update the plugin's settings and perform Cross-Site Scripting attacks against all visitor and users on the frontend

PLUGIN Before 3

CVE-2021-24971

MEDIUM CVSS 5.4 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24823 - Before 3 Plugin

The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

PLUGIN Before 3

CVE-2021-24823

HIGH CVSS 8.1 2022-02-28
Scroll to top