Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total291
Critical15
High59
Medium208
Reset
Showing 121-140 of 291 records
Threat Entry Updated 2025-06-03

CVE-2023-6139 - Before 4 Plugin

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.

PLUGIN Before 4

CVE-2023-6139

MEDIUM CVSS 6.5 2024-01-08
Threat Entry Updated 2025-06-18

CVE-2023-6000 - Before 4 Plugin

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

PLUGIN Before 4

CVE-2023-6000

MEDIUM CVSS 6.1 2024-01-01
Threat Entry Updated 2024-11-21

CVE-2023-5991 - Before 4 Plugin

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

PLUGIN Before 4

CVE-2023-5991

CRITICAL CVSS 9.8 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5931 - Before 4 Plugin

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server

PLUGIN Before 4

CVE-2023-5931

HIGH CVSS 8.8 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-6114 - Before 4 Plugin

The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.

PLUGIN Before 4

CVE-2023-6114

HIGH CVSS 7.5 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5939 - Before 4 Plugin

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users.

PLUGIN Before 4

CVE-2023-5939

HIGH CVSS 7.2 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5884 - Before 4 Plugin

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.

PLUGIN Before 4

CVE-2023-5884

MEDIUM CVSS 6.5 2023-12-04
Threat Entry Updated 2024-11-21

CVE-2023-5620 - Before 4 Plugin

The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.

PLUGIN Before 4

CVE-2023-5620

MEDIUM CVSS 5.4 2023-11-27
Threat Entry Updated 2025-04-23

CVE-2023-5003 - Before 4 Plugin

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.

PLUGIN Before 4

CVE-2023-5003

HIGH CVSS 7.5 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-5089 - Before 4 Plugin

The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.

PLUGIN Before 4

CVE-2023-5089

MEDIUM CVSS 5.3 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-4811 - Before 4 Plugin

The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 4

CVE-2023-4811

MEDIUM CVSS 5.4 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-4643 - Before 4 Plugin

The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog

PLUGIN Before 4

CVE-2023-4643

HIGH CVSS 8.8 2023-10-16
Threat Entry Updated 2024-11-21

CVE-2023-3226 - Before 4 Plugin

The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2023-3226

MEDIUM CVSS 4.8 2023-09-25
Threat Entry Updated 2025-05-02

CVE-2023-4270 - Before 4 Plugin

The Min Max Control WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 4

CVE-2023-4270

MEDIUM CVSS 6.1 2023-09-11
Threat Entry Updated 2024-11-21

CVE-2023-3169 - Before 4 Plugin

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 4

CVE-2023-3169

MEDIUM CVSS 6.1 2023-09-11
Threat Entry Updated 2024-11-21

CVE-2023-3170 - Before 4 Plugin

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not validate and escape some settings, which could allow users with Admin privileges to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 4

CVE-2023-3170

MEDIUM CVSS 4.8 2023-09-11
Threat Entry Updated 2025-05-12

CVE-2023-4254 - Before 4 Plugin

The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 4

CVE-2023-4254

MEDIUM CVSS 4.8 2023-09-04
Threat Entry Updated 2025-05-12

CVE-2023-4253 - Before 4 Plugin

The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 4

CVE-2023-4253

MEDIUM CVSS 4.8 2023-09-04
Threat Entry Updated 2025-04-23

CVE-2023-4013 - Before 4 Plugin

The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks

PLUGIN Before 4

CVE-2023-4013

MEDIUM CVSS 6.5 2023-08-30
Threat Entry Updated 2025-04-23

CVE-2023-4150 - Before 4 Plugin

The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks

PLUGIN Before 4

CVE-2023-4150

MEDIUM CVSS 4.3 2023-08-30
Scroll to top