Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total153
Critical10
High27
Medium112
Reset
Showing 81-100 of 153 records
Threat Entry Updated 2024-11-21

CVE-2022-2271 - Before 5 Plugin

The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 5

CVE-2022-2271

MEDIUM CVSS 4.8 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2594 - Before 5 Plugin

The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release.

PLUGIN Before 5

CVE-2022-2594

HIGH CVSS 8.8 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2407 - Before 5 Plugin

The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 5

CVE-2022-2407

MEDIUM CVSS 4.8 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2198 - Before 5 Plugin

The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read other users private message using the message id, which can easily be brute forced.

PLUGIN Before 5

CVE-2022-2198

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-1323 - Before 5 Theme

The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.

THEME Before 5

CVE-2022-1323

MEDIUM CVSS 6.5 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-1933 - Before 5 Plugin

The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

PLUGIN Before 5

CVE-2022-1933

MEDIUM CVSS 6.1 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2144 - Before 5 Plugin

The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack

PLUGIN Before 5

CVE-2022-2144

MEDIUM CVSS 4.3 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-1321 - Before 5 Plugin

The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

PLUGIN Before 5

CVE-2022-1321

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1095 - Before 5 Plugin

The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 5

CVE-2022-1095

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1610 - Before 5 Plugin

The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Before 5

CVE-2022-1610

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-0663 - Before 5 Plugin

The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text settings, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 5

CVE-2022-0663

MEDIUM CVSS 4.8 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1422 - Before 5 Theme

The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.

THEME Before 5

CVE-2022-1422

MEDIUM CVSS 6.5 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1597 - Before 5 Plugin

The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a parameter on its reset password form which makes it possible to perform Reflected Cross-Site Scripting attacks

PLUGIN Before 5

CVE-2022-1597

MEDIUM CVSS 6.1 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1598 - Before 5 Plugin

The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.

PLUGIN Before 5

CVE-2022-1598

MEDIUM CVSS 5.3 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1421 - Before 5 Theme

The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

THEME Before 5

CVE-2022-1421

MEDIUM CVSS 4.3 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1568 - Before 5 Plugin

The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 5

CVE-2022-1568

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1425 - Before 5 Plugin

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of the wpqa_message_view ajax action belongs to the requesting user, leading to any user being able to read messages for any other users via a Insecure Direct Object Reference (IDOR) vulnerability.

PLUGIN Before 5

CVE-2022-1425

MEDIUM CVSS 4.3 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1349 - Before 5 Plugin

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to the requesting user, allowing any users (with privileges as low as Subscriber) to delete the profile pictures of any other user.

PLUGIN Before 5

CVE-2022-1349

MEDIUM CVSS 4.3 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1051 - Before 5 Plugin

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks.

PLUGIN Before 5

CVE-2022-1051

MEDIUM CVSS 5.4 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-0771 - Before 5 Plugin

The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections

PLUGIN Before 5

CVE-2022-0771

CRITICAL CVSS 9.8 2022-05-02
Scroll to top