Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total153
Critical10
High27
Medium112
Reset
Showing 101-120 of 153 records
Threat Entry Updated 2024-11-21

CVE-2022-0428 - Before 5 Plugin

The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 5

CVE-2022-0428

MEDIUM CVSS 6.1 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0662 - Before 5 Plugin

The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 5

CVE-2022-0662

MEDIUM CVSS 4.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0649 - Before 5 Plugin

The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 5

CVE-2022-0649

MEDIUM CVSS 4.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1152 - Before 5 Plugin

The Menubar WordPress plugin before 5.8 does not sanitise and escape the command parameter before outputting it back in the response via the menubar AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting

PLUGIN Before 5

CVE-2022-1152

MEDIUM CVSS 5.4 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2022-0403 - Before 5 Plugin

The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders.

PLUGIN Before 5

CVE-2022-0403

HIGH CVSS 8.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0787 - Before 5 Plugin

The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections

PLUGIN Before 5

CVE-2022-0787

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0229 - Before 5 Plugin

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

PLUGIN Before 5

CVE-2022-0229

HIGH CVSS 8.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0590 - Before 5 Plugin

The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 5

CVE-2022-0590

MEDIUM CVSS 4.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0254 - Before 5 Plugin

The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection

PLUGIN Before 5

CVE-2022-0254

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0439 - Before 5 Plugin

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.

PLUGIN Before 5

CVE-2022-0439

HIGH CVSS 8.8 2022-03-07
Threat Entry Updated 2026-03-06

CVE-2022-0410 - Before 5 Plugin

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection

PLUGIN Before 5

CVE-2022-0410

HIGH CVSS 8.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0420 - Before 5 Plugin

The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks

PLUGIN Before 5

CVE-2022-0420

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0267 - Before 5 Plugin

The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection

PLUGIN Before 5

CVE-2022-0267

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2026-03-06

CVE-2021-25042 - Before 5 Plugin

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the lack of validation, sanitisation and escaping, users could set a malicious value and perform Cross-Site Scripting attacks against logged in admin

PLUGIN Before 5

CVE-2021-25042

MEDIUM CVSS 5.4 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25105 - Before 5 Plugin

The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 5

CVE-2021-25105

MEDIUM CVSS 4.8 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24993 - Before 5 Plugin

The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example

PLUGIN Before 5

CVE-2021-24993

MEDIUM CVSS 6.5 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2022-0320 - Before 5 Plugin

The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploaded files or other LFI to RCE techniques.

PLUGIN Before 5

CVE-2022-0320

CRITICAL CVSS 9.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24648 - Before 5 Plugin

The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before outputting back in an attribute, leading to a Reflected Cross-Site Scripting

PLUGIN Before 5

CVE-2021-24648

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24707 - Before 5 Plugin

The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, which could allow high privilege users to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 5

CVE-2021-24707

MEDIUM CVSS 4.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25028 - Before 5 Plugin

The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue

PLUGIN Before 5

CVE-2021-25028

MEDIUM CVSS 6.1 2022-01-24
Scroll to top