Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total135
Critical12
High24
Medium97
Reset
Showing 61-80 of 135 records
Threat Entry Updated 2024-11-21

CVE-2023-6155 - Before 6 Plugin

The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.

PLUGIN Before 6

CVE-2023-6155

MEDIUM CVSS 5.3 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-6203 - Before 6 Plugin

The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request

PLUGIN Before 6

CVE-2023-6203

HIGH CVSS 7.5 2023-12-18
Threat Entry Updated 2025-05-27

CVE-2023-5907 - Before 6 Plugin

The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, where site administrators should not be allowed to modify the sites files.

PLUGIN Before 6

CVE-2023-5907

MEDIUM CVSS 6.5 2023-12-11
Threat Entry Updated 2025-03-24

CVE-2023-5355 - Before 6 Plugin

The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.

PLUGIN Before 6

CVE-2023-5355

HIGH CVSS 8.1 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-5354 - Before 6 Plugin

The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 6

CVE-2023-5354

MEDIUM CVSS 6.1 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-5352 - Before 6 Plugin

The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.

PLUGIN Before 6

CVE-2023-5352

MEDIUM CVSS 4.3 2023-11-06
Threat Entry Updated 2025-04-22

CVE-2023-5211 - Before 6 Plugin

The Fattura24 WordPress plugin before 6.2.8 does not sanitize or escape the 'id' parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting vulnerability.

PLUGIN Before 6

CVE-2023-5211

MEDIUM CVSS 6.1 2023-10-31
Threat Entry Updated 2025-04-23

CVE-2023-4971 - Before 6 Plugin

The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.

PLUGIN Before 6

CVE-2023-4971

HIGH CVSS 7.2 2023-10-16
Threat Entry Updated 2024-11-21

CVE-2023-2877 - Before 6 Plugin

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.

PLUGIN Before 6

CVE-2023-2877

HIGH CVSS 8.8 2023-06-27
Threat Entry Updated 2025-01-03

CVE-2023-1323 - Before 6 Plugin

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 6

CVE-2023-1323

MEDIUM CVSS 4.8 2023-06-12
Threat Entry Updated 2025-01-08

CVE-2023-2571 - Before 6 Plugin

The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 6

CVE-2023-2571

MEDIUM CVSS 6.1 2023-06-05
Threat Entry Updated 2025-01-10

CVE-2023-2518 - Before 6 Plugin

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 6

CVE-2023-2518

MEDIUM CVSS 6.1 2023-05-30
Threat Entry Updated 2026-03-06

CVE-2023-0600 - Before 6 Plugin

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

PLUGIN Before 6

CVE-2023-0600

CRITICAL CVSS 9.8 2023-05-15
Threat Entry Updated 2025-03-21

CVE-2023-1809 - Before 6 Plugin

The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.

PLUGIN Before 6

CVE-2023-1809

HIGH CVSS 7.5 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1669 - Before 6 Plugin

The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

PLUGIN Before 6

CVE-2023-1669

HIGH CVSS 7.2 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1525 - Before 6 Plugin

The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 6

CVE-2023-1525

MEDIUM CVSS 4.8 2023-05-02
Threat Entry Updated 2025-02-04

CVE-2023-1324 - Before 6 Plugin

The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 6

CVE-2023-1324

MEDIUM CVSS 6.1 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-0276 - Before 6 Plugin

The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 6

CVE-2023-0276

MEDIUM CVSS 5.4 2023-04-24
Threat Entry Updated 2025-03-05

CVE-2023-1325 - Before 6 Plugin

The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 6

CVE-2023-1325

MEDIUM CVSS 5.4 2023-04-17
Threat Entry Updated 2025-02-19

CVE-2023-1093 - Before 6 Plugin

The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack

PLUGIN Before 6

CVE-2023-1093

MEDIUM CVSS 6.5 2023-03-27
Scroll to top