Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total135
Critical12
High24
Medium97
Reset
Showing 81-100 of 135 records
Threat Entry Updated 2025-02-19

CVE-2023-1092 - Before 6 Plugin

The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack

PLUGIN Before 6

CVE-2023-1092

MEDIUM CVSS 6.5 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0816 - Before 6 Plugin

The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.

PLUGIN Before 6

CVE-2023-0816

MEDIUM CVSS 6.5 2023-03-27
Threat Entry Updated 2025-02-18

CVE-2023-1069 - Before 6 Plugin

The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 6

CVE-2023-1069

MEDIUM CVSS 5.4 2023-03-27
Threat Entry Updated 2025-04-23

CVE-2023-1400 - Before 6 Plugin

The Modern Events Calendar Lite WordPress plugin before 6.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 6

CVE-2023-1400

MEDIUM CVSS 4.8 2023-03-27
Threat Entry Updated 2025-02-26

CVE-2023-1025 - Before 6 Plugin

The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 6

CVE-2023-1025

MEDIUM CVSS 4.8 2023-03-27
Threat Entry Updated 2025-05-07

CVE-2022-3246 - Before 6 Plugin

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers

PLUGIN Before 6

CVE-2022-3246

HIGH CVSS 8.8 2022-10-25
Threat Entry Updated 2025-05-09

CVE-2022-3247 - Before 6 Plugin

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks

PLUGIN Before 6

CVE-2022-3247

MEDIUM CVSS 6.5 2022-10-25
Threat Entry Updated 2025-05-14

CVE-2022-3243 - Before 6 Plugin

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

PLUGIN Before 6

CVE-2022-3243

HIGH CVSS 7.2 2022-10-17
Threat Entry Updated 2025-05-13

CVE-2022-3244 - Before 6 Plugin

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce

PLUGIN Before 6

CVE-2022-3244

MEDIUM CVSS 4.2 2022-10-17
Threat Entry Updated 2024-11-21

CVE-2022-2361 - Before 6 Plugin

The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 6

CVE-2022-2361

MEDIUM CVSS 4.8 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-1251 - Before 6 Theme

The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.

THEME Before 6

CVE-2022-1251

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-1600 - Before 6 Plugin

The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

PLUGIN Before 6

CVE-2022-1600

MEDIUM CVSS 5.3 2022-08-01
Threat Entry Updated 2024-11-21

CVE-2022-2133 - Before 6 Plugin

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.

PLUGIN Before 6

CVE-2022-2133

MEDIUM CVSS 5.3 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2099 - Before 6 Plugin

The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

PLUGIN Before 6

CVE-2022-2099

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-1977 - Before 6 Plugin

The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

PLUGIN Before 6

CVE-2022-1977

HIGH CVSS 7.2 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1424 - Before 6 Theme

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.

THEME Before 6

CVE-2022-1424

MEDIUM CVSS 6.5 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1241 - Before 6 Theme

The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues

THEME Before 6

CVE-2022-1241

MEDIUM CVSS 6.1 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1436 - Before 6 Plugin

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number parameter before outputting it back in the page, which could allow attackers to perform reflected Cross-Site Scripting attacks.

PLUGIN Before 6

CVE-2022-1436

MEDIUM CVSS 6.1 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1435 - Before 6 Plugin

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Before 6

CVE-2022-1435

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1265 - Before 6 Plugin

The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 6

CVE-2022-1265

MEDIUM CVSS 4.8 2022-05-16
Scroll to top