Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total65
Critical5
High14
Medium44
Reset
Showing 41-60 of 65 records
Threat Entry Updated 2024-11-21

CVE-2022-2376 - Before 7 Plugin

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

PLUGIN Before 7

CVE-2022-2376

MEDIUM CVSS 5.3 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2377 - Before 7 Plugin

The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog

PLUGIN Before 7

CVE-2022-2377

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2025-09-03

CVE-2022-2460 - Before 7 Plugin

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

PLUGIN Before 7

CVE-2022-2460

CRITICAL CVSS 9.8 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2046 - Before 7 Plugin

The Directorist WordPress plugin before 7.2.3 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets the zip files from. This could allow administrators to run code on the server, which is a problem in multisite configurations.

PLUGIN Before 7

CVE-2022-2046

MEDIUM CVSS 4.9 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2184 - Before 7 Plugin

The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server.

PLUGIN Before 7

CVE-2022-2184

HIGH CVSS 8.8 2022-08-01
Threat Entry Updated 2024-11-21

CVE-2022-1889 - Before 7 Plugin

The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed

PLUGIN Before 7

CVE-2022-1889

MEDIUM CVSS 4.8 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1756 - Before 7 Plugin

The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.

PLUGIN Before 7

CVE-2022-1756

MEDIUM CVSS 6.1 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1396 - Before 7 Plugin

The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed

PLUGIN Before 7

CVE-2022-1396

MEDIUM CVSS 4.8 2022-04-25
Threat Entry Updated 2025-03-17

CVE-2022-1153 - Before 7 Plugin

The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in various place, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Before 7

CVE-2022-1153

MEDIUM CVSS 4.8 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2021-24987 - Before 7 Plugin

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue.

PLUGIN Before 7

CVE-2021-24987

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0760 - Before 7 Plugin

The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

PLUGIN Before 7

CVE-2022-0760

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2021-24216 - Before 7 Plugin

The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.

PLUGIN Before 7

CVE-2021-24216

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-25034 - Before 7 Plugin

The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 7

CVE-2021-25034

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25093 - Before 7 Plugin

The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request

PLUGIN Before 7

CVE-2021-25093

HIGH CVSS 7.5 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25092 - Before 7 Plugin

The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack

PLUGIN Before 7

CVE-2021-25092

MEDIUM CVSS 6.5 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25091 - Before 7 Plugin

The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 7

CVE-2021-25091

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24944 - Before 7 Plugin

The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 7

CVE-2021-24944

MEDIUM CVSS 4.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24934 - Before 7 Plugin

The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 7

CVE-2021-24934

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24981 - Before 7 Plugin

The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.

PLUGIN Before 7

CVE-2021-24981

HIGH CVSS 7.5 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24822 - Before 7 Plugin

The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site Scripting attacks against logged in admin, as well as frontend users due to the lack of sanitisation and escaping in some parameters

PLUGIN Before 7

CVE-2021-24822

MEDIUM CVSS 5.4 2021-11-29
Scroll to top