Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,196
Critical182
High651
Medium2,339
Reset
Showing 2701-2720 of 3196 records
Threat Entry Updated 2024-11-21

CVE-2023-6971 - Changeset Plugin

The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability requires that the target server's php.ini is configured with 'allow_url_include' set to 'on'. This feature is deprecated as of PHP 7.4 and is disabled by default, but can still be explicitly enabled in later versions of PHP.

PLUGIN Changeset

CVE-2023-6971

HIGH CVSS 8.1 2023-12-23
Threat Entry Updated 2024-11-21

CVE-2023-6972 - Changeset Plugin

The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.

PLUGIN Changeset

CVE-2023-6972

HIGH CVSS 7.5 2023-12-23
Threat Entry Updated 2024-11-21

CVE-2023-7002 - Changeset Plugin

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.

PLUGIN Changeset

CVE-2023-7002

HIGH CVSS 7.2 2023-12-23
Threat Entry Updated 2024-11-21

CVE-2023-5432 - Changeset Plugin

The Jquery news ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jquery-news-ticker' shortcode in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-5432

MEDIUM CVSS 6.4 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-5413 - Changeset Plugin

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ihrss-gallery' shortcode in versions up to, and including, 13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-5413

MEDIUM CVSS 6.4 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-6559 - Changeset Plugin

The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.

PLUGIN Changeset

CVE-2023-6559

HIGH CVSS 7.5 2023-12-16
Threat Entry Updated 2024-11-21

CVE-2023-6827 - Changeset Plugin

The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFonts' function in versions up to, and including, 4.3.5. This makes it possible for authenticated attackers with subscriber-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Changeset

CVE-2023-6827

HIGH CVSS 7.5 2023-12-15
Threat Entry Updated 2024-11-21

CVE-2023-6826 - Changeset Plugin

The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1.20.25. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Changeset

CVE-2023-6826

HIGH CVSS 7.2 2023-12-15
Threat Entry Updated 2025-02-20

CVE-2023-6120 - Changeset Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 via the upload_certificate_file function. This makes it possible for administrators to upload .pem or .crt files to arbitrary locations on the server.

PLUGIN Changeset

CVE-2023-6120

MEDIUM CVSS 4.1 2023-12-09
Threat Entry Updated 2024-11-21

CVE-2023-6449 - Changeset Plugin

The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' function in versions up to, and including, 5.8.3. This makes it possible for authenticated attackers with editor-level capabilities or above to upload arbitrary files on the affected site's server, but due to the htaccess configuration, remote code cannot be executed in most cases. By default, the file will be deleted from the server immediately. However, in some cases, other plugins may…

PLUGIN Changeset

CVE-2023-6449

MEDIUM CVSS 6.6 2023-12-01
Threat Entry Updated 2024-11-21

CVE-2023-6219 - Changeset Plugin

The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'bookingpress_process_upload' function in versions up to, and including, 1.0.76. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Changeset

CVE-2023-6219

HIGH CVSS 7.2 2023-11-28
Threat Entry Updated 2024-11-21

CVE-2023-6160 - Changeset Plugin

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 7.4.2 via the maybe_serve_export function. This makes it possible for authenticated attackers, with administrator or LMS manager access and above, to read the contents of arbitrary CSV files on the server, which can contain sensitive information as well as removing those files from the server.

PLUGIN Changeset

CVE-2023-6160

LOW CVSS 3.3 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5706 - Changeset Plugin

The VK Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk-blocks/ancestor-page-list' block in all versions up to, and including, 1.63.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-5706

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5667 - Changeset Plugin

The Tab Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-5667

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5664 - Changeset Plugin

The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ggpkg' shortcode in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This was partially patched in version 2.2.7 and fully patched in version 2.2.9.

PLUGIN Changeset

CVE-2023-5664

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5469 - Changeset Plugin

The Drop Shadow Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dropshadowbox' shortcode in versions up to, and including, 1.7.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-5469

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5466 - Changeset Plugin

The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2023-5466

HIGH CVSS 8.8 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5465 - Changeset Plugin

The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2023-5465

HIGH CVSS 8.8 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5419 - Changeset Plugin

The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_test_mail function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to send test emails to an arbitrary email address.

PLUGIN Changeset

CVE-2023-5419

MEDIUM CVSS 4.3 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5417 - Changeset Plugin

The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_update_category function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the Funnelforms category for a given post ID.

PLUGIN Changeset

CVE-2023-5417

MEDIUM CVSS 4.3 2023-11-22
Scroll to top