Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 2881-2900 of 3408 records
Threat Entry Updated 2025-06-03

CVE-2023-7071 - Changeset Plugin

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and including, 4.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-7071

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-7048 - Changeset Plugin

The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.6. This is due to missing or incorrect nonce validation in mystickymenu-contact-leads.php. This makes it possible for unauthenticated attackers to trigger the export of a CSV file containing contact leads via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Because the CSV file is exported to a public location, it can be downloaded during a very short window…

PLUGIN Changeset

CVE-2023-7048

LOW CVSS 3.1 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-7019 - Changeset Plugin

The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to change page designs.

PLUGIN Changeset

CVE-2023-7019

MEDIUM CVSS 4.3 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6882 - Changeset Plugin

The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ parameter in all versions up to, and including, 4.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-6882

MEDIUM CVSS 6.1 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6924 - Changeset Plugin

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with administrator-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. It can also be exploited with a contributor-level permission with a page builder plugin.

PLUGIN Changeset

CVE-2023-6924

MEDIUM CVSS 4.4 2024-01-11
Threat Entry Updated 2025-06-04

CVE-2023-6875 - Changeset Plugin

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover.

PLUGIN Changeset

CVE-2023-6875

CRITICAL CVSS 9.8 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6855 - Changeset Plugin

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up to 2.12.5 (inclusive). This makes it possible for unauthenticated attackers to change membership levels including prices.

PLUGIN Changeset

CVE-2023-6855

MEDIUM CVSS 5.3 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6776 - Changeset Plugin

The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all versions up to, and including, 1.15.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-6776

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6684 - Changeset Plugin

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' shortcode in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on 'width' and 'height' user supplied attribute. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-6684

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6742 - Changeset Plugin

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_gallery_insert_images' function in all versions up to, and including, 1.8.7.1. This makes it possible for authenticated attackers, with contributor access and above, to modify galleries on other users' posts.

PLUGIN Changeset

CVE-2023-6742

MEDIUM CVSS 4.3 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6634 - Changeset Plugin

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.

PLUGIN Changeset

CVE-2023-6634

HIGH CVSS 8.1 2024-01-11
Threat Entry Updated 2025-06-10

CVE-2023-6636 - Changeset Plugin

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'gspb_save_files' function in versions up to, and including, 7.6.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Changeset

CVE-2023-6636

HIGH CVSS 7.2 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6637 - Changeset Plugin

The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_settings' function in versions up to, and including, 4.7.14. This makes it possible for unauthenticated attackers to update plugin settings.

PLUGIN Changeset

CVE-2023-6637

MEDIUM CVSS 6.5 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6567 - Changeset Plugin

The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Changeset

CVE-2023-6567

CRITICAL CVSS 9.8 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6558 - Changeset Plugin

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for authenticated attackers with shop manager-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Changeset

CVE-2023-6558

HIGH CVSS 7.2 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6583 - Changeset Plugin

The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary files on the server including wp-config.php, which can contain sensitive information.

PLUGIN Changeset

CVE-2023-6583

MEDIUM CVSS 6.6 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6582 - Changeset Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft, private or pending review status that should not be visible to the general public. This applies to posts created with Elementor only.

PLUGIN Changeset

CVE-2023-6582

MEDIUM CVSS 5.3 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6598 - Changeset Plugin

The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the speedycache_save_varniship, speedycache_img_update_settings, speedycache_preloading_add_settings, and speedycache_preloading_delete_resource functions in all versions up to, and including, 1.1.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to update plugin options.

PLUGIN Changeset

CVE-2023-6598

MEDIUM CVSS 4.3 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6316 - Changeset Plugin

The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Changeset

CVE-2023-6316

CRITICAL CVSS 9.8 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6369 - Changeset Plugin

The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 2.1.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose sensitive information or perform unauthorized actions, such as saving advanced plugin settings.

PLUGIN Changeset

CVE-2023-6369

MEDIUM CVSS 5.4 2024-01-11
Scroll to top