Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,198
Critical182
High652
Medium2,340
Reset
Showing 2941-2960 of 3198 records
Threat Entry Updated 2026-04-08

CVE-2021-4349 - Changeset Plugin

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2021-4349

HIGH CVSS 8.8 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4338 - Changeset Plugin

The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to view, create and edit redirections.

PLUGIN Changeset

CVE-2021-4338

MEDIUM CVSS 6.4 2023-06-07
Threat Entry Updated 2024-11-21

CVE-2023-2546 - Changeset Plugin

The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2. This is due to incorrect authentication checking in the 'wpus_allow_user_to_admin_bar_menu' function with the 'wpus_who_switch' cookie value. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator, if they have access to the username.

PLUGIN Changeset

CVE-2023-2546

HIGH CVSS 8.8 2023-06-06
Threat Entry Updated 2024-11-21

CVE-2023-2835 - Changeset Plugin

The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-2835

MEDIUM CVSS 6.1 2023-06-02
Threat Entry Updated 2024-11-21

CVE-2023-2836 - Changeset Plugin

The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Changeset

CVE-2023-2836

MEDIUM CVSS 4.4 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-2276 - Changeset Plugin

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.

PLUGIN Changeset

CVE-2023-2276

CRITICAL CVSS 9.8 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2736 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.8. This is due to missing nonce validation in the 'ajax_edit_contact' function. This makes it possible for authenticated attackers to receive the auto login link via shortcode and then modify the assigned user to the auto login link to elevate verified user privileges via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-2736

HIGH CVSS 7.5 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2717 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.8. This is due to missing nonce validation on the 'enable_safe_mode' function. This makes it possible for unauthenticated attackers to enable safe mode, which disables all other plugins, via a forged request if they can successfully trick an administrator into performing an action such as clicking on a link. A warning message about safe mode is displayed to the admin, which can be easily disabled.

PLUGIN Changeset

CVE-2023-2717

MEDIUM CVSS 5.4 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2716 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'ajax_upload_file' function in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload a file to the contact, and then lists all the other uploaded files related to the contact.

PLUGIN Changeset

CVE-2023-2716

MEDIUM CVSS 5.4 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2735 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gh_form' shortcode in versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Please note this only works with legacy contact forms.

PLUGIN Changeset

CVE-2023-2735

MEDIUM CVSS 4.9 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2715 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_ticket' function in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers to create a support ticket that sends the website's data to the plugin developer, and it is also possible to create an admin access with an auto login link that is also sent to the plugin developer with the ticket. It only works if the plugin is activated with a valid license.

PLUGIN Changeset

CVE-2023-2715

MEDIUM CVSS 4.3 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2714 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_license' functions in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the license key and support license key, but it can only be changed to a valid license key.

PLUGIN Changeset

CVE-2023-2714

MEDIUM CVSS 4.3 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-1931 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the deleteCssAndJsCacheToolbar function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to perform cache deletion.

PLUGIN Changeset

CVE-2023-1931

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1930 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the wpfc_clear_cache_of_allsites_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to delete caches.

PLUGIN Changeset

CVE-2023-1930

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1929 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_purgecache_varnish_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to purge the varnish cache.

PLUGIN Changeset

CVE-2023-1929

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1928 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_preload_single_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to initiate cache creation.

PLUGIN Changeset

CVE-2023-1928

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1927 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCssAndJsCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1927

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1926 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1926

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1925 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_clear_cache_of_allsites_callback function. This makes it possible for unauthenticated attackers to clear caches via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1925

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1924 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_toolbar_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1924

MEDIUM CVSS 4.3 2023-04-06
Scroll to top