Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 2941-2960 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2023-5234 - Changeset Plugin

The Related Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'woo-related' shortcode in versions up to, and including, 3.3.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-5234

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5096 - Changeset Plugin

The HTML filter and csv-file search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'csvsearch' shortcode in versions up to, and including, 2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-5096

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5314 - Changeset Plugin

The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capability check on the 'test-email' section of the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to send emails with arbitrary content to arbitrary locations from the affected site's mail server.

PLUGIN Changeset

CVE-2023-5314

MEDIUM CVSS 4.3 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-4686 - Changeset Plugin

The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.6.6 via the ajax_enabled_posts function. This can allow authenticated attackers to extract sensitive data such as post titles and slugs, including those of protected and trashed posts and pages in addition to other post types such as galleries.

PLUGIN Changeset

CVE-2023-4686

MEDIUM CVSS 4.3 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-4214 - Changeset Plugin

The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.

PLUGIN Changeset

CVE-2023-4214

HIGH CVSS 8.1 2023-11-18
Threat Entry Updated 2024-11-21

CVE-2023-6187 - Changeset Plugin

The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This can be exploited if 2Checkout (deprecated since version 2.6) or PayPal Express is set as the payment method and a custom user field is added that is only visible at profile, and…

PLUGIN Changeset

CVE-2023-6187

HIGH CVSS 7.5 2023-11-18
Threat Entry Updated 2024-11-21

CVE-2023-4602 - Changeset Plugin

The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-4602

MEDIUM CVSS 6.1 2023-11-15
Threat Entry Updated 2024-11-21

CVE-2023-6133 - Changeset Plugin

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary files on the affected site's server, but due to the htaccess configuration, remote code cannot be executed.

PLUGIN Changeset

CVE-2023-6133

MEDIUM CVSS 6.6 2023-11-15
Threat Entry Updated 2024-11-21

CVE-2023-4889 - Changeset Plugin

The Shareaholic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shareaholic' shortcode in versions up to, and including, 9.7.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-4889

MEDIUM CVSS 6.4 2023-11-15
Threat Entry Updated 2024-11-21

CVE-2023-6109 - Changeset Plugin

The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible for unauthenticated attackers to place multiple votes on a single poll even when the poll is set to one vote per person.

PLUGIN Changeset

CVE-2023-6109

MEDIUM CVSS 5.3 2023-11-14
Threat Entry Updated 2024-11-21

CVE-2023-4603 - Changeset Plugin

The Star CloudPRNT for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'printersettings' parameter in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-4603

MEDIUM CVSS 6.1 2023-11-13
Threat Entry Updated 2024-11-21

CVE-2023-4775 - Changeset Plugin

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-4775

MEDIUM CVSS 6.4 2023-11-13
Threat Entry Updated 2024-11-21

CVE-2023-5982 - Changeset Plugin

The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the instance_id on the 'updraftmethod-googledrive-auth' action used to update Google Drive remote storage location. This makes it possible for unauthenticated attackers to modify the Google Drive location that backups are sent to via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.…

PLUGIN Changeset

CVE-2023-5982

MEDIUM CVSS 5.4 2023-11-07
Threat Entry Updated 2024-11-21

CVE-2023-5703 - Changeset Plugin

The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'giftup' shortcode in all versions up to, and including, 2.20.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-5703

MEDIUM CVSS 6.4 2023-11-07
Threat Entry Updated 2024-11-21

CVE-2023-4888 - Changeset Plugin

The Simple Like Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sfp-page-plugin' shortcode in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-4888

MEDIUM CVSS 6.4 2023-11-07
Threat Entry Updated 2024-11-21

CVE-2023-4842 - Changeset Plugin

The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-4842

MEDIUM CVSS 6.4 2023-11-07
Threat Entry Updated 2024-11-21

CVE-2023-5076 - Changeset Plugin

The Ziteboard Online Whiteboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ziteboard' shortcode in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-5076

MEDIUM CVSS 6.4 2023-11-07
Threat Entry Updated 2024-11-21

CVE-2023-5946 - Changeset Plugin

The Digirisk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_group_id' parameter in version 6.0.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-5946

MEDIUM CVSS 6.1 2023-11-03
Threat Entry Updated 2024-11-21

CVE-2023-5707 - Changeset Plugin

The SEO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slider' shortcode and post meta in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-5707

MEDIUM CVSS 6.4 2023-11-03
Threat Entry Updated 2024-11-21

CVE-2023-5860 - Changeset Plugin

The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Changeset

CVE-2023-5860

HIGH CVSS 7.2 2023-11-02
Scroll to top