Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,198
Critical182
High652
Medium2,340
Reset
Showing 2961-2980 of 3198 records
Threat Entry Updated 2024-11-21

CVE-2023-1923 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_remove_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1923

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1922 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_pause_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1922

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1921 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_start_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1921

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1920 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_purgecache_varnish_callback function. This makes it possible for unauthenticated attackers to purge the varnish cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1920

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1919 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache-related settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1919

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1918 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_callback function. This makes it possible for unauthenticated attackers to invoke a cache building action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1918

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1470 - Changeset Plugin

The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Changeset

CVE-2023-1470

MEDIUM CVSS 4.4 2023-03-17
Threat Entry Updated 2026-02-13

CVE-2023-1346 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_page_cache function. This makes it possible for unauthenticated attackers to clear the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1346

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1345 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the queue_posts function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1345

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1344 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the uucss_update_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1344

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1343 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the attach_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1343

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1342 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect function. This makes it possible for unauthenticated attackers to connect the site to a new license key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1342

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1341 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated attackers to turn off caching via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1341

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1340 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_uucss_logs function. This makes it possible for unauthenticated attackers to clear plugin logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1340

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1339 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the uucss_update_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to update caching rules.

PLUGIN Changeset

CVE-2023-1339

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1338 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the attach_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify cache rules.

PLUGIN Changeset

CVE-2023-1338

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1337 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files.

PLUGIN Changeset

CVE-2023-1337

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1336 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to disable caching.

PLUGIN Changeset

CVE-2023-1336

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1335 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the ucss_connect function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to connect a new license key to the site.

PLUGIN Changeset

CVE-2023-1335

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1334 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the queue_posts function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify the plugin's cache.

PLUGIN Changeset

CVE-2023-1334

MEDIUM CVSS 4.3 2023-03-10
Scroll to top