Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3061-3080 of 3408 records
Threat Entry Updated 2025-04-03

CVE-2023-0958 - Changeset Plugin

Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, such as subscribers, to install select plugins from Inisev on vulnerable sites. CVE-2023-38514 appears to be a duplicate of this vulnerability.

PLUGIN Changeset

CVE-2023-0958

MEDIUM CVSS 4.3 2023-07-28
Threat Entry Updated 2024-11-21

CVE-2023-3957 - Changeset Plugin

The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient restriction on the 'apg_profile_update' function in versions up to, and including, 1.9. This makes it possible for authenticated attackers, with subscriber-level permissions or above, to update the user metas arbitrarily. The meta value can only be a string.

PLUGIN Changeset

CVE-2023-3957

MEDIUM CVSS 4.3 2023-07-27
Threat Entry Updated 2024-11-21

CVE-2023-3956 - Changeset Plugin

The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. This makes it possible for unauthenticated attackers to add, modify or delete post and taxonomy, install, activate or deactivate plugin, change customizer settings, add or modify or delete user including administrator user.

PLUGIN Changeset

CVE-2023-3956

CRITICAL CVSS 9.8 2023-07-27
Threat Entry Updated 2024-11-21

CVE-2023-2433 - Changeset Plugin

The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-2433

MEDIUM CVSS 6.4 2023-07-18
Threat Entry Updated 2024-11-21

CVE-2023-3713 - Changeset Plugin

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily. This can be used by attackers to achieve privilege escalation.

PLUGIN Changeset

CVE-2023-3713

HIGH CVSS 8.8 2023-07-18
Threat Entry Updated 2024-11-21

CVE-2023-3714 - Changeset Plugin

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_role' parameter, which defines the member's role. This issue was partially patched in version 5.5.2 preventing privilege escalation, however, it was fully patched in 5.5.3.

PLUGIN Changeset

CVE-2023-3714

HIGH CVSS 7.5 2023-07-18
Threat Entry Updated 2024-11-21

CVE-2023-3459 - Changeset Plugin

The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop manager-level permissions to change user passwords and potentially take over administrator accounts.

PLUGIN Changeset

CVE-2023-3459

HIGH CVSS 7.2 2023-07-18
Threat Entry Updated 2024-11-21

CVE-2023-3403 - Changeset Plugin

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to import new users and update existing users.

PLUGIN Changeset

CVE-2023-3403

MEDIUM CVSS 5.4 2023-07-18
Threat Entry Updated 2024-11-21

CVE-2023-3342 - Changeset Plugin

The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitrary files on the affected site's server which may make remote code execution possible. This was partially patched in version 3.0.2 and fully patched in version 3.0.2.1.

PLUGIN Changeset

CVE-2023-3342

CRITICAL CVSS 9.9 2023-07-13
Threat Entry Updated 2024-11-21

CVE-2023-3343 - Changeset Plugin

The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Changeset

CVE-2023-3343

HIGH CVSS 8.8 2023-07-13
Threat Entry Updated 2026-04-08

CVE-2021-4424 - Changeset Plugin

The Slider Hero plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.0. This is due to missing or incorrect nonce validation on the qc_slider_hero_duplicate() function. This makes it possible for unauthenticated attackers to duplicate slides via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2021-4424

MEDIUM CVSS 4.3 2023-07-12
Threat Entry Updated 2026-04-08

CVE-2021-4423 - Changeset Plugin

The RAYS Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the rsgd_insert_update() function. This makes it possible for unauthenticated attackers to update post fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2021-4423

MEDIUM CVSS 4.3 2023-07-12
Threat Entry Updated 2024-11-21

CVE-2023-3168 - Changeset Plugin

The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-3168

HIGH CVSS 7.2 2023-07-12
Threat Entry Updated 2024-11-21

CVE-2023-3167 - Changeset Plugin

The Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-3167

HIGH CVSS 7.2 2023-07-12
Threat Entry Updated 2024-11-21

CVE-2023-3166 - Changeset Plugin

The Lana Email Logger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, Lana Email Logger due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-3166

HIGH CVSS 7.2 2023-07-12
Threat Entry Updated 2024-11-21

CVE-2023-3135 - Changeset Plugin

The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-3135

HIGH CVSS 7.2 2023-07-12
Threat Entry Updated 2024-11-21

CVE-2023-3122 - Changeset Plugin

The GD Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-3122

HIGH CVSS 7.2 2023-07-12
Threat Entry Updated 2024-11-21

CVE-2023-3093 - Changeset Plugin

The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-3093

HIGH CVSS 7.2 2023-07-12
Threat Entry Updated 2024-11-21

CVE-2023-3088 - Changeset Plugin

The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-3088

HIGH CVSS 7.2 2023-07-12
Threat Entry Updated 2024-11-21

CVE-2023-3087 - Changeset Plugin

The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-3087

HIGH CVSS 7.2 2023-07-12
Scroll to top