Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3141-3160 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2023-0693 - Changeset Plugin

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_transaction_id' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about the transaction ids of arbitrary form submissions that included payment.

PLUGIN Changeset

CVE-2023-0693

MEDIUM CVSS 6.5 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-0692 - Changeset Plugin

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_status' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about the payment status of arbitrary form submissions.

PLUGIN Changeset

CVE-2023-0692

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-0688 - Changeset Plugin

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about form submissions, including payment status, and transaction ID.

PLUGIN Changeset

CVE-2023-0688

MEDIUM CVSS 6.5 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-0691 - Changeset Plugin

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions, specifically the submitter's last name.

PLUGIN Changeset

CVE-2023-0691

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-0292 - Changeset Plugin

The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary media files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-0292

MEDIUM CVSS 5.4 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-0291 - Changeset Plugin

The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files.

PLUGIN Changeset

CVE-2023-0291

HIGH CVSS 7.2 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2986 - Changeset Plugin

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows unauthenticated attackers to log in as users who have abandoned the cart, who are typically customers. Further security hardening was introduced in version 5.15.1 that ensures sites are no longer vulnerable through historical check-out links, and additional hardening was introduced in version 5.15.2 that ensured null key…

PLUGIN Changeset

CVE-2023-2986

CRITICAL CVSS 9.8 2023-06-08
Threat Entry Updated 2026-04-08

CVE-2021-4382 - Changeset Plugin

The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fetch_external_image() function in versions up to, and including, 3.0.4. This makes it possible for authenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Changeset

CVE-2021-4382

HIGH CVSS 8.8 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4373 - Changeset Plugin

The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to import settings via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2021-4373

HIGH CVSS 8.8 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4377 - Changeset Plugin

The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.8.5 via the dmm_export_donations() function which is called via the admin_post_dmm_export hook due to missing capability checks. This can allow authenticated attackers to extract a CSV file that contains sensitive information about the donors.

PLUGIN Changeset

CVE-2021-4377

MEDIUM CVSS 6.5 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4349 - Changeset Plugin

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2021-4349

HIGH CVSS 8.8 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4338 - Changeset Plugin

The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to view, create and edit redirections.

PLUGIN Changeset

CVE-2021-4338

MEDIUM CVSS 6.4 2023-06-07
Threat Entry Updated 2024-11-21

CVE-2023-2546 - Changeset Plugin

The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2. This is due to incorrect authentication checking in the 'wpus_allow_user_to_admin_bar_menu' function with the 'wpus_who_switch' cookie value. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator, if they have access to the username.

PLUGIN Changeset

CVE-2023-2546

HIGH CVSS 8.8 2023-06-06
Threat Entry Updated 2024-11-21

CVE-2023-2835 - Changeset Plugin

The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-2835

MEDIUM CVSS 6.1 2023-06-02
Threat Entry Updated 2024-11-21

CVE-2023-2836 - Changeset Plugin

The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Changeset

CVE-2023-2836

MEDIUM CVSS 4.4 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-2276 - Changeset Plugin

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.

PLUGIN Changeset

CVE-2023-2276

CRITICAL CVSS 9.8 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2736 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.8. This is due to missing nonce validation in the 'ajax_edit_contact' function. This makes it possible for authenticated attackers to receive the auto login link via shortcode and then modify the assigned user to the auto login link to elevate verified user privileges via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-2736

HIGH CVSS 7.5 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2717 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.8. This is due to missing nonce validation on the 'enable_safe_mode' function. This makes it possible for unauthenticated attackers to enable safe mode, which disables all other plugins, via a forged request if they can successfully trick an administrator into performing an action such as clicking on a link. A warning message about safe mode is displayed to the admin, which can be easily disabled.

PLUGIN Changeset

CVE-2023-2717

MEDIUM CVSS 5.4 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2716 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'ajax_upload_file' function in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload a file to the contact, and then lists all the other uploaded files related to the contact.

PLUGIN Changeset

CVE-2023-2716

MEDIUM CVSS 5.4 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2735 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gh_form' shortcode in versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Please note this only works with legacy contact forms.

PLUGIN Changeset

CVE-2023-2735

MEDIUM CVSS 4.9 2023-05-20
Scroll to top