Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3161-3180 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2023-2715 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_ticket' function in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers to create a support ticket that sends the website's data to the plugin developer, and it is also possible to create an admin access with an auto login link that is also sent to the plugin developer with the ticket. It only works if the plugin is activated with a valid license.

PLUGIN Changeset

CVE-2023-2715

MEDIUM CVSS 4.3 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2714 - Changeset Plugin

The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_license' functions in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the license key and support license key, but it can only be changed to a valid license key.

PLUGIN Changeset

CVE-2023-2714

MEDIUM CVSS 4.3 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-1931 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the deleteCssAndJsCacheToolbar function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to perform cache deletion.

PLUGIN Changeset

CVE-2023-1931

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1930 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the wpfc_clear_cache_of_allsites_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to delete caches.

PLUGIN Changeset

CVE-2023-1930

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1929 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_purgecache_varnish_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to purge the varnish cache.

PLUGIN Changeset

CVE-2023-1929

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1928 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_preload_single_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to initiate cache creation.

PLUGIN Changeset

CVE-2023-1928

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1927 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCssAndJsCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1927

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1926 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1926

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1925 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_clear_cache_of_allsites_callback function. This makes it possible for unauthenticated attackers to clear caches via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1925

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1924 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_toolbar_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1924

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1923 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_remove_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1923

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1922 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_pause_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1922

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1921 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_start_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1921

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1920 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_purgecache_varnish_callback function. This makes it possible for unauthenticated attackers to purge the varnish cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1920

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1919 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache-related settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1919

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1918 - Changeset Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_callback function. This makes it possible for unauthenticated attackers to invoke a cache building action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1918

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1470 - Changeset Plugin

The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Changeset

CVE-2023-1470

MEDIUM CVSS 4.4 2023-03-17
Threat Entry Updated 2026-02-13

CVE-2023-1346 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_page_cache function. This makes it possible for unauthenticated attackers to clear the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1346

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1345 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the queue_posts function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1345

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1344 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the uucss_update_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1344

MEDIUM CVSS 4.3 2023-03-10
Scroll to top