Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3181-3200 of 3408 records
Threat Entry Updated 2026-02-20

CVE-2023-1343 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the attach_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1343

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1342 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect function. This makes it possible for unauthenticated attackers to connect the site to a new license key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1342

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1341 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated attackers to turn off caching via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1341

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1340 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_uucss_logs function. This makes it possible for unauthenticated attackers to clear plugin logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1340

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1339 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the uucss_update_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to update caching rules.

PLUGIN Changeset

CVE-2023-1339

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1338 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the attach_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify cache rules.

PLUGIN Changeset

CVE-2023-1338

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1337 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files.

PLUGIN Changeset

CVE-2023-1337

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1336 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to disable caching.

PLUGIN Changeset

CVE-2023-1336

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1335 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the ucss_connect function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to connect a new license key to the site.

PLUGIN Changeset

CVE-2023-1335

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1334 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the queue_posts function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify the plugin's cache.

PLUGIN Changeset

CVE-2023-1334

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-13

CVE-2023-1333 - Changeset Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_page_cache function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete the plugin's cache.

PLUGIN Changeset

CVE-2023-1333

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2024-11-21

CVE-2023-1023 - Changeset Plugin

The WP Meta SEO plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the saveSitemapSettings function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to change sitemap-related settings of the plugin. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.

PLUGIN Changeset

CVE-2023-1023

MEDIUM CVSS 5.4 2023-02-28
Threat Entry Updated 2024-11-21

CVE-2023-1028 - Changeset Plugin

The WP Meta SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.3. This is due to missing or incorrect nonce validation on the setIgnore function. This makes it possible for unauthenticated attackers to update plugin options via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1028

MEDIUM CVSS 4.3 2023-02-28
Threat Entry Updated 2024-11-21

CVE-2023-1027 - Changeset Plugin

The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the checkAllCategoryInSitemap function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to obtain post categories. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.

PLUGIN Changeset

CVE-2023-1027

MEDIUM CVSS 4.3 2023-02-28
Threat Entry Updated 2024-11-21

CVE-2023-1026 - Changeset Plugin

The WP Meta SEO plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the listPostsCategory function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to get post listings by category as long as those posts are published. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.

PLUGIN Changeset

CVE-2023-1026

MEDIUM CVSS 4.3 2023-02-28
Threat Entry Updated 2024-11-21

CVE-2023-1024 - Changeset Plugin

The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the regenerateSitemaps function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to generate sitemaps. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.

PLUGIN Changeset

CVE-2023-1024

MEDIUM CVSS 4.3 2023-02-28
Threat Entry Updated 2024-11-21

CVE-2023-1022 - Changeset Plugin

The WP Meta SEO plugin for WordPress is vulnerable to unauthorized options update due to a missing capability check on the wpmsGGSaveInformation function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to update google analytics options maintained by the plugin. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.

PLUGIN Changeset

CVE-2023-1022

MEDIUM CVSS 5.4 2023-02-28
Threat Entry Updated 2024-11-21

CVE-2023-1068 - Changeset Plugin

The Download Read More Excerpt Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.0. This is due to missing or incorrect nonce validation on the read_more_excerpt_link_menu_options() function. This makes it possible for unauthenticated attackers to update he plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1068

MEDIUM CVSS 4.3 2023-02-27
Threat Entry Updated 2024-11-21

CVE-2023-1029 - Changeset Plugin

The WP Meta SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.3. This is due to missing or incorrect nonce validation on the regenerateSitemaps function. This makes it possible for unauthenticated attackers to regenerate Sitemaps via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-1029

MEDIUM CVSS 4.3 2023-02-24
Threat Entry Updated 2025-03-12

CVE-2023-0232 - Changeset Plugin

The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.

PLUGIN Changeset

CVE-2023-0232

CRITICAL CVSS 9.8 2023-02-21
Scroll to top