Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3201-3220 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2023-0555 - Changeset Plugin

The Quick Restaurant Menu plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke those actions intended for administrator use. Actions include menu item creation, update and deletion and other menu management functions. Since the plugin does not verify that a post ID passed to one of its AJAX actions belongs to a menu item, this can lead to arbitrary post…

PLUGIN Changeset

CVE-2023-0555

HIGH CVSS 7.6 2023-01-27
Threat Entry Updated 2024-11-21

CVE-2023-0554 - Changeset Plugin

The Quick Restaurant Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to update menu items, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2023-0554

HIGH CVSS 7.6 2023-01-27
Threat Entry Updated 2024-11-21

CVE-2023-0550 - Changeset Plugin

The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the fact that during menu item deletion/modification, the plugin does not verify that the post ID provided to the AJAX action is indeed a menu item. This makes it possible for authenticated attackers, with subscriber-level access or higher, to modify or delete arbitrary posts.

PLUGIN Changeset

CVE-2023-0550

HIGH CVSS 7.6 2023-01-27
Threat Entry Updated 2024-11-21

CVE-2023-0553 - Changeset Plugin

The Quick Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2023-0553

MEDIUM CVSS 5.5 2023-01-27
Threat Entry Updated 2024-11-21

CVE-2022-2939 - Changeset Plugin

The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to improper validation on the value supplied through the 'author' parameter found in the ~/cerber-load.php file. In vulnerable versions, the plugin only blocks requests if the value supplied is numeric, making it possible for attackers to supply additional non-numeric characters to bypass the protection. The non-numeric characters are stripped and the user requested is displayed. This can be used by unauthenticated attackers…

PLUGIN Changeset

CVE-2022-2939

MEDIUM CVSS 5.3 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2633 - Changeset Plugin

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users to download sensitive files hosted on the affected server and forge requests to the server.

PLUGIN Changeset

CVE-2022-2633

HIGH CVSS 7.5 2022-09-06
Threat Entry Updated 2025-08-21

CVE-2022-2433 - Changeset Plugin

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an action such as clicking on a link, that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that…

PLUGIN Changeset

CVE-2022-2433

HIGH CVSS 7.5 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2438 - Changeset Plugin

The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 1.11.16. This makes it possible for authenticated attackers with administrative privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.

PLUGIN Changeset

CVE-2022-2438

HIGH CVSS 7.2 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2544 - Changeset Plugin

The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.

PLUGIN Changeset

CVE-2022-2544

HIGH CVSS 7.5 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2046 - Changeset Plugin

The Directorist WordPress plugin before 7.2.3 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets the zip files from. This could allow administrators to run code on the server, which is a problem in multisite configurations.

PLUGIN Changeset

CVE-2022-2046

MEDIUM CVSS 4.9 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2117 - Changeset Plugin

The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled. This functionality has been completely removed in version 2.20.2.

PLUGIN Changeset

CVE-2022-2117

MEDIUM CVSS 5.3 2022-07-18
Threat Entry Updated 2025-05-05

CVE-2022-2001 - Changeset Plugin

The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing nonce protection on the dxss_admin_page() function found in the ~/dx-share-selection.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site's administrator into performing an action such as clicking on a link.

PLUGIN Changeset

CVE-2022-2001

HIGH CVSS 8.8 2022-07-18
Threat Entry Updated 2025-05-05

CVE-2022-2108 - Changeset Plugin

The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.

PLUGIN Changeset

CVE-2022-2108

MEDIUM CVSS 6.5 2022-07-18
Threat Entry Updated 2025-05-05

CVE-2022-1442 - Changeset Plugin

The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.

PLUGIN Changeset

CVE-2022-1442

HIGH CVSS 7.5 2022-05-10
Threat Entry Updated 2024-11-21

CVE-2022-0948 - Changeset Plugin

The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

PLUGIN Changeset

CVE-2022-0948

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-1281 - Changeset Plugin

The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.

PLUGIN Changeset

CVE-2022-1281

CRITICAL CVSS 9.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0191 - Changeset Plugin

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans

PLUGIN Changeset

CVE-2022-0191

MEDIUM CVSS 6.5 2022-05-02
Threat Entry Updated 2025-05-05

CVE-2022-0992 - Changeset Plugin

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA for pending accounts. Upon successful configuration, the attacker is logged in as that user without access to a username/password pair which is the expected first form of authentication. This affects versions up to, and including, 1.2.5.

PLUGIN Changeset

CVE-2022-0992

CRITICAL CVSS 9.8 2022-04-19
Scroll to top