Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3221-3240 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2022-1329 - Changeset Plugin

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

PLUGIN Changeset

CVE-2022-1329

HIGH CVSS 8.8 2022-04-19
Threat Entry Updated 2024-11-21

CVE-2022-0993 - Changeset Plugin

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects versions up to, and including, 1.2.5.

PLUGIN Changeset

CVE-2022-0993

HIGH CVSS 8.1 2022-04-19
Threat Entry Updated 2024-11-21

CVE-2022-1001 - Changeset Plugin

The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" settings, but does not sanitise and escape it server side, allowing high privilege users such as admin to perform Cross-Site attacks even when the unfiltered_html capability is disallowed

PLUGIN Changeset

CVE-2022-1001

MEDIUM CVSS 4.8 2022-04-18
Threat Entry Updated 2025-02-07

CVE-2022-0706 - Changeset Plugin

The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

PLUGIN Changeset

CVE-2022-0706

MEDIUM CVSS 4.8 2022-04-18
Threat Entry Updated 2025-02-07

CVE-2022-0707 - Changeset Plugin

The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes, which could allow attackers to make a logged admin insert arbitrary notes via a CSRF attack

PLUGIN Changeset

CVE-2022-0707

MEDIUM CVSS 4.3 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1023 - Changeset Plugin

The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file

PLUGIN Changeset

CVE-2022-1023

HIGH CVSS 7.2 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-1008 - Changeset Plugin

The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed

PLUGIN Changeset

CVE-2022-1008

HIGH CVSS 7.2 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-1006 - Changeset Plugin

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks

PLUGIN Changeset

CVE-2022-1006

HIGH CVSS 7.2 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-1007 - Changeset Plugin

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2022-1007

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0471 - Changeset Plugin

The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2022-0471

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0969 - Changeset Plugin

The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Changeset

CVE-2022-0969

MEDIUM CVSS 4.8 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-1165 - Changeset Plugin

The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots. This could also be abused by competitors to cause damage related to visibility in search engines, can be used to bypass arbitrary blocks caused by this plugin, block any visitor or even the administrator and even more.

PLUGIN Changeset

CVE-2022-1165

CRITICAL CVSS 9.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0958 - Changeset Plugin

The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Changeset

CVE-2022-0958

MEDIUM CVSS 4.8 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0431 - Changeset Plugin

The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2022-0431

MEDIUM CVSS 6.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0825 - Changeset Plugin

The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

PLUGIN Changeset

CVE-2022-0825

MEDIUM CVSS 5.4 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0884 - Changeset Plugin

The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Changeset

CVE-2022-0884

MEDIUM CVSS 4.8 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0595 - Changeset Plugin

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

PLUGIN Changeset

CVE-2022-0595

MEDIUM CVSS 5.4 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0479 - Changeset Plugin

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link

PLUGIN Changeset

CVE-2022-0479

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2021-24962 - Changeset Plugin

The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution.

PLUGIN Changeset

CVE-2021-24962

HIGH CVSS 8.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0493 - Changeset Plugin

The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will be used to output the relevant matches from the matching file, all content of the file can be disclosed.

PLUGIN Changeset

CVE-2022-0493

MEDIUM CVSS 4.9 2022-03-28
Scroll to top