Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3261-3280 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2022-0426 - Changeset Plugin

The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before outputting it back in an attribute via the woosea_categories_dropdown AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2022-0426

MEDIUM CVSS 5.4 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0535 - Changeset Plugin

The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Changeset

CVE-2022-0535

MEDIUM CVSS 4.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0384 - Changeset Plugin

The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog

PLUGIN Changeset

CVE-2022-0384

MEDIUM CVSS 4.3 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24961 - Changeset Plugin

The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

PLUGIN Changeset

CVE-2021-24961

MEDIUM CVSS 5.4 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24960 - Changeset Plugin

The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks

PLUGIN Changeset

CVE-2021-24960

MEDIUM CVSS 5.4 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24216 - Changeset Plugin

The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.

PLUGIN Changeset

CVE-2021-24216

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0412 - Changeset Plugin

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

PLUGIN Changeset

CVE-2022-0412

CRITICAL CVSS 9.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0411 - Changeset Plugin

The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection

PLUGIN Changeset

CVE-2022-0411

HIGH CVSS 8.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-23911 - Changeset Plugin

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection

PLUGIN Changeset

CVE-2022-23911

HIGH CVSS 7.2 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0383 - Changeset Plugin

The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks

PLUGIN Changeset

CVE-2022-0383

HIGH CVSS 7.2 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-23912 - Changeset Plugin

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting

PLUGIN Changeset

CVE-2022-23912

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0360 - Changeset Plugin

The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues

PLUGIN Changeset

CVE-2022-0360

MEDIUM CVSS 4.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25081 - Changeset Plugin

The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack

PLUGIN Changeset

CVE-2021-25081

MEDIUM CVSS 6.5 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0189 - Changeset Plugin

The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2022-0189

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0150 - Changeset Plugin

The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2022-0150

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25112 - Changeset Plugin

The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2021-25112

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25011 - Changeset Plugin

The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.

PLUGIN Changeset

CVE-2021-25011

MEDIUM CVSS 5.7 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25118 - Changeset Plugin

The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

PLUGIN Changeset

CVE-2021-25118

MEDIUM CVSS 5.3 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24920 - Changeset Plugin

The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Changeset

CVE-2021-24920

MEDIUM CVSS 4.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0328 - Changeset Plugin

The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

PLUGIN Changeset

CVE-2022-0328

MEDIUM CVSS 4.7 2022-02-28
Scroll to top