Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3281-3300 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2021-24913 - Changeset Plugin

The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_data AJAX action, allowing attackers to make a logged in high privilege user, change title, description, alt text, and URL of arbitrary uploaded media.

PLUGIN Changeset

CVE-2021-24913

MEDIUM CVSS 4.3 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24864 - Changeset Plugin

The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue

PLUGIN Changeset

CVE-2021-24864

HIGH CVSS 8.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0228 - Changeset Plugin

The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection

PLUGIN Changeset

CVE-2022-0228

HIGH CVSS 7.2 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0252 - Changeset Plugin

The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2022-0252

MEDIUM CVSS 6.1 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0234 - Changeset Plugin

The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2022-0234

MEDIUM CVSS 6.1 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0313 - Changeset Plugin

The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow attackers to make a logged in admin delete them via a CSRF attack

PLUGIN Changeset

CVE-2022-0313

MEDIUM CVSS 4.3 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0199 - Changeset Plugin

The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack

PLUGIN Changeset

CVE-2022-0199

MEDIUM CVSS 4.3 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0164 - Changeset Plugin

The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users

PLUGIN Changeset

CVE-2022-0164

MEDIUM CVSS 4.3 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-25082 - Changeset Plugin

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

PLUGIN Changeset

CVE-2021-25082

HIGH CVSS 8.8 2022-02-21
Threat Entry Updated 2025-03-21

CVE-2021-25069 - Changeset Plugin

The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2021-25069

HIGH CVSS 8.8 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-25100 - Changeset Plugin

The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2021-25100

MEDIUM CVSS 6.1 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-25099 - Changeset Plugin

The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2021-25099

MEDIUM CVSS 6.1 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0513 - Changeset Plugin

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.4. This requires the "Record Exclusions" option to be enabled on the vulnerable site.

PLUGIN Changeset

CVE-2022-0513

CRITICAL CVSS 9.8 2022-02-16
Threat Entry Updated 2024-11-21

CVE-2022-0201 - Changeset Plugin

The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2022-0201

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0193 - Changeset Plugin

The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2022-0193

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2025-04-15

CVE-2022-0176 - Changeset Plugin

The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2022-0176

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2026-03-20

CVE-2021-25115 - Changeset Plugin

The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.

PLUGIN Changeset

CVE-2021-25115

MEDIUM CVSS 6.4 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25107 - Changeset Plugin

The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back in the created entry, allowing unauthenticated attacker to perform Cross-Site Scripting attacks against admin

PLUGIN Changeset

CVE-2021-25107

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25033 - Changeset Plugin

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue

PLUGIN Changeset

CVE-2021-25033

MEDIUM CVSS 6.1 2022-02-14
Scroll to top