Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical1
High0
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2024-11-21

CVE-2024-2172 - Malware Scanner Plugin

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This makes it possible for unauthenticated attackers to escalate their privileges to that of an administrator.

PLUGIN Malware Scanner

CVE-2024-2172

CRITICAL CVSS 9.8 2024-03-13
Threat Entry Updated 2024-11-21

CVE-2022-1995 - Malware Scanner Plugin

The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

PLUGIN Malware Scanner

CVE-2022-1995

MEDIUM CVSS 4.8 2022-06-27
Scroll to top