Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total567
Critical21
High113
Medium423
Reset
Showing 381-400 of 567 records
Threat Entry Updated 2024-11-21

CVE-2022-1956 - Through 1 Plugin

The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its settings, which could allow any authenticated users, such as subscriber, to update them.

PLUGIN Through 1

CVE-2022-1956

MEDIUM CVSS 4.3 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1546 - Through 1 Plugin

The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Through 1

CVE-2022-1546

MEDIUM CVSS 6.1 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1626 - Through 1 Plugin

The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and also lead to Stored Cross-Site Scripting issue due to the lack of sanitisation and escaping in some of them

PLUGIN Through 1

CVE-2022-1626

MEDIUM CVSS 5.4 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1971 - Through 1 Plugin

The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Through 1

CVE-2022-1971

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1960 - Through 1 Plugin

The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Through 1

CVE-2022-1960

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1914 - Through 1 Plugin

The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well

PLUGIN Through 1

CVE-2022-1914

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1574 - Through 1 Plugin

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

PLUGIN Through 1

CVE-2022-1574

CRITICAL CVSS 9.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1572 - Through 1 Plugin

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

PLUGIN Through 1

CVE-2022-1572

HIGH CVSS 8.1 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1593 - Through 1 Plugin

The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its settings, and it also lacking sanitisation as well as escaping in some of them. As a result, attackers could make a logged in admin change them and put Cross-Site Scripting payloads in them via a CSRF attack

PLUGIN Through 1

CVE-2022-1593

MEDIUM CVSS 6.1 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1847 - Through 1 Plugin

The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Through 1

CVE-2022-1847

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1844 - Through 1 Plugin

The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

PLUGIN Through 1

CVE-2022-1844

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1573 - Through 1 Plugin

The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them

PLUGIN Through 1

CVE-2022-1573

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1326 - Through 1 Plugin

The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Through 1

CVE-2022-1326

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1831 - Through 1 Plugin

The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Through 1

CVE-2022-1831

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1830 - Through 1 Plugin

The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

PLUGIN Through 1

CVE-2022-1830

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1792 - Through 1 Plugin

The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them

PLUGIN Through 1

CVE-2022-1792

MEDIUM CVSS 5.4 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1765 - Through 1 Plugin

The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations or licensing rules).

PLUGIN Through 1

CVE-2022-1765

HIGH CVSS 8.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1758 - Through 1 Plugin

The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS as well as RCE when custom code is added via the plugin settings.

PLUGIN Through 1

CVE-2022-1758

HIGH CVSS 8.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1779 - Through 1 Plugin

The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific posts, categories and attachments at once.

PLUGIN Through 1

CVE-2022-1779

HIGH CVSS 8.1 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1773 - Through 1 Plugin

The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Through 1

CVE-2022-1773

MEDIUM CVSS 6.1 2022-06-13
Scroll to top