Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical1
High0
Medium2
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2024-11-21

CVE-2022-1436 - Trace Plugin

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number parameter before outputting it back in the page, which could allow attackers to perform reflected Cross-Site Scripting attacks.

PLUGIN Trace

CVE-2022-1436

MEDIUM CVSS 6.1 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1435 - Trace Plugin

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Trace

CVE-2022-1435

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2021-25003 - Trace Plugin

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

PLUGIN Trace

CVE-2021-25003

CRITICAL CVSS 9.8 2022-03-14
Scroll to top