Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12161-12180 of 16202 records
Threat Entry Updated 2024-11-21

CVE-2023-6970 - Wp Recipe Maker Plugin

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Recipe Maker

CVE-2023-6970

MEDIUM CVSS 6.1 2024-01-18
Threat Entry Updated 2025-06-17

CVE-2023-5041 - Track The Click Plugin

The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.

PLUGIN Track The Click

CVE-2023-5041

HIGH CVSS 8.8 2024-01-17
Threat Entry Updated 2025-06-11

CVE-2023-5006 - Wp Discord Invite Plugin

The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request.

PLUGIN Wp Discord Invite

CVE-2023-5006

MEDIUM CVSS 6.5 2024-01-17
Threat Entry Updated 2026-04-08

CVE-2021-4434 - Social Warfare Plugin

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.

PLUGIN Social Warfare

CVE-2021-4434

CRITICAL CVSS 10.0 2024-01-17
Threat Entry Updated 2025-06-02

CVE-2024-0405 - Burst Statistics Plugin

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id', 'page_url', 'platform', and 'referrer'. This vulnerability arises due to insufficient escaping of user-supplied parameters and the lack of adequate preparation in SQL queries. As a result, authenticated attackers with editor access or higher can append additional SQL queries into existing ones, potentially leading to unauthorized access to sensitive information from the database.

PLUGIN Burst Statistics

CVE-2024-0405

HIGH CVSS 7.2 2024-01-17
Threat Entry Updated 2025-05-09

CVE-2024-0239 - Contact Form 7 Connector Plugin

The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.

PLUGIN Contact Form 7 Connector

CVE-2024-0239

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2024-0238 - Eventon Premium Plugin

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

PLUGIN Eventon Premium

CVE-2024-0238

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2024-0233 - Before 2 Plugin

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2024-0233

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2025-05-22

CVE-2024-0187 - Community By Peepso Plugin

The Community by PeepSo WordPress plugin before 6.3.1.2 does not sanitise and escape various parameters and generated URLs before outputting them back attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Community By Peepso

CVE-2024-0187

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2026-02-27

CVE-2023-7151 - Product Enquiry For Woocommerce Plugin

The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Product Enquiry For Woocommerce

CVE-2023-7151

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2023-7084 - Voting Record Plugin

The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authenticated users, such as subscriber to perform Stored XSS attacks

PLUGIN Voting Record

CVE-2023-7084

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2024-0237 - Before 2 Plugin

The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc

PLUGIN Before 2

CVE-2024-0237

MEDIUM CVSS 5.3 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2024-0236 - Before 2 Plugin

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)

PLUGIN Before 2

CVE-2024-0236

MEDIUM CVSS 5.3 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2024-0235 - Before 2 Plugin

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

PLUGIN Before 2

CVE-2024-0235

MEDIUM CVSS 5.3 2024-01-16
Threat Entry Updated 2024-11-21

CVE-2023-7154 - Before 1 Plugin

The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2023-7154

MEDIUM CVSS 4.8 2024-01-16
Threat Entry Updated 2025-06-17

CVE-2023-7125 - Community By Peepso Plugin

The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack

PLUGIN Community By Peepso

CVE-2023-7125

MEDIUM CVSS 4.3 2024-01-16
Threat Entry Updated 2025-06-11

CVE-2023-6373 - Before 2 Plugin

The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the lack of CSRF check, the issue could also be exploited via a CSRF against a logged editor (or above)

PLUGIN Before 2

CVE-2023-6373

HIGH CVSS 8.8 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2023-4536 - My Account Page Editor Plugin

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

PLUGIN My Account Page Editor

CVE-2023-4536

HIGH CVSS 8.8 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2023-5922 - Royal Elementor Addons And Templates Plugin

The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently disabled in the plugin) have the right to do so, allowing unauthenticated users to access arbitrary draft, private and password protected posts/pages content

PLUGIN Royal Elementor Addons And Templates

CVE-2023-5922

HIGH CVSS 7.5 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2023-4703 - All In One B2b For Woocommerce Plugin

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.

PLUGIN All In One B2b For Woocommerce

CVE-2023-4703

HIGH CVSS 7.5 2024-01-16
Scroll to top