Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12181-12200 of 16202 records
Threat Entry Updated 2025-06-11

CVE-2023-4797 - Before 4 Plugin

The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.

PLUGIN Before 4

CVE-2023-4797

HIGH CVSS 7.2 2024-01-16
Threat Entry Updated 2025-06-11

CVE-2023-6824 - Wp Customer Area Plugin

The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.

PLUGIN Wp Customer Area

CVE-2023-6824

MEDIUM CVSS 6.5 2024-01-16
Threat Entry Updated 2024-11-21

CVE-2023-5558 - Before 4 Plugin

The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 4

CVE-2023-5558

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2023-7083 - Voting Record Plugin

The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Voting Record

CVE-2023-7083

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2023-4757 - Before 1 Plugin

The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.

PLUGIN Before 1

CVE-2023-4757

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2023-6732 - Ultimate Maps By Supsystic Plugin

The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Ultimate Maps By Supsystic

CVE-2023-6732

MEDIUM CVSS 4.8 2024-01-16
Threat Entry Updated 2025-06-13

CVE-2023-6046 - Before 2 Plugin

The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2023-6046

MEDIUM CVSS 4.8 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2023-6005 - Before 2 Plugin

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 2

CVE-2023-6005

MEDIUM CVSS 4.8 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2023-6741 - Wp Customer Area Plugin

The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.

PLUGIN Wp Customer Area

CVE-2023-6741

MEDIUM CVSS 4.3 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2023-6292 - Ecwid Ecommerce Shopping Cart Plugin

The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

PLUGIN Ecwid Ecommerce Shopping Cart

CVE-2023-6292

MEDIUM CVSS 4.3 2024-01-16
Threat Entry Updated 2025-06-11

CVE-2023-3211 - Wordpress Database Administrator Plugin

The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

PLUGIN Wordpress Database Administrator

CVE-2023-3211

CRITICAL CVSS 9.8 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2023-3771 - T1 Plugin

The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.

PLUGIN T1

CVE-2023-3771

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2023-3372 - Lana Shortcodes Plugin

The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Lana Shortcodes

CVE-2023-3372

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2023-3647 - Iurny By Indigitall Plugin

The IURNY by INDIGITALL WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Iurny By Indigitall

CVE-2023-3647

MEDIUM CVSS 4.8 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2023-3178 - Post Smtp Mailer Plugin

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.

PLUGIN Post Smtp Mailer

CVE-2023-3178

MEDIUM CVSS 4.3 2024-01-16
Threat Entry Updated 2025-06-13

CVE-2023-0224 - Before 2 Plugin

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks

PLUGIN Before 2

CVE-2023-0224

CRITICAL CVSS 9.8 2024-01-16
Threat Entry Updated 2025-06-11

CVE-2023-1405 - Formidable Forms Plugin

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

PLUGIN Formidable Forms

CVE-2023-1405

HIGH CVSS 7.5 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2023-2655 - Contact Form Maker Plugin

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

PLUGIN Contact Form Maker

CVE-2023-2655

HIGH CVSS 7.2 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2023-0824 - Userplus Plugin

The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.

PLUGIN Userplus

CVE-2023-0824

MEDIUM CVSS 6.5 2024-01-16
Scroll to top