Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12201-12220 of 16202 records
Threat Entry Updated 2025-06-02

CVE-2023-0769 - Migration Simple Plugin

The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.

PLUGIN Migration Simple

CVE-2023-0769

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2023-0479 - Delivery Notes For Woocommerce Plugin

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding.

PLUGIN Delivery Notes For Woocommerce

CVE-2023-0479

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2023-0376 - Before 1 Plugin

The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0376

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2024-11-21

CVE-2023-0094 - Upqode Google Maps Plugin

The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Upqode Google Maps

CVE-2023-0094

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2023-0079 - Customer Reviews For Woocommerce Plugin

The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Customer Reviews For Woocommerce

CVE-2023-0079

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-11

CVE-2023-0389 - Calculated Fields Form Plugin

The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Calculated Fields Form

CVE-2023-0389

MEDIUM CVSS 4.8 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2023-2252 - Before 7 Plugin

The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

PLUGIN Before 7

CVE-2023-2252

LOW CVSS 2.7 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2021-24869 - Wp Fastest Cache Plugin

The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading to an SQL injection exploitable by low privilege users such as subscriber

PLUGIN Wp Fastest Cache

CVE-2021-24869

HIGH CVSS 8.8 2024-01-16
Threat Entry Updated 2025-05-12

CVE-2021-24870 - Wp Fastest Cache Plugin

The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload

PLUGIN Wp Fastest Cache

CVE-2021-24870

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2024-11-21

CVE-2021-24567 - Simple Post Plugin

The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.

PLUGIN Simple Post

CVE-2021-24567

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2021-4227 - Ark Commenteditor Plugin

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section

PLUGIN Ark Commenteditor

CVE-2021-4227

MEDIUM CVSS 5.3 2024-01-16
Threat Entry Updated 2025-06-17

CVE-2021-25117 - Wp Postratings Plugin

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.

PLUGIN Wp Postratings

CVE-2021-25117

MEDIUM CVSS 4.8 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2021-24151 - Before 1 Plugin

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.

PLUGIN Before 1

CVE-2021-24151

HIGH CVSS 7.2 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2021-24559 - Before 0 Plugin

The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site Scripting attacks. Furthermore, the data_uri_to_meta AJAX action, available to all authenticated users, only had a CSRF check in place, with the nonce available to users with a role as low as Contributor allowing any user with such role (and above) to set a malicious data-uri in arbitrary QR Code posts, leading to a Stored Cross-Site Scripting issue.

PLUGIN Before 0

CVE-2021-24559

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2021-24433 - Through 0 Plugin

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use allowed URL protocols, which can lead to stored cross-site scripting by users with a role as low as Contributor

PLUGIN Through 0

CVE-2021-24433

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-11

CVE-2023-6623 - Essential Blocks Plugin

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.

PLUGIN Essential Blocks

CVE-2023-6623

CRITICAL CVSS 9.8 2024-01-15
Threat Entry Updated 2025-06-03

CVE-2023-6049 - Estatik Real Estate Plugin

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog

PLUGIN Estatik Real Estate

CVE-2023-6049

CRITICAL CVSS 9.8 2024-01-15
Threat Entry Updated 2025-06-11

CVE-2023-6991 - Before 2 Plugin

The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow users with contributor role and above to perform SSRF attacks.

PLUGIN Before 2

CVE-2023-6991

HIGH CVSS 8.8 2024-01-15
Scroll to top