Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12241-12260 of 16202 records
Threat Entry Updated 2024-11-21

CVE-2023-6979 - Customer Reviews For Woocommerce Plugin

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Customer Reviews For Woocommerce

CVE-2023-6979

CRITICAL CVSS 9.8 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6988 - Colibri Page Builder Plugin

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_builder_render_js shortcode in all versions up to, and including, 1.0.239 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Colibri Page Builder

CVE-2023-6988

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6934 - Limit Login Attempts Reloaded Plugin

The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Limit Login Attempts Reloaded

CVE-2023-6934

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6882 - Simple Membership Plugin

The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ parameter in all versions up to, and including, 4.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Simple Membership

CVE-2023-6882

MEDIUM CVSS 6.1 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6924 - Photo Gallery Plugin

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with administrator-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. It can also be exploited with a contributor-level permission with a page builder plugin.

PLUGIN Photo Gallery

CVE-2023-6924

MEDIUM CVSS 4.4 2024-01-11
Threat Entry Updated 2025-06-04

CVE-2023-6875 - Post Smtp Plugin

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover.

PLUGIN Post Smtp

CVE-2023-6875

CRITICAL CVSS 9.8 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6878 - Slick Social Share Buttons Plugin

The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dcssb_ajax_update' function in versions up to, and including, 2.4.11. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily.

PLUGIN Slick Social Share Buttons

CVE-2023-6878

HIGH CVSS 8.8 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6828 - Arforms Form Builder Plugin

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ arf_http_referrer_url’ parameter in all versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Arforms Form Builder

CVE-2023-6828

HIGH CVSS 7.2 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6782 - Amp For Wp Plugin

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Amp For Wp

CVE-2023-6782

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6781 - Orbit Fox Plugin

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 2.10.26 due to insufficient input sanitization and output escaping on user supplied values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Orbit Fox

CVE-2023-6781

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6855 - Paid Memberships Pro Plugin

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up to 2.12.5 (inclusive). This makes it possible for unauthenticated attackers to change membership levels including prices.

PLUGIN Paid Memberships Pro

CVE-2023-6855

MEDIUM CVSS 5.3 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6751 - Hostinger Plugin

The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_website in all versions up to, and including, 1.9.7. This makes it possible for unauthenticated attackers to enable and disable maintenance mode.

PLUGIN Hostinger

CVE-2023-6751

HIGH CVSS 7.3 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6776 - 3D FlipBook – PDF Flipbook WordPress Plugin

The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all versions up to, and including, 1.15.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN 3D FlipBook – PDF Flipbook WordPress

CVE-2023-6776

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6684 - Ibtana Plugin

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' shortcode in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on 'width' and 'height' user supplied attribute. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ibtana

CVE-2023-6684

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6645 - Post Grid Combo Plugin

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Post Grid Combo

CVE-2023-6645

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6737 - Enable Media Replace Plugin

The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG parameter in all versions up to, and including, 4.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploiting this vulnerability requires the attacker to know the ID of an attachment uploaded by the user they are attacking.

PLUGIN Enable Media Replace

CVE-2023-6737

MEDIUM CVSS 4.7 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6742 - Envira Gallery Plugin

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_gallery_insert_images' function in all versions up to, and including, 1.8.7.1. This makes it possible for authenticated attackers, with contributor access and above, to modify galleries on other users' posts.

PLUGIN Envira Gallery

CVE-2023-6742

MEDIUM CVSS 4.3 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6634 - Learnpress Plugin

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.

PLUGIN Learnpress

CVE-2023-6634

HIGH CVSS 8.1 2024-01-11
Threat Entry Updated 2025-06-10

CVE-2023-6636 - Greenshift Plugin

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'gspb_save_files' function in versions up to, and including, 7.6.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Greenshift

CVE-2023-6636

HIGH CVSS 7.2 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6638 - Gg Woo Feed Plugin

The GTG Product Feed for Shopping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_settings' function in versions up to, and including, 1.2.4. This makes it possible for unauthenticated attackers to update plugin settings.

PLUGIN Gg Woo Feed

CVE-2023-6638

MEDIUM CVSS 6.5 2024-01-11
Scroll to top