Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12261-12280 of 16202 records
Threat Entry Updated 2025-06-03

CVE-2023-6637 - Complete Analytics Optimization Suite Plugin

The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_settings' function in versions up to, and including, 4.7.14. This makes it possible for unauthenticated attackers to update plugin settings.

PLUGIN Complete Analytics Optimization Suite

CVE-2023-6637

MEDIUM CVSS 6.5 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6632 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Happy Addons For Elementor

CVE-2023-6632

MEDIUM CVSS 6.1 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6624 - Import And Export Users And Customers Plugin

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Import And Export Users And Customers

CVE-2023-6624

MEDIUM CVSS 4.9 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6567 - Learnpress Plugin

The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Learnpress

CVE-2023-6567

CRITICAL CVSS 9.8 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6558 - Import Export Wordpress Users Plugin

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for authenticated attackers with shop manager-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Import Export Wordpress Users

CVE-2023-6558

HIGH CVSS 7.2 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6583 - Import And Export Users And Customers Plugin

The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary files on the server including wp-config.php, which can contain sensitive information.

PLUGIN Import And Export Users And Customers

CVE-2023-6583

MEDIUM CVSS 6.6 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6561 - Featured Image From Url Plugin

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured image alt text in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Featured Image From Url

CVE-2023-6561

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6582 - Elements Kit Elementor Addons Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft, private or pending review status that should not be visible to the general public. This applies to posts created with Elementor only.

PLUGIN Elements Kit Elementor Addons

CVE-2023-6582

MEDIUM CVSS 5.3 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6598 - Speedycache Plugin

The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the speedycache_save_varniship, speedycache_img_update_settings, speedycache_preloading_add_settings, and speedycache_preloading_delete_resource functions in all versions up to, and including, 1.1.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to update plugin options.

PLUGIN Speedycache

CVE-2023-6598

MEDIUM CVSS 4.3 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6316 - Mw Wp Form Plugin

The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Mw Wp Form

CVE-2023-6316

CRITICAL CVSS 9.8 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6266 - Backup Migration Plugin

The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers to download back-up files which can contain sensitive information such as user passwords, PII, database credentials, and much more.

PLUGIN Backup Migration

CVE-2023-6266

HIGH CVSS 7.5 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6556 - Fox Currency Switcher Professional For Woocommerce Plugin

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Fox Currency Switcher Professional For Woocommerce

CVE-2023-6556

MEDIUM CVSS 5.4 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6369 - Export Wp Page To Static Html Css Plugin

The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 2.1.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose sensitive information or perform unauthorized actions, such as saving advanced plugin settings.

PLUGIN Export Wp Page To Static Html Css

CVE-2023-6369

MEDIUM CVSS 5.4 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6496 - Manage Notification E Mails Plugin

The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_famne_export_settings function. This makes it possible for unauthenticated attackers to obtain plugin settings.

PLUGIN Manage Notification E Mails

CVE-2023-6496

MEDIUM CVSS 5.3 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6504 - Profile Builder Plugin

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler function in all versions up to, and including, 3.10.7. This makes it possible for authenticated attackers, with contributor-level access and above, to expose sensitive information within user metadata.

PLUGIN Profile Builder

CVE-2023-6504

MEDIUM CVSS 4.3 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-5504 - Backwpup Plugin

The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server. Additionally, default settings will place an index.php and a .htaccess file into the chosen directory (unless already present) when the first backup job is run that are intended to prevent directory listing and file access. This means that an attacker could set the backup directory to…

PLUGIN Backwpup

CVE-2023-5504

HIGH CVSS 8.7 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-6220 - Piotnet Forms Plugin

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_form_builder' function in versions up to, and including, 1.0.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Piotnet Forms

CVE-2023-6220

HIGH CVSS 8.1 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-4962 - Video Popup Plugin

The Video PopUp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'video_popup' shortcode in versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Video Popup

CVE-2023-4962

MEDIUM CVSS 6.4 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-5691 - Chatbot Plugin

The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 2.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Chatbot

CVE-2023-5691

MEDIUM CVSS 4.4 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-4960 - Wcfm Marketplace Plugin

The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wcfm Marketplace

CVE-2023-4960

MEDIUM CVSS 6.4 2024-01-11
Scroll to top