Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12321-12340 of 16202 records
Threat Entry Updated 2024-11-21

CVE-2023-52128 - White Label Plugin

Cross-Site Request Forgery (CSRF) vulnerability in WhiteWP White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard.This issue affects White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard: from n/a through 2.9.0.

PLUGIN White Label

CVE-2023-52128

MEDIUM CVSS 4.3 2024-01-05
Threat Entry Updated 2024-11-21

CVE-2023-6493 - Depicter Slider Plugin

The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2023-51491 appears to be a duplicate of this issue.

PLUGIN Depicter Slider

CVE-2023-6493

MEDIUM CVSS 4.3 2024-01-05
Threat Entry Updated 2024-11-21

CVE-2023-7044 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ID in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access and higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons For Elementor

CVE-2023-7044

MEDIUM CVSS 6.4 2024-01-04
Threat Entry Updated 2024-11-21

CVE-2023-6733 - Wp Members Plugin

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including user emails, password hashes, usernames, and more.

PLUGIN Wp Members

CVE-2023-6733

MEDIUM CVSS 6.5 2024-01-04
Threat Entry Updated 2024-11-21

CVE-2023-6738 - Pagelayer Plugin

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This appears to be a reintroduction of a vulnerability patched in version 1.7.7.

PLUGIN Pagelayer

CVE-2023-6738

MEDIUM CVSS 5.4 2024-01-04
Threat Entry Updated 2024-11-21

CVE-2023-6498 - Ccpa Cookie Consent Plugin

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Ccpa Cookie Consent

CVE-2023-6498

MEDIUM CVSS 4.4 2024-01-04
Threat Entry Updated 2024-11-21

CVE-2024-0201 - Product Expiry For Woocommerce Plugin

The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function in versions up to, and including, 2.5. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.

PLUGIN Product Expiry For Woocommerce

CVE-2024-0201

MEDIUM CVSS 5.4 2024-01-03
Threat Entry Updated 2024-11-21

CVE-2023-6747 - Foogallery Plugin

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for contributors and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Foogallery

CVE-2023-6747

MEDIUM CVSS 6.4 2024-01-03
Threat Entry Updated 2025-06-18

CVE-2023-6621 - Post Smtp Plugin

The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Post Smtp

CVE-2023-6621

MEDIUM CVSS 6.1 2024-01-03
Threat Entry Updated 2025-06-03

CVE-2023-6984 - Powerpack Addons For Elementor Plugin

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13. This is due to missing or incorrect nonce validation in the powerpack-lite-for-elementor/classes/class-pp-admin-settings.php file. This makes it possible for unauthenticated attackers to modify and reset plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Powerpack Addons For Elementor

CVE-2023-6984

MEDIUM CVSS 5.3 2024-01-03
Threat Entry Updated 2024-11-21

CVE-2023-7068 - Woocommerce Pdf Invoices Packing Slips Delivery Notes And Shipping Labels Plugin

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on theprint_packinglist action in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to export orders which can contain sensitive information.

PLUGIN Woocommerce Pdf Invoices Packing Slips Delivery Notes And Shipping Labels

CVE-2023-7068

MEDIUM CVSS 4.3 2024-01-03
Threat Entry Updated 2024-11-21

CVE-2023-6986 - Embedpress Plugin

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed_oembed_html shortcode in all versions up to 3.9.5 (exclusive) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Embedpress

CVE-2023-6986

MEDIUM CVSS 6.4 2024-01-03
Threat Entry Updated 2025-06-03

CVE-2023-6600 - Omgf Plugin

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings() function hooked via admin_init in all versions up to, and including, 5.7.9. This makes it possible for unauthenticated attackers to update the plugin's settings which can be used to inject Cross-Site Scripting payloads and delete entire directories. PLease note there were several attempted patched, and we consider 5.7.10 to be the most sufficiently patched.

PLUGIN Omgf

CVE-2023-6600

HIGH CVSS 8.6 2024-01-03
Threat Entry Updated 2024-11-21

CVE-2023-6524 - Mappress Plugin

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and including 2.88.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mappress

CVE-2023-6524

MEDIUM CVSS 6.4 2024-01-03
Threat Entry Updated 2024-12-17

CVE-2023-6981 - Wp Sms Plugin

The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to SQL Injection via the 'group_id' parameter in all versions up to, and including, 6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can leveraged to achieve Reflected…

PLUGIN Wp Sms

CVE-2023-6981

MEDIUM CVSS 6.1 2024-01-03
Threat Entry Updated 2025-07-11

CVE-2023-6980 - Wp Sms Plugin

The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5. This is due to missing or incorrect nonce validation on the 'delete' action of the wp-sms-subscribers page. This makes it possible for unauthenticated attackers to delete subscribers via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Sms

CVE-2023-6980

MEDIUM CVSS 4.3 2024-01-03
Threat Entry Updated 2024-11-21

CVE-2023-7027 - Post Smtp Plugin

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Post Smtp

CVE-2023-7027

HIGH CVSS 7.2 2024-01-03
Threat Entry Updated 2024-11-21

CVE-2023-6629 - Post Smtp Plugin

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Post Smtp

CVE-2023-6629

MEDIUM CVSS 6.1 2024-01-03
Threat Entry Updated 2025-06-11

CVE-2023-6271 - Backup Migration Plugin

The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.

PLUGIN Backup Migration

CVE-2023-6271

HIGH CVSS 7.5 2024-01-01
Scroll to top