Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12341-12360 of 16202 records
Threat Entry Updated 2025-06-18

CVE-2023-6113 - Wp Staging Plugin

The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information about ongoing backups processes, allowing unauthenticated attackers to download said backups later.

PLUGIN Wp Staging

CVE-2023-6113

HIGH CVSS 7.5 2024-01-01
Threat Entry Updated 2025-06-18

CVE-2023-6000 - Popup Builder Plugin

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

PLUGIN Popup Builder

CVE-2023-6000

MEDIUM CVSS 6.1 2024-01-01
Threat Entry Updated 2025-06-18

CVE-2023-6485 - Html5 Video Player Plugin

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins

PLUGIN Html5 Video Player

CVE-2023-6485

MEDIUM CVSS 5.4 2024-01-01
Threat Entry Updated 2025-06-18

CVE-2023-6037 - Wp Tripadvisor Review Slider Plugin

The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wp Tripadvisor Review Slider

CVE-2023-6037

MEDIUM CVSS 4.8 2024-01-01
Threat Entry Updated 2025-06-03

CVE-2023-5877 - Affiliate Toolkit Plugin

The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.

PLUGIN Affiliate Toolkit

CVE-2023-5877

CRITICAL CVSS 9.8 2024-01-01
Threat Entry Updated 2024-11-21

CVE-2023-51547 - Fluent Support Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin.This issue affects Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin: from n/a through 1.7.6.

PLUGIN Fluent Support

CVE-2023-51547

HIGH CVSS 7.6 2023-12-31
Threat Entry Updated 2024-11-21

CVE-2023-52134 - Geo My Wordpress Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.0.2.

PLUGIN Geo My Wordpress

CVE-2023-52134

HIGH CVSS 7.6 2023-12-31
Threat Entry Updated 2024-11-21

CVE-2023-52185 - Everest Backup Plugin

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Everestthemes Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin.This issue affects Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin: from n/a through 2.1.9.

PLUGIN Everest Backup

CVE-2023-52185

MEDIUM CVSS 5.3 2023-12-31
Threat Entry Updated 2024-11-21

CVE-2023-52182 - Ari Stream Quiz Plugin

Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.

PLUGIN Ari Stream Quiz

CVE-2023-52182

CRITICAL CVSS 9.9 2023-12-31
Threat Entry Updated 2024-11-21

CVE-2023-51688 - Ecommerce Product Catalog Plugin

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Plugin for WordPress: from n/a through 3.3.26.

PLUGIN Ecommerce Product Catalog

CVE-2023-51688

MEDIUM CVSS 5.3 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-51419 - Bertha Ai Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Bertha.Ai BERTHA AI. Your AI co-pilot for WordPress and Chrome.This issue affects BERTHA AI. Your AI co-pilot for WordPress and Chrome: from n/a through 1.11.10.7.

PLUGIN Bertha Ai

CVE-2023-51419

CRITICAL CVSS 10.0 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50893 - Impreza Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution Impreza – WordPress Website and WooCommerce Builder allows Reflected XSS.This issue affects Impreza – WordPress Website and WooCommerce Builder: from n/a through 8.17.4.

PLUGIN Impreza

CVE-2023-50893

HIGH CVSS 7.1 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50892 - Thegem Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme allows Reflected XSS.This issue affects TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme: from n/a through 5.9.1.

PLUGIN Thegem

CVE-2023-50892

HIGH CVSS 7.1 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50891 - This Issue Affects Form Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Form plugin for WordPress – Zoho Forms allows Stored XSS.This issue affects Form plugin for WordPress – Zoho Forms: from n/a through 3.0.1.

PLUGIN This Issue Affects Form

CVE-2023-50891

MEDIUM CVSS 6.5 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50889 - Beaver Builder Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder – WordPress Page Builder allows Stored XSS.This issue affects Beaver Builder – WordPress Page Builder: from n/a through 2.7.2.

PLUGIN Beaver Builder

CVE-2023-50889

MEDIUM CVSS 6.5 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50879 - Wordpress Com Editing Toolkit Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress.Com Editing Toolkit allows Stored XSS.This issue affects WordPress.Com Editing Toolkit: from n/a through 3.78784.

PLUGIN Wordpress Com Editing Toolkit

CVE-2023-50879

MEDIUM CVSS 6.5 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-52135 - Ws Form Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WS Form WS Form LITE – Drag & Drop Contact Form Builder for WordPress.This issue affects WS Form LITE – Drag & Drop Contact Form Builder for WordPress: from n/a through 1.9.170.

PLUGIN Ws Form

CVE-2023-52135

HIGH CVSS 7.6 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-51372 - Hashbar Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HashBar – WordPress Notification Bar allows Stored XSS.This issue affects HashBar – WordPress Notification Bar: from n/a through 1.4.1.

PLUGIN Hashbar

CVE-2023-51372

MEDIUM CVSS 5.9 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50896 - Weforms Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weForms weForms – Easy Drag & Drop Contact Form Builder For WordPress allows Stored XSS.This issue affects weForms – Easy Drag & Drop Contact Form Builder For WordPress: from n/a through 1.6.17.

PLUGIN Weforms

CVE-2023-50896

MEDIUM CVSS 5.9 2023-12-29
Scroll to top