Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12361-12380 of 16202 records
Threat Entry Updated 2024-11-21

CVE-2023-40606 - Kanban Boards For Wordpress Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Kanban for WordPress Kanban Boards for WordPress.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21.

PLUGIN Kanban Boards For Wordpress

CVE-2023-40606

CRITICAL CVSS 9.1 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50845 - Geodirectory Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins GeoDirectory – WordPress Business Directory Plugin, or Classified Directory.This issue affects GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: from n/a through 2.3.28.

PLUGIN Geodirectory

CVE-2023-50845

HIGH CVSS 7.6 2023-12-28
Threat Entry Updated 2024-11-21

CVE-2023-50849 - E2pdf Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.23.

PLUGIN E2pdf

CVE-2023-50849

HIGH CVSS 7.6 2023-12-28
Threat Entry Updated 2024-11-21

CVE-2023-50856 - Funnel Builder Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize Profits.This issue affects Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize Profits: from n/a through 2.14.3.

PLUGIN Funnel Builder

CVE-2023-50856

HIGH CVSS 7.6 2023-12-28
Threat Entry Updated 2024-12-17

CVE-2023-27447 - Wp Sms Plugin

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc.This issue affects WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc: from n/a through 6.0.4.

PLUGIN Wp Sms

CVE-2023-27447

MEDIUM CVSS 5.3 2023-12-28
Threat Entry Updated 2024-11-21

CVE-2023-51501 - Uncode Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Undsgn Uncode - Creative & WooCommerce WordPress Theme allows Reflected XSS.This issue affects Uncode - Creative & WooCommerce WordPress Theme: from n/a through 2.8.6.

PLUGIN Uncode

CVE-2023-51501

HIGH CVSS 7.1 2023-12-28
Threat Entry Updated 2024-11-21

CVE-2023-50874 - Ajax Load More Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney WordPress Infinite Scroll – Ajax Load More allows Stored XSS.This issue affects WordPress Infinite Scroll – Ajax Load More: from n/a through 6.1.0.1.

PLUGIN Ajax Load More

CVE-2023-50874

MEDIUM CVSS 6.5 2023-12-28
Threat Entry Updated 2024-11-21

CVE-2023-51700 - Unofficial Mobile Bankid Integration Plugin

Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability, specifically impacting scenarios where an attacker can manipulate the database. If unauthorized actors gain access to the database, they could exploit this vulnerability to execute object injection attacks. This could lead to unauthorized code execution, data manipulation, or data exfiltration within the WordPress environment. Users of the plugin should upgrade to version 1.0.1 (or later),…

PLUGIN Unofficial Mobile Bankid Integration

CVE-2023-51700

MEDIUM CVSS 6.4 2023-12-27
Threat Entry Updated 2024-11-21

CVE-2023-5991 - Hotel Booking Lite Plugin

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

PLUGIN Hotel Booking Lite

CVE-2023-5991

CRITICAL CVSS 9.8 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5931 - Buddypress And Bbpress Plugin

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server

PLUGIN Buddypress And Bbpress

CVE-2023-5931

HIGH CVSS 8.8 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5674 - Before 1 Plugin

The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

PLUGIN Before 1

CVE-2023-5674

HIGH CVSS 8.8 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-6250 - Before 2 Plugin

The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag

PLUGIN Before 2

CVE-2023-6250

HIGH CVSS 7.5 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-6114 - Duplicator Pro Plugin

The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.

PLUGIN Duplicator Pro

CVE-2023-6114

HIGH CVSS 7.5 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5939 - Buddypress And Bbpress Plugin

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users.

PLUGIN Buddypress And Bbpress

CVE-2023-5939

HIGH CVSS 7.2 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-6268 - Json Content Importer Plugin

The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Json Content Importer

CVE-2023-6268

MEDIUM CVSS 6.1 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-6166 - Before 6 Plugin

The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

PLUGIN Before 6

CVE-2023-6166

MEDIUM CVSS 6.1 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-6155 - Quiz Maker Plugin

The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.

PLUGIN Quiz Maker

CVE-2023-6155

MEDIUM CVSS 5.3 2023-12-26
Threat Entry Updated 2025-04-17

CVE-2023-5980 - Bsk Forms Blacklist Plugin

The BSK Forms Blacklist WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Bsk Forms Blacklist

CVE-2023-5980

MEDIUM CVSS 4.8 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5673 - Wp Mail Log Plugin

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.

PLUGIN Wp Mail Log

CVE-2023-5673

HIGH CVSS 8.8 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5645 - Wp Mail Log Plugin

The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

PLUGIN Wp Mail Log

CVE-2023-5645

HIGH CVSS 8.8 2023-12-26
Scroll to top