Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12381-12400 of 16202 records
Threat Entry Updated 2024-11-21

CVE-2023-5644 - Before 1 Plugin

The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.

PLUGIN Before 1

CVE-2023-5644

HIGH CVSS 7.6 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5203 - Wp Sessions Time Monitoring Full Automatic Plugin

The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.

PLUGIN Wp Sessions Time Monitoring Full Automatic

CVE-2023-5203

HIGH CVSS 7.5 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5672 - Before 1 Plugin

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.

PLUGIN Before 1

CVE-2023-5672

MEDIUM CVSS 6.5 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-6744 - Divi Plugin

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Divi

CVE-2023-6744

MEDIUM CVSS 6.4 2023-12-23
Threat Entry Updated 2024-11-21

CVE-2023-6971 - Backup Migration Plugin

The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability requires that the target server's php.ini is configured with 'allow_url_include' set to 'on'. This feature is deprecated as of PHP 7.4 and is disabled by default, but can still be explicitly enabled in later versions of PHP.

PLUGIN Backup Migration

CVE-2023-6971

HIGH CVSS 8.1 2023-12-23
Threat Entry Updated 2024-11-21

CVE-2023-6972 - Backup Migration Plugin

The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.

PLUGIN Backup Migration

CVE-2023-6972

HIGH CVSS 7.5 2023-12-23
Threat Entry Updated 2024-11-21

CVE-2023-7002 - Backup Migration Plugin

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.

PLUGIN Backup Migration

CVE-2023-7002

HIGH CVSS 7.2 2023-12-23
Threat Entry Updated 2024-11-21

CVE-2023-47191 - Youzify Plugin

Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: from n/a through 1.2.2.

PLUGIN Youzify

CVE-2023-47191

MEDIUM CVSS 6.5 2023-12-21
Threat Entry Updated 2024-11-21

CVE-2023-50828 - Ultimate Dashboard Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard – Custom WordPress Dashboard: from n/a through 3.7.11.

PLUGIN Ultimate Dashboard

CVE-2023-50828

MEDIUM CVSS 5.9 2023-12-21
Threat Entry Updated 2024-11-21

CVE-2023-50824 - Insert Or Embed Articulate Content Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS.This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000021.

PLUGIN Insert Or Embed Articulate Content

CVE-2023-50824

MEDIUM CVSS 6.5 2023-12-21
Threat Entry Updated 2024-11-21

CVE-2023-48288 - Jobwp Plugin

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment Plugin – JobWP: from n/a through 2.1.

PLUGIN Jobwp

CVE-2023-48288

HIGH CVSS 7.5 2023-12-21
Threat Entry Updated 2024-11-21

CVE-2023-49162 - Bigcommerce Plugin

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BigCommerce BigCommerce For WordPress.This issue affects BigCommerce For WordPress: from n/a through 5.0.6.

PLUGIN Bigcommerce

CVE-2023-49162

MEDIUM CVSS 5.3 2023-12-21
Threat Entry Updated 2024-11-21

CVE-2023-28421 - Wp Email Capture Plugin

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugin – WP Email Capture.This issue affects WordPress Email Marketing Plugin – WP Email Capture: from n/a through 3.10.

PLUGIN Wp Email Capture

CVE-2023-28421

MEDIUM CVSS 5.3 2023-12-21
Threat Entry Updated 2024-11-21

CVE-2023-49826 - Soledad Plugin

Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

PLUGIN Soledad

CVE-2023-49826

HIGH CVSS 8.1 2023-12-21
Threat Entry Updated 2024-11-21

CVE-2023-29384 - Jobwp Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment Plugin – JobWP: from n/a through 2.0.

PLUGIN Jobwp

CVE-2023-29384

CRITICAL CVSS 10.0 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-49752 - Adifier Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoon themes Adifier - Classified Ads WordPress Theme.This issue affects Adifier - Classified Ads WordPress Theme: from n/a before 3.1.4.

PLUGIN Adifier

CVE-2023-49752

CRITICAL CVSS 9.3 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-29096 - Messages Database Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress.This issue affects Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress: from n/a through 1.7.0.

PLUGIN Messages Database

CVE-2023-29096

HIGH CVSS 8.5 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-29432 - Houzez Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme.This issue affects Houzez - Real Estate WordPress Theme: from n/a before 2.8.3.

PLUGIN Houzez

CVE-2023-29432

HIGH CVSS 8.2 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-28788 - Most Wanted Analytics Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 6.4.2.

PLUGIN Most Wanted Analytics

CVE-2023-28788

HIGH CVSS 7.1 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-30750 - Cm Popup Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.

PLUGIN Cm Popup

CVE-2023-30750

HIGH CVSS 8.5 2023-12-20
Scroll to top