Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,213
Critical1,006
High3,355
Medium11,600
Reset
Showing 12421-12440 of 16213 records
Threat Entry Updated 2024-11-21

CVE-2023-6488 - Shortcodes Ultimate Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_button', 'su_members', and 'su_tabs' shortcodes in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shortcodes Ultimate

CVE-2023-6488

MEDIUM CVSS 5.4 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-46154 - E2pdf Plugin

Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.18.

PLUGIN E2pdf

CVE-2023-46154

MEDIUM CVSS 6.6 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-49821 - Wp Live Chat Plugin

Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.

PLUGIN Wp Live Chat

CVE-2023-49821

MEDIUM CVSS 5.4 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6295 - Siteorigin Widgets Bundle Plugin

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

PLUGIN Siteorigin Widgets Bundle

CVE-2023-6295

HIGH CVSS 7.2 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6272 - Theme My Login 2fa Plugin

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

PLUGIN Theme My Login 2fa

CVE-2023-6272

CRITICAL CVSS 9.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-5886 - Wp All Export Pro Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.

PLUGIN Wp All Export Pro

CVE-2023-5886

HIGH CVSS 8.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-5882 - Wp All Export Pro Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.

PLUGIN Wp All Export Pro

CVE-2023-5882

HIGH CVSS 8.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-4311 - Vrm360 Plugin

The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode.

PLUGIN Vrm360

CVE-2023-4311

HIGH CVSS 8.8 2023-12-18
Threat Entry Updated 2025-05-20

CVE-2023-4724 - Wp All Export Pro Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server

PLUGIN Wp All Export Pro

CVE-2023-4724

HIGH CVSS 7.2 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6077 - Before 3 Plugin

The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected

PLUGIN Before 3

CVE-2023-6077

MEDIUM CVSS 6.5 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6065 - Quttera Web Malware Scanner Plugin

The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code

PLUGIN Quttera Web Malware Scanner

CVE-2023-6065

MEDIUM CVSS 5.3 2023-12-18
Threat Entry Updated 2025-05-07

CVE-2023-5005 - Autocomplete Location Field Contact Form 7 Plugin

The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-pro WordPress plugin before 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Autocomplete Location Field Contact Form 7

CVE-2023-5005

MEDIUM CVSS 4.8 2023-12-18
Threat Entry Updated 2025-05-07

CVE-2023-6289 - Swift Performance Lite Plugin

The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.

PLUGIN Swift Performance Lite

CVE-2023-6289

MEDIUM CVSS 4.3 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6559 - Mw Wp Form Plugin

The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.

PLUGIN Mw Wp Form

CVE-2023-6559

HIGH CVSS 7.5 2023-12-16
Threat Entry Updated 2024-11-21

CVE-2023-49187 - Adifier Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spoonthemes Adifier - Classified Ads WordPress Theme allows Reflected XSS.This issue affects Adifier - Classified Ads WordPress Theme: from n/a before 3.1.4.

PLUGIN Adifier

CVE-2023-49187

HIGH CVSS 7.1 2023-12-15
Scroll to top