Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,213
Critical1,006
High3,355
Medium11,600
Reset
Showing 12481-12500 of 16213 records
Threat Entry Updated 2024-11-21

CVE-2023-5210 - Amp Plus Plugin

The AMP+ Plus WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Amp Plus

CVE-2023-5210

MEDIUM CVSS 6.1 2023-12-04
Threat Entry Updated 2024-11-21

CVE-2023-5141 - Bsk Contact Form 7 Blacklist Plugin

The BSK Contact Form 7 Blacklist WordPress plugin through 1.0.1 does not sanitise and escape the inserted_count parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Bsk Contact Form 7 Blacklist

CVE-2023-5141

MEDIUM CVSS 6.1 2023-12-04
Threat Entry Updated 2024-11-21

CVE-2023-4460 - Uploading Svg Webp And Ico Files Plugin

The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

PLUGIN Uploading Svg Webp And Ico Files

CVE-2023-4460

MEDIUM CVSS 5.4 2023-12-04
Threat Entry Updated 2024-11-21

CVE-2023-5874 - Before 3 Plugin

The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2023-5874

MEDIUM CVSS 4.8 2023-12-04
Threat Entry Updated 2024-11-21

CVE-2023-5809 - Popup Box Plugin

The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Popup Box

CVE-2023-5809

MEDIUM CVSS 4.8 2023-12-04
Threat Entry Updated 2025-05-29

CVE-2023-5137 - Simply Excerpts Plugin

The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).

PLUGIN Simply Excerpts

CVE-2023-5137

MEDIUM CVSS 4.8 2023-12-04
Threat Entry Updated 2024-11-21

CVE-2023-6449 - Contact Form 7 Plugin

The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' function in versions up to, and including, 5.8.3. This makes it possible for authenticated attackers with editor-level capabilities or above to upload arbitrary files on the affected site's server, but due to the htaccess configuration, remote code cannot be executed in most cases. By default, the file will be deleted from the server immediately. However, in some cases, other plugins may…

PLUGIN Contact Form 7

CVE-2023-6449

MEDIUM CVSS 6.6 2023-12-01
Threat Entry Updated 2024-11-21

CVE-2023-6360 - My Calendar Plugin

The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.

PLUGIN My Calendar

CVE-2023-6360

HIGH CVSS 8.6 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-46086 - Affiliate Toolkit Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin allows Reflected XSS.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.4.3.

PLUGIN Affiliate Toolkit

CVE-2023-46086

HIGH CVSS 7.1 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-48754 - Delete Post Revisions Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Wap Nepal Delete Post Revisions In WordPress allows Cross Site Request Forgery.This issue affects Delete Post Revisions In WordPress: from n/a through 4.6.

PLUGIN Delete Post Revisions

CVE-2023-48754

MEDIUM CVSS 5.4 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-48328 - Nextgen Gallery Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through 3.37.

PLUGIN Nextgen Gallery

CVE-2023-48328

MEDIUM CVSS 4.3 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-5803 - Business Directory Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Business Directory Team Business Directory Plugin – Easy Listing Directories for WordPress allows Cross-Site Request Forgery.This issue affects Business Directory Plugin – Easy Listing Directories for WordPress: from n/a through 6.3.10.

PLUGIN Business Directory

CVE-2023-5803

MEDIUM CVSS 4.3 2023-11-30
Threat Entry Updated 2025-02-11

CVE-2023-37890 - Kb Support Plugin

Missing Authorization vulnerability in WPOmnia KB Support – WordPress Help Desk and Knowledge Base allows Accessing Functionality Not Properly Constrained by ACLs. Users with a role as low as a subscriber can view other customers.This issue affects KB Support – WordPress Help Desk and Knowledge Base: from n/a through 1.5.88.

PLUGIN Kb Support

CVE-2023-37890

MEDIUM CVSS 4.3 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-37867 - Yet Another Stars Rating Plugin

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: from n/a through 3.3.8.

PLUGIN Yet Another Stars Rating

CVE-2023-37867

LOW CVSS 3.7 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-48323 - Awesome Support Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.

PLUGIN Awesome Support

CVE-2023-48323

MEDIUM CVSS 4.3 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-38474 - Campaign Monitor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Reflected XSS.This issue affects Campaign Monitor for WordPress: from n/a through 2.8.12.

PLUGIN Campaign Monitor

CVE-2023-38474

HIGH CVSS 7.1 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-48322 - Employee Job Application Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eDoc Intelligence eDoc Employee Job Application – Best WordPress Job Manager for Employees allows Reflected XSS.This issue affects eDoc Employee Job Application – Best WordPress Job Manager for Employees: from n/a through 1.13.

PLUGIN Employee Job Application

CVE-2023-48322

HIGH CVSS 7.1 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-5772 - Debug Log Manager Plugin

The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the clear_log() function. This makes it possible for unauthenticated attackers to clear the debug log via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Debug Log Manager

CVE-2023-5772

MEDIUM CVSS 4.3 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-6225 - Shortcodes Ultimate Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_meta shortcode combined with post meta data in all versions up to, and including, 5.13.3 due to insufficient input sanitization and output escaping on user supplied meta values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shortcodes Ultimate

CVE-2023-6225

MEDIUM CVSS 6.4 2023-11-28
Threat Entry Updated 2024-11-21

CVE-2023-6226 - Shortcodes Ultimate Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys 'key' and 'post_id'. This makes it possible for authenticated attackers, with contributor-level access and above, to retrieve arbitrary post meta values which may contain sensitive information when combined with another plugin.

PLUGIN Shortcodes Ultimate

CVE-2023-6226

MEDIUM CVSS 4.3 2023-11-28
Scroll to top