Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,213
Critical1,006
High3,355
Medium11,600
Reset
Showing 12501-12520 of 16213 records
Threat Entry Updated 2024-11-21

CVE-2023-6219 - Bookingpress Plugin

The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'bookingpress_process_upload' function in versions up to, and including, 1.0.76. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Bookingpress

CVE-2023-6219

HIGH CVSS 7.2 2023-11-28
Threat Entry Updated 2024-11-21

CVE-2023-5604 - Asgaros Forum Plugin

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.

PLUGIN Asgaros Forum

CVE-2023-5604

CRITICAL CVSS 9.8 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5906 - Before 1 Plugin

The Job Manager & Career WordPress plugin before 1.4.4 contains a vulnerability in the Directory Listings system, which allows an unauthorized user to view and download private files of other users. This vulnerability poses a serious security threat because it allows an attacker to gain access to confidential data and files of other users without their permission.

PLUGIN Before 1

CVE-2023-5906

HIGH CVSS 7.5 2023-11-27
Threat Entry Updated 2025-06-04

CVE-2023-5958 - Post Smtp Mailer Plugin

The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.

PLUGIN Post Smtp Mailer

CVE-2023-5958

MEDIUM CVSS 6.1 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5653 - Wassup Real Time Analytics Plugin

The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins

PLUGIN Wassup Real Time Analytics

CVE-2023-5653

MEDIUM CVSS 6.1 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5641 - Easy Seo Backlink Link Building Network Plugin

The Martins Free & Easy SEO BackLink Link Building Network WordPress plugin before 1.2.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Easy Seo Backlink Link Building Network

CVE-2023-5641

MEDIUM CVSS 6.1 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5942 - Before 1 Plugin

The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-5942

MEDIUM CVSS 5.4 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5738 - Before 1 Plugin

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-5738

MEDIUM CVSS 5.4 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5620 - Web Push Notifications Plugin

The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.

PLUGIN Web Push Notifications

CVE-2023-5620

MEDIUM CVSS 5.4 2023-11-27
Threat Entry Updated 2025-01-16

CVE-2023-5611 - Seraphinite Accelerator Plugin

The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them

PLUGIN Seraphinite Accelerator

CVE-2023-5611

MEDIUM CVSS 5.3 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5737 - Before 1 Plugin

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.

PLUGIN Before 1

CVE-2023-5737

MEDIUM CVSS 4.3 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5559 - 10web Booster Plugin

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

PLUGIN 10web Booster

CVE-2023-5559

CRITICAL CVSS 9.1 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5239 - Malware Scan By Cleantalk Plugin

The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.

PLUGIN Malware Scan By Cleantalk

CVE-2023-5239

HIGH CVSS 7.5 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5560 - Wp Useronline Plugin

The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputting its content on the page, which allows unauthenticated users to perform Cross-Site Scripting attacks.

PLUGIN Wp Useronline

CVE-2023-5560

MEDIUM CVSS 6.1 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-4642 - Kk Star Ratings Plugin

The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.

PLUGIN Kk Star Ratings

CVE-2023-4642

MEDIUM CVSS 5.9 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-4514 - Mmm Simple File List Plugin

The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Mmm Simple File List

CVE-2023-4514

MEDIUM CVSS 5.4 2023-11-27
Scroll to top