Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,213
Critical1,006
High3,355
Medium11,600
Reset
Showing 12701-12720 of 16213 records
Threat Entry Updated 2024-11-21

CVE-2023-5583 - Wp Simple Galleries Plugin

The WP Simple Galleries plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.34 via deserialization of untrusted input from the 'wpsimplegallery_gallery' post meta via 'wpsgallery' shortcode. This allows authenticated attackers, with contributor-level permissions and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Wp Simple Galleries

CVE-2023-5583

HIGH CVSS 8.8 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5666 - Accordion Plugin

The Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcpaccordion' shortcode in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Accordion

CVE-2023-5666

MEDIUM CVSS 6.4 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5566 - Simple Shortcodes Plugin

The Simple Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Shortcodes

CVE-2023-5566

MEDIUM CVSS 6.4 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5199 - Php To Page Plugin

The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and potentially execute code on the server. While subscribers may need to poison log files or otherwise get a file installed in order to achieve remote code execution, author and above users can upload files by default and achieve remote code execution easily.

PLUGIN Php To Page

CVE-2023-5199

CRITICAL CVSS 9.9 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5315 - Google Maps Made Simple Plugin

The Google Maps made Simple plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Google Maps Made Simple

CVE-2023-5315

HIGH CVSS 8.8 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5565 - Shortcod Menu Plugin

The Shortcode Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortmenu' shortcode in versions up to, and including, 3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shortcod Menu

CVE-2023-5565

MEDIUM CVSS 6.4 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5362 - Carousel Recent Post Slider And Banner Slider Plugin

The Carousel, Recent Post Slider and Banner Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'spice_post_slider' shortcode in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Carousel Recent Post Slider And Banner Slider

CVE-2023-5362

MEDIUM CVSS 6.4 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5335 - Buzzsprout Plugin

The Buzzsprout Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buzzsprout' shortcode in versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Buzzsprout

CVE-2023-5335

MEDIUM CVSS 6.4 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5252 - Fareharbor Plugin

The FareHarbor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.6.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Fareharbor

CVE-2023-5252

MEDIUM CVSS 6.4 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5250 - Grid Plus Plugin

The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.2 via a shortcode attribute. This allows subscriber-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files with arbitrary content can be uploaded and included. This is limited to .php files.

PLUGIN Grid Plus

CVE-2023-5250

MEDIUM CVSS 6.4 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5164 - Bellows Accordion Menu Plugin

The Bellows Accordion Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bellows Accordion Menu

CVE-2023-5164

MEDIUM CVSS 6.4 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5049 - Rafflepress Plugin

The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rafflepress' and 'rafflepress_gutenberg' shortcode in versions up to, and including, 1.12.0 due to insufficient input sanitization and output escaping on 'giframe' user supplied attribute. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rafflepress

CVE-2023-5049

MEDIUM CVSS 6.4 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5251 - Grid Plus Plugin

The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid_plus_save_layout_callback' and 'grid_plus_delete_callback' functions in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with subscriber privileges or above, to add, update or delete grid layout.

PLUGIN Grid Plus

CVE-2023-5251

MEDIUM CVSS 5.4 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5426 - Post Meta Data Manager Plugin

The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_delete_user_meta, pmdm_wp_delete_term_meta, and pmdm_wp_ajax_delete_meta functions in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to delete user, term, and post meta belonging to arbitrary users.

PLUGIN Post Meta Data Manager

CVE-2023-5426

HIGH CVSS 7.5 2023-10-28
Threat Entry Updated 2024-11-21

CVE-2023-5425 - Post Meta Data Manager Plugin

The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_change_user_meta and pmdm_wp_change_post_meta functions in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to gain elevated (e.g., administrator) privileges.

PLUGIN Post Meta Data Manager

CVE-2023-5425

HIGH CVSS 8.8 2023-10-28
Threat Entry Updated 2024-11-21

CVE-2023-5821 - Thumbnail Carousel Slider Plugin

The Thumbnail carousel slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the deleteselected function. This makes it possible for unauthenticated attackers to delete sliders in bulk via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Thumbnail Carousel Slider

CVE-2023-5821

MEDIUM CVSS 4.3 2023-10-27
Threat Entry Updated 2024-11-21

CVE-2023-5820 - Thumbnail Slider With Lightbox Plugin

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Thumbnail Slider With Lightbox

CVE-2023-5820

CRITICAL CVSS 9.6 2023-10-27
Threat Entry Updated 2024-11-21

CVE-2023-5705 - Vk Filter Search Plugin

The VK Filter Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk_filter_search' shortcode in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Vk Filter Search

CVE-2023-5705

MEDIUM CVSS 6.4 2023-10-27
Threat Entry Updated 2024-11-21

CVE-2023-5817 - Neon Text Plugin

The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes (color). This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Neon Text

CVE-2023-5817

MEDIUM CVSS 6.4 2023-10-27
Threat Entry Updated 2024-11-21

CVE-2023-5774 - Animated Counters Plugin

The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Animated Counters

CVE-2023-5774

MEDIUM CVSS 6.4 2023-10-27
Scroll to top