Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,213
Critical1,006
High3,355
Medium11,600
Reset
Showing 12801-12820 of 16213 records
Threat Entry Updated 2025-05-12

CVE-2023-5241 - Wpbot Plugin

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "

PLUGIN Wpbot

CVE-2023-5241

CRITICAL CVSS 9.6 2023-10-19
Threat Entry Updated 2025-05-12

CVE-2023-5212 - Wpbot Plugin

The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files on the server, which makes it possible to take over affected sites as well as others sharing the same hosting account. Version 4.9.1 originally addressed the issue, but it was reintroduced in 4.9.2 and fixed again in 4.9.3.

PLUGIN Wpbot

CVE-2023-5212

CRITICAL CVSS 9.6 2023-10-19
Threat Entry Updated 2025-05-12

CVE-2023-5204 - Wpbot Plugin

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wpbot

CVE-2023-5204

CRITICAL CVSS 9.8 2023-10-19
Threat Entry Updated 2024-11-21

CVE-2023-5639 - Team Showcase Plugin

The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tmfshortcode' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Team Showcase

CVE-2023-5639

MEDIUM CVSS 6.4 2023-10-19
Threat Entry Updated 2024-11-21

CVE-2023-5336 - Ipanorama 360 Wordpress Virtual Tour Builder Plugin

The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ipanorama 360 Wordpress Virtual Tour Builder

CVE-2023-5336

HIGH CVSS 8.8 2023-10-19
Threat Entry Updated 2024-11-21

CVE-2023-5638 - Booster For Woocommerce Plugin

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcj_image' shortcode in versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Booster For Woocommerce

CVE-2023-5638

MEDIUM CVSS 6.4 2023-10-19
Threat Entry Updated 2024-11-21

CVE-2023-4645 - Ad Inserter Plugin

The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai_ajax function. This can allow unauthenticated attackers to extract sensitive data such as post titles and slugs (including those of protected posts along with their passwords), usernames, available roles, the plugin license key provided the remote debugging option is enabled. In the default state it is disabled.

PLUGIN Ad Inserter

CVE-2023-4645

MEDIUM CVSS 5.3 2023-10-19
Threat Entry Updated 2024-11-21

CVE-2023-5621 - Thumbnail Slider With Lightbox Plugin

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title field in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Thumbnail Slider With Lightbox

CVE-2023-5621

MEDIUM CVSS 4.4 2023-10-18
Threat Entry Updated 2024-11-21

CVE-2023-4938 - Bear Woocommerce Bulk Editor And Products Manager Professional Plugin

The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.

PLUGIN Bear Woocommerce Bulk Editor And Products Manager Professional

CVE-2023-4938

MEDIUM CVSS 4.3 2023-10-18
Threat Entry Updated 2024-11-21

CVE-2023-5538 - Mpoperationlogs Plugin

The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mpoperationlogs

CVE-2023-5538

HIGH CVSS 7.2 2023-10-18
Threat Entry Updated 2024-11-21

CVE-2023-3254 - Widgets For Google Reviews Plugin

The Widgets for Google Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.9. This is due to missing or incorrect nonce validation within setup_no_reg_header.php. This makes it possible for unauthenticated attackers to reset plugin settings and remove reviews via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Widgets For Google Reviews

CVE-2023-3254

MEDIUM CVSS 4.3 2023-10-18
Threat Entry Updated 2025-04-23

CVE-2023-5133 - This User Activity Log Pro Plugin

This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

PLUGIN This User Activity Log Pro

CVE-2023-5133

HIGH CVSS 7.5 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-5003 - Ldap Integration Plugin

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.

PLUGIN Ldap Integration

CVE-2023-5003

HIGH CVSS 7.5 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-4971 - Weaver Xtreme Theme Support Plugin

The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.

PLUGIN Weaver Xtreme Theme Support

CVE-2023-4971

HIGH CVSS 7.2 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-4861 - File Manager Pro Plugin

The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code execution.

PLUGIN File Manager Pro

CVE-2023-4861

HIGH CVSS 7.2 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-5167 - User Activity Log Pro Plugin

The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Stored Cross-Site Scripting attacks.

PLUGIN User Activity Log Pro

CVE-2023-5167

MEDIUM CVSS 5.4 2023-10-16
Scroll to top