Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,213
Critical1,006
High3,355
Medium11,600
Reset
Showing 12861-12880 of 16213 records
Threat Entry Updated 2024-11-21

CVE-2023-5531 - Thumbnail Slider With Lightbox Plugin

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to delete image lightboxes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Thumbnail Slider With Lightbox

CVE-2023-5531

MEDIUM CVSS 4.3 2023-10-12
Threat Entry Updated 2024-11-21

CVE-2023-5468 - Slick Contact Forms Plugin

The Slick Contact Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcscf-link' shortcode in versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Slick Contact Forms

CVE-2023-5468

MEDIUM CVSS 6.4 2023-10-10
Threat Entry Updated 2024-11-21

CVE-2023-5467 - Geo My Wordpress Plugin

The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Geo My Wordpress

CVE-2023-5467

MEDIUM CVSS 6.4 2023-10-10
Threat Entry Updated 2024-11-21

CVE-2023-4469 - Profile Extra Fields Plugin

The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to expose potentially sensitive user data, including data entered into custom fields.

PLUGIN Profile Extra Fields

CVE-2023-4469

MEDIUM CVSS 5.3 2023-10-06
Threat Entry Updated 2024-11-21

CVE-2023-5357 - Instagram For Wordpress Plugin

The Instagram for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Instagram For Wordpress

CVE-2023-5357

MEDIUM CVSS 6.4 2023-10-04
Threat Entry Updated 2024-11-21

CVE-2023-5291 - Blog Filter Plugin

The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Blog Filter

CVE-2023-5291

MEDIUM CVSS 6.4 2023-10-04
Threat Entry Updated 2024-11-21

CVE-2023-3213 - Wp Mail Smtp Plugin

The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page function in versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to disclose potentially sensitive email information.

PLUGIN Wp Mail Smtp

CVE-2023-3213

MEDIUM CVSS 5.3 2023-10-04
Threat Entry Updated 2024-11-21

CVE-2023-5334 - Wp Responsive Header Image Slider Plugin

The WP Responsive header image slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sp_responsiveslider' shortcode in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Responsive Header Image Slider

CVE-2023-5334

MEDIUM CVSS 6.4 2023-10-03
Threat Entry Updated 2024-11-21

CVE-2023-5201 - Openhook Plugin

The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php] shortcode setting to be enabled on the vulnerable site.

PLUGIN Openhook

CVE-2023-5201

CRITICAL CVSS 9.9 2023-09-30
Threat Entry Updated 2024-11-21

CVE-2023-5295 - Blog Filter Plugin

The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vivafbcomment' shortcode in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Blog Filter

CVE-2023-5295

MEDIUM CVSS 6.4 2023-09-30
Threat Entry Updated 2024-11-21

CVE-2023-5233 - Font Awesome Integration Plugin

The Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fawesome' shortcode in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Font Awesome Integration

CVE-2023-5233

MEDIUM CVSS 6.4 2023-09-28
Threat Entry Updated 2024-11-21

CVE-2023-5232 - Font Awesome More Icons Plugin

The Font Awesome More Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' shortcode in versions up to, and including, 3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Font Awesome More Icons

CVE-2023-5232

MEDIUM CVSS 6.4 2023-09-28
Threat Entry Updated 2024-11-21

CVE-2023-5230 - Tm Woocommerce Compare Wishlist Plugin

The TM WooCommerce Compare & Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tm_woo_wishlist_table' shortcode in versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tm Woocommerce Compare Wishlist

CVE-2023-5230

MEDIUM CVSS 6.4 2023-09-28
Threat Entry Updated 2024-11-21

CVE-2023-5162 - Options For Twenty Seventeen Plugin

The Options for Twenty Seventeen plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social-links' shortcode in versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Options For Twenty Seventeen

CVE-2023-5162

MEDIUM CVSS 6.4 2023-09-27
Scroll to top