Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,213
Critical1,006
High3,355
Medium11,600
Reset
Showing 12881-12900 of 16213 records
Threat Entry Updated 2024-11-21

CVE-2023-5161 - Modal Window Plugin

The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Modal Window

CVE-2023-5161

MEDIUM CVSS 6.4 2023-09-27
Threat Entry Updated 2024-11-21

CVE-2023-5135 - Simple Cloudfare Turnstile Plugin

The Simple Cloudflare Turnstile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gravity-simple-turnstile' shortcode in versions up to, and including, 1.23.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Cloudfare Turnstile

CVE-2023-5135

MEDIUM CVSS 6.4 2023-09-27
Threat Entry Updated 2024-11-21

CVE-2023-4423 - Wp Event Manager Plugin

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.1.37.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Wp Event Manager

CVE-2023-4423

MEDIUM CVSS 4.4 2023-09-27
Threat Entry Updated 2024-11-21

CVE-2023-4506 - Ldap Login For Intranet Sites Plugin

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.

PLUGIN Ldap Login For Intranet Sites

CVE-2023-4506

LOW CVSS 2.2 2023-09-27
Threat Entry Updated 2024-11-21

CVE-2023-4505 - Ldap Ad Staff Employee Directory Search Plugin

The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.

PLUGIN Ldap Ad Staff Employee Directory Search

CVE-2023-4505

LOW CVSS 2.2 2023-09-27
Threat Entry Updated 2025-04-23

CVE-2023-4521 - Import Xml And Rss Feeds Plugin

The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

PLUGIN Import Xml And Rss Feeds

CVE-2023-4521

CRITICAL CVSS 9.8 2023-09-25
Threat Entry Updated 2025-04-23

CVE-2023-4490 - Wp Job Portal Plugin

The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

PLUGIN Wp Job Portal

CVE-2023-4490

CRITICAL CVSS 9.8 2023-09-25
Threat Entry Updated 2025-04-23

CVE-2023-4300 - Import Xml And Rss Feeds Plugin

The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution.

PLUGIN Import Xml And Rss Feeds

CVE-2023-4300

HIGH CVSS 7.2 2023-09-25
Threat Entry Updated 2026-03-03

CVE-2023-4549 - Dologin Security Plugin

The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.

PLUGIN Dologin Security

CVE-2023-4549

MEDIUM CVSS 6.1 2023-09-25
Threat Entry Updated 2025-04-23

CVE-2023-4476 - Locatoraid Store Locator Plugin

The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Locatoraid Store Locator

CVE-2023-4476

MEDIUM CVSS 6.1 2023-09-25
Threat Entry Updated 2026-03-03

CVE-2023-4631 - Dologin Security Plugin

The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.

PLUGIN Dologin Security

CVE-2023-4631

MEDIUM CVSS 5.3 2023-09-25
Threat Entry Updated 2025-05-02

CVE-2023-4502 - Translate Wordpress With Gtranslate Plugin

The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). This vulnerability affects multiple parameters.

PLUGIN Translate Wordpress With Gtranslate

CVE-2023-4502

MEDIUM CVSS 4.8 2023-09-25
Threat Entry Updated 2025-04-22

CVE-2023-4238 - Folders Access Plugin

The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

PLUGIN Folders Access

CVE-2023-4238

HIGH CVSS 7.2 2023-09-25
Threat Entry Updated 2024-11-21

CVE-2023-3664 - Fileorganizer Plugin

The FileOrganizer WordPress plugin through 1.0.2 does not restrict functionality on multisite instances, allowing site admins to gain full control over the server.

PLUGIN Fileorganizer

CVE-2023-3664

HIGH CVSS 7.2 2023-09-25
Threat Entry Updated 2025-05-01

CVE-2023-4148 - Before 3 Plugin

The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 3

CVE-2023-4148

MEDIUM CVSS 6.1 2023-09-25
Threat Entry Updated 2025-04-23

CVE-2023-4281 - This Activity Log Plugin

This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

PLUGIN This Activity Log

CVE-2023-4281

MEDIUM CVSS 5.3 2023-09-25
Threat Entry Updated 2024-11-21

CVE-2023-3226 - Before 4 Plugin

The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 4

CVE-2023-3226

MEDIUM CVSS 4.8 2023-09-25
Threat Entry Updated 2024-11-21

CVE-2023-5134 - Easy Registration Forms Plugin

The Easy Registration Forms for WordPress is vulnerable to Information Disclosure via the 'erforms_user_meta' shortcode in versions up to, and including, 2.1.1 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for authenticated attackers, with subscriber-level capabilities or above, to retrieve arbitrary sensitive user meta.

PLUGIN Easy Registration Forms

CVE-2023-5134

MEDIUM CVSS 4.3 2023-09-23
Scroll to top