Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,246
Critical1,011
High3,368
Medium11,615
Reset
Showing 12941-12960 of 16246 records
Threat Entry Updated 2024-11-21

CVE-2023-5054 - Super Store Finder Plugin

The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9.3. This is due to insufficient restrictions on the sendMail.php file that allows direct access. This makes it possible for unauthenticated attackers to send emails utilizing the vulnerable site's server, with arbitrary content. Please note that this vulnerability has already been publicly disclosed with an exploit which is why we are publishing the details without a patch available, we are attempting to initiate contact with the developer.

PLUGIN Super Store Finder

CVE-2023-5054

MEDIUM CVSS 5.8 2023-09-19
Threat Entry Updated 2024-11-21

CVE-2023-3025 - Dropbox Folder Share Plugin

The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.9.7 via the 'link' parameter. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Dropbox Folder Share

CVE-2023-3025

HIGH CVSS 7.2 2023-09-16
Threat Entry Updated 2024-11-21

CVE-2023-5001 - Horizontal Scrolling Announcement Plugin

The Horizontal scrolling announcement for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'horizontal-scrolling' shortcode in versions up to, and including, 9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Horizontal Scrolling Announcement

CVE-2023-5001

MEDIUM CVSS 6.4 2023-09-16
Threat Entry Updated 2024-11-21

CVE-2023-4994 - Allow Php In Posts And Pages Plugin

The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.

PLUGIN Allow Php In Posts And Pages

CVE-2023-4994

CRITICAL CVSS 9.9 2023-09-16
Threat Entry Updated 2024-11-21

CVE-2023-4963 - Ws Facebook Like Box Widget Plugin

The WS Facebook Like Box Widget for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ws-facebook-likebox' shortcode in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ws Facebook Like Box Widget

CVE-2023-4963

MEDIUM CVSS 6.4 2023-09-15
Threat Entry Updated 2024-11-21

CVE-2023-4948 - Woocommerce Cvr Payment Gateway Plugin

The WooCommerce CVR Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_cvr_data AJAX action in versions up to 6.1.0. This makes it possible for authenticated attackers with contributor-level access and above, to update CVR numbers for orders.

PLUGIN Woocommerce Cvr Payment Gateway

CVE-2023-4948

MEDIUM CVSS 4.3 2023-09-14
Threat Entry Updated 2024-11-21

CVE-2023-4945 - Booster For Woocommerce Plugin

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in versions up to, and including, 7.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Booster For Woocommerce

CVE-2023-4945

MEDIUM CVSS 6.4 2023-09-14
Threat Entry Updated 2024-11-21

CVE-2023-4944 - Awesome Weather Widget Plugin

The Awesome Weather Widget for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' shortcode in versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Awesome Weather Widget

CVE-2023-4944

MEDIUM CVSS 6.4 2023-09-14
Threat Entry Updated 2024-11-21

CVE-2023-4841 - Feeds For Youtube Plugin

The Feeds for YouTube for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Feeds For Youtube

CVE-2023-4841

MEDIUM CVSS 6.4 2023-09-14
Threat Entry Updated 2024-11-21

CVE-2023-4916 - Login With Phone Number Plugin

The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function. This makes it possible for unauthenticated attackers to change user password via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Login With Phone Number

CVE-2023-4916

HIGH CVSS 8.8 2023-09-13
Threat Entry Updated 2024-11-21

CVE-2023-4917 - Leyka Plugin

The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.3 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.

PLUGIN Leyka

CVE-2023-4917

MEDIUM CVSS 5.3 2023-09-13
Threat Entry Updated 2024-11-21

CVE-2023-4915 - Wp User Control Plugin

The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.5.3. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (in the WP User Control Widget). The function changes the user's password after providing the email. The new password is only sent to the user's email, so the attacker does not have access to the new password.

PLUGIN Wp User Control

CVE-2023-4915

MEDIUM CVSS 5.3 2023-09-13
Threat Entry Updated 2024-11-21

CVE-2023-4213 - Simplr Registration Form Plus Plugin

The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.4.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with subscriber-level permissions or above to change user passwords and potentially take over administrator accounts.

PLUGIN Simplr Registration Form Plus

CVE-2023-4213

HIGH CVSS 8.8 2023-09-13
Threat Entry Updated 2024-11-21

CVE-2023-4153 - Ban Users Plugin

The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to a missing capability check on the 'w3dev_save_ban_user_settings_callback' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify the plugin settings to access the ban and unban functionality and set the role of the unbanned user.

PLUGIN Ban Users

CVE-2023-4153

HIGH CVSS 8.8 2023-09-13
Threat Entry Updated 2024-11-21

CVE-2023-4893 - Crayon Syntax Highlighter Plugin

The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and including, 2.8.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Crayon Syntax Highlighter

CVE-2023-4893

MEDIUM CVSS 6.4 2023-09-12
Threat Entry Updated 2024-11-21

CVE-2023-4890 - Jquery Accordion Menu Widget Plugin

The JQuery Accordion Menu Widget for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcwp-jquery-accordion' shortcode in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Jquery Accordion Menu Widget

CVE-2023-4890

MEDIUM CVSS 6.4 2023-09-12
Threat Entry Updated 2024-11-21

CVE-2023-4887 - Google Maps Plugin By Intergeo

The Google Maps Plugin by Intergeo for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Google Maps Plugin By Intergeo

CVE-2023-4887

MEDIUM CVSS 6.4 2023-09-12
Threat Entry Updated 2024-11-21

CVE-2023-4840 - Mappress Plugin

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortcode in versions up to, and including, 2.88.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mappress

CVE-2023-4840

MEDIUM CVSS 6.4 2023-09-12
Threat Entry Updated 2025-04-23

CVE-2023-4314 - Before 2 Plugin

The wpDataTables WordPress plugin before 2.1.66 does not validate the "Serialized PHP array" input data before deserializing the data. This allows admins to deserialize arbitrary data which may lead to remote code execution if a suitable gadget chain is present on the server. This is impactful in environments where admin users should not be allowed to execute arbitrary code, such as multisite.

PLUGIN Before 2

CVE-2023-4314

HIGH CVSS 7.2 2023-09-11
Threat Entry Updated 2025-04-23

CVE-2023-4318 - Herd Effects Plugin

The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack

PLUGIN Herd Effects

CVE-2023-4318

MEDIUM CVSS 4.3 2023-09-11
Scroll to top