Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,246
Critical1,011
High3,368
Medium11,615
Reset
Showing 12981-13000 of 16246 records
Threat Entry Updated 2025-03-06

CVE-2023-4284 - Post Timeline Plugin

The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Post Timeline

CVE-2023-4284

MEDIUM CVSS 6.1 2023-09-04
Threat Entry Updated 2025-03-06

CVE-2023-4151 - Store Locator Plugin

The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Store Locator

CVE-2023-4151

MEDIUM CVSS 6.1 2023-09-04
Threat Entry Updated 2025-04-23

CVE-2023-4298 - Before 1 Plugin

The 123.chat WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2023-4298

MEDIUM CVSS 4.8 2023-09-04
Threat Entry Updated 2025-05-12

CVE-2023-4254 - Ai Chatbot Plugin

The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Ai Chatbot

CVE-2023-4254

MEDIUM CVSS 4.8 2023-09-04
Threat Entry Updated 2025-05-12

CVE-2023-4253 - Ai Chatbot Plugin

The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Ai Chatbot

CVE-2023-4253

MEDIUM CVSS 4.8 2023-09-04
Threat Entry Updated 2025-04-23

CVE-2023-4269 - User Activity Log Plugin

The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.

PLUGIN User Activity Log

CVE-2023-4269

MEDIUM CVSS 4.3 2023-09-04
Threat Entry Updated 2025-03-06

CVE-2023-4059 - Profile Builder Plugin

The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog

PLUGIN Profile Builder

CVE-2023-4059

MEDIUM CVSS 4.3 2023-09-04
Threat Entry Updated 2025-04-23

CVE-2023-4216 - Orders Tracking For Woocommerce Plugin

The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however limited to the first line of the file.

PLUGIN Orders Tracking For Woocommerce

CVE-2023-4216

LOW CVSS 2.7 2023-09-04
Threat Entry Updated 2025-03-06

CVE-2023-3814 - Advanced File Manager Plugin

The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.

PLUGIN Advanced File Manager

CVE-2023-3814

MEDIUM CVSS 4.9 2023-09-04
Threat Entry Updated 2025-04-23

CVE-2023-3499 - Slider In Rbs Image Gallery Plugin

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Slider In Rbs Image Gallery

CVE-2023-3499

MEDIUM CVSS 4.8 2023-09-04
Threat Entry Updated 2024-11-21

CVE-2023-2813 - Restaurant Pt Plugin

All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite WordPress theme before 2.1, Cafe Bistro WordPress theme before 1.1.4, College WordPress theme before 1.5.1, Connections Reloaded WordPress theme through 3.1, Counterpoint WordPress theme through 1.8.1, Digitally WordPress theme through 1.0.8, Directory WordPress theme before 3.0.2, Drop WordPress theme before 1.22, Everse WordPress theme before 1.2.4, Fashionable…

PLUGIN Restaurant Pt

CVE-2023-2813

MEDIUM CVSS 6.1 2023-09-04
Threat Entry Updated 2024-11-21

CVE-2023-4718 - Font Awesome 4 Menus Plugin

The Font Awesome 4 Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fa' and 'fa-stack' shortcodes in versions up to, and including, 4.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Font Awesome 4 Menus

CVE-2023-4718

MEDIUM CVSS 6.4 2023-09-02
Threat Entry Updated 2024-11-21

CVE-2023-4471 - Order Tracking Plugin

The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_date parameters in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Order Tracking

CVE-2023-4471

MEDIUM CVSS 6.1 2023-08-31
Threat Entry Updated 2024-11-21

CVE-2023-4315 - Woo Custom Emails Plugin

The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the wcemails_edit parameter in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Woo Custom Emails

CVE-2023-4315

MEDIUM CVSS 6.1 2023-08-31
Threat Entry Updated 2024-11-21

CVE-2023-4500 - Order Tracking Plugin

The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers (admin or higher) to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Order Tracking

CVE-2023-4500

MEDIUM CVSS 4.7 2023-08-31
Threat Entry Updated 2024-11-21

CVE-2023-3677 - Woocommerce Pdf Invoice Builder Plugin

The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in versions up to, and including, 1.2.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for subscribers or higher to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Woocommerce Pdf Invoice Builder

CVE-2023-3677

HIGH CVSS 8.8 2023-08-31
Threat Entry Updated 2024-11-21

CVE-2023-3636 - Wp Project Manager Plugin

The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'usernames' parameter.

PLUGIN Wp Project Manager

CVE-2023-3636

HIGH CVSS 8.8 2023-08-31
Threat Entry Updated 2024-11-21

CVE-2023-4000 - Waiting Plugin

The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.2. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to create and delete countdowns, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Waiting

CVE-2023-4000

MEDIUM CVSS 6.3 2023-08-31
Scroll to top