Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,248
Critical1,013
High3,368
Medium11,615
Reset
Showing 13021-13040 of 16248 records
Threat Entry Updated 2025-04-23

CVE-2023-4209 - Before 0 Plugin

The POEditor WordPress plugin before 0.9.8 does not have CSRF checks in various places, which could allow attackers to make logged in admins perform unwanted actions, such as reset the plugin's settings and update its API key via CSRF attacks.

PLUGIN Before 0

CVE-2023-4209

MEDIUM CVSS 4.3 2023-08-30
Threat Entry Updated 2025-04-23

CVE-2023-4013 - Before 4 Plugin

The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks

PLUGIN Before 4

CVE-2023-4013

MEDIUM CVSS 6.5 2023-08-30
Threat Entry Updated 2025-05-05

CVE-2023-3720 - Upload Media By Url Plugin

The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload files (including HTML containing JS code for users with the unfiltered_html capability) on their behalf.

PLUGIN Upload Media By Url

CVE-2023-3720

MEDIUM CVSS 6.5 2023-08-30
Threat Entry Updated 2025-04-23

CVE-2023-3992 - Before 3 Plugin

The PostX WordPress plugin before 3.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2023-3992

MEDIUM CVSS 6.1 2023-08-30
Threat Entry Updated 2025-04-23

CVE-2023-4035 - Simple Blog Card Plugin

The Simple Blog Card WordPress plugin before 1.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Simple Blog Card

CVE-2023-4035

MEDIUM CVSS 5.4 2023-08-30
Threat Entry Updated 2025-04-23

CVE-2023-3501 - Before 1 Plugin

The FormCraft WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2023-3501

MEDIUM CVSS 4.8 2023-08-30
Threat Entry Updated 2025-04-23

CVE-2023-4150 - User Activity Tracking And Log Plugin

The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks

PLUGIN User Activity Tracking And Log

CVE-2023-4150

MEDIUM CVSS 4.3 2023-08-30
Threat Entry Updated 2025-05-02

CVE-2023-4036 - Simple Blog Card Plugin

The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones

PLUGIN Simple Blog Card

CVE-2023-4036

MEDIUM CVSS 4.3 2023-08-30
Threat Entry Updated 2024-11-21

CVE-2023-3356 - Subscribers Text Counter Plugin

The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

PLUGIN Subscribers Text Counter

CVE-2023-3356

MEDIUM CVSS 4.3 2023-08-30
Threat Entry Updated 2024-11-21

CVE-2023-1982 - Front Editor Plugin

The Front Editor WordPress plugin through 4.0.4 does not sanitize and escape some of its form settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Front Editor

CVE-2023-1982

MEDIUM CVSS 4.8 2023-08-30
Threat Entry Updated 2024-11-21

CVE-2023-4600 - Affiliatewp Plugin

The AffiliateWP for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'affwp_activate_addons_page_plugin' function called via an AJAX action in versions up to, and including, 2.14.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to activate arbitrary plugins.

PLUGIN Affiliatewp

CVE-2023-4600

MEDIUM CVSS 4.3 2023-08-30
Threat Entry Updated 2024-11-21

CVE-2023-3136 - Mailarchiver Plugin

The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mailarchiver

CVE-2023-3136

HIGH CVSS 7.2 2023-08-30
Threat Entry Updated 2024-11-21

CVE-2023-4596 - Forminator Plugin

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Forminator

CVE-2023-4596

CRITICAL CVSS 9.8 2023-08-30
Threat Entry Updated 2024-11-21

CVE-2023-4599 - Email Encoder Plugin

The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Email Encoder

CVE-2023-4599

MEDIUM CVSS 6.4 2023-08-30
Scroll to top