Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,248
Critical1,013
High3,368
Medium11,615
Reset
Showing 13121-13140 of 16248 records
Threat Entry Updated 2025-05-05

CVE-2023-3344 - Auto Location For Wp Job Manager Via Google Plugin

The Auto Location for WP Job Manager via Google WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Auto Location For Wp Job Manager Via Google

CVE-2023-3344

MEDIUM CVSS 4.8 2023-07-24
Threat Entry Updated 2025-04-23

CVE-2023-3248 - All In One Floating Contact Form Plugin

The All-in-one Floating Contact Form WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN All In One Floating Contact Form

CVE-2023-3248

MEDIUM CVSS 4.8 2023-07-24
Threat Entry Updated 2024-11-21

CVE-2023-3813 - Jupiter X Core Plugin

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to download the contents of arbitrary files on the server, which can contain sensitive information. The requires the premium version of the plugin to be activated.

PLUGIN Jupiter X Core

CVE-2023-3813

HIGH CVSS 7.5 2023-07-21
Threat Entry Updated 2024-11-21

CVE-2023-3779 - Essential Addons For Elementor Plugin

The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp API key. We recommend resetting any MailChimp API keys if running a vulnerable version of this plugin with the MailChimp block enabled as the API key may have been compromised. This only affects sites running the premium…

PLUGIN Essential Addons For Elementor

CVE-2023-3779

MEDIUM CVSS 5.3 2023-07-20
Threat Entry Updated 2024-11-21

CVE-2021-4428 - Autosuggest Plugin

A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic. Affected by this vulnerability is the function enqueue_scripts of the file w3w-autosuggest/public/class-w3w-autosuggest-public.php of the component Setting Handler. The manipulation leads to information disclosure. The attack can be launched remotely. Upgrading to version 4.0.1 is able to address this issue. The patch is named dd59cbac5f86057d6a73b87007c08b8bfa0c32ac. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-234247.

PLUGIN Autosuggest

CVE-2021-4428

LOW CVSS 2.7 2023-07-18
Threat Entry Updated 2024-11-21

CVE-2023-2433 - Yet Another Related Posts Plugin

The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Yet Another Related Posts

CVE-2023-2433

MEDIUM CVSS 6.4 2023-07-18
Threat Entry Updated 2024-11-21

CVE-2023-3713 - Profilegrid Plugin

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily. This can be used by attackers to achieve privilege escalation.

PLUGIN Profilegrid

CVE-2023-3713

HIGH CVSS 8.8 2023-07-18
Threat Entry Updated 2024-11-21

CVE-2023-3714 - Profilegrid Plugin

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_role' parameter, which defines the member's role. This issue was partially patched in version 5.5.2 preventing privilege escalation, however, it was fully patched in 5.5.3.

PLUGIN Profilegrid

CVE-2023-3714

HIGH CVSS 7.5 2023-07-18
Threat Entry Updated 2024-11-21

CVE-2023-3709 - Royal Elementor Addons Plugin

The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp API key. We recommend resetting any MailChimp API keys if running a vulnerable version of this plugin with the MailChimp block enabled as the API key may have been compromised.

PLUGIN Royal Elementor Addons

CVE-2023-3709

MEDIUM CVSS 5.3 2023-07-18
Threat Entry Updated 2024-11-21

CVE-2023-3459 - Import Export Wordpress Users Plugin

The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop manager-level permissions to change user passwords and potentially take over administrator accounts.

PLUGIN Import Export Wordpress Users

CVE-2023-3459

HIGH CVSS 7.2 2023-07-18
Threat Entry Updated 2026-02-06

CVE-2023-3708 - Medikaid Plugin

Several themes for WordPress by DeoThemes are vulnerable to Reflected Cross-Site Scripting via breadcrumbs in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Medikaid

CVE-2023-3708

MEDIUM CVSS 6.1 2023-07-18
Threat Entry Updated 2024-11-21

CVE-2023-3403 - Profilegrid Plugin

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to import new users and update existing users.

PLUGIN Profilegrid

CVE-2023-3403

MEDIUM CVSS 5.4 2023-07-18
Threat Entry Updated 2025-04-23

CVE-2023-3245 - Floating Chat Widget Plugin

The Floating Chat Widget WordPress plugin before 3.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Floating Chat Widget

CVE-2023-3245

MEDIUM CVSS 4.8 2023-07-17
Threat Entry Updated 2024-11-21

CVE-2023-3186 - Popup By Supsystic Plugin

The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.

PLUGIN Popup By Supsystic

CVE-2023-3186

CRITICAL CVSS 9.8 2023-07-17
Threat Entry Updated 2025-06-04

CVE-2023-3179 - Post Smtp Mailer Plugin

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability resend an email to an arbitrary address (for example a password reset email could be resent to an attacker controlled email, and allow them to take over an account).

PLUGIN Post Smtp Mailer

CVE-2023-3179

HIGH CVSS 8.8 2023-07-17
Threat Entry Updated 2024-11-21

CVE-2023-2636 - An Gradebook Plugin

The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber

PLUGIN An Gradebook

CVE-2023-2636

HIGH CVSS 8.8 2023-07-17
Threat Entry Updated 2024-11-21

CVE-2023-3182 - Before 3 Plugin

The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2023-3182

MEDIUM CVSS 6.1 2023-07-17
Threat Entry Updated 2025-05-05

CVE-2023-3041 - Automatic Conversation Plugin

The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before outputting it back on the page, leading to a cross-site Scripting attack.

PLUGIN Automatic Conversation

CVE-2023-3041

MEDIUM CVSS 6.1 2023-07-17
Threat Entry Updated 2024-11-21

CVE-2023-2701 - Gravity Forms Plugin

The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.

PLUGIN Gravity Forms

CVE-2023-2701

MEDIUM CVSS 6.1 2023-07-17
Scroll to top