Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,248
Critical1,013
High3,368
Medium11,615
Reset
Showing 13221-13240 of 16248 records
Threat Entry Updated 2024-11-21

CVE-2023-2028 - Call Now Accessibility Button Plugin

The Call Now Accessibility Button WordPress plugin before 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Call Now Accessibility Button

CVE-2023-2028

MEDIUM CVSS 4.8 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-2026 - Image Protector Plugin

The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Image Protector

CVE-2023-2026

MEDIUM CVSS 4.8 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-1597 - Tagdiv Cloud Library Plugin

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.

PLUGIN Tagdiv Cloud Library

CVE-2023-1597

HIGH CVSS 8.8 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-1780 - Companion Sitemap Generator Plugin

The Companion Sitemap Generator WordPress plugin before 4.5.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Companion Sitemap Generator

CVE-2023-1780

MEDIUM CVSS 6.1 2023-07-10
Threat Entry Updated 2025-01-06

CVE-2023-1119 - Wp Optimize Plugin

The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.

PLUGIN Wp Optimize

CVE-2023-1119

MEDIUM CVSS 6.1 2023-07-10
Threat Entry Updated 2024-11-21

CVE-2023-3460 - Ultimate Member Plugin

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

PLUGIN Ultimate Member

CVE-2023-3460

CRITICAL CVSS 9.8 2023-07-04
Threat Entry Updated 2024-11-21

CVE-2023-1273 - Nd Shortcodes Plugin

The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks

PLUGIN Nd Shortcodes

CVE-2023-1273

HIGH CVSS 8.8 2023-07-04
Threat Entry Updated 2024-11-21

CVE-2023-3133 - Before 2 Plugin

The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.

PLUGIN Before 2

CVE-2023-3133

HIGH CVSS 7.5 2023-07-04
Threat Entry Updated 2024-11-21

CVE-2023-2333 - Gsheetconnector Ninja Forms Pro Plugin

The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Gsheetconnector Ninja Forms Pro

CVE-2023-2333

MEDIUM CVSS 6.1 2023-07-04
Threat Entry Updated 2024-11-21

CVE-2023-2324 - Gsheetconnector For Elementor Forms Pro Plugin

The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Gsheetconnector For Elementor Forms Pro

CVE-2023-2324

MEDIUM CVSS 6.1 2023-07-04
Threat Entry Updated 2024-11-21

CVE-2023-2321 - Gsheetconnector Wpforms Pro Plugin

The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Gsheetconnector Wpforms Pro

CVE-2023-2321

MEDIUM CVSS 6.1 2023-07-04
Threat Entry Updated 2024-11-21

CVE-2023-2320 - Cf7 Google Sheets Connector Pro Plugin

The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Cf7 Google Sheets Connector Pro

CVE-2023-2320

MEDIUM CVSS 6.1 2023-07-04
Threat Entry Updated 2024-11-21

CVE-2023-2010 - Before 1 Plugin

The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Condition that may allow a single user to vote multiple times on a poll.

PLUGIN Before 1

CVE-2023-2010

LOW CVSS 3.1 2023-07-04
Threat Entry Updated 2026-04-08

CVE-2021-4401 - Style Kits Plugin

The Style Kits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.0. This is due to missing or incorrect nonce validation on the update_posts_stylekit() function. This makes it possible for unauthenticated attackers to update style kits for posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Style Kits

CVE-2021-4401

HIGH CVSS 8.8 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4405 - Elasticpress Plugin

The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on the epio_send_autosuggest_allowed() function. This makes it possible for unauthenticated attackers to send allowed parameters for autosuggest to elasticpress[.]io via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Elasticpress

CVE-2021-4405

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4404 - Event Espresso 4 Decaf Plugin

The Event Espresso 4 Decaf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10.11. This is due to missing or incorrect nonce validation on the ajaxHandler() function. This makes it possible for unauthenticated attackers to op into notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Event Espresso 4 Decaf

CVE-2021-4404

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4403 - Remove Schema Plugin

The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Remove Schema

CVE-2021-4403

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4402 - Multiple Roles Plugin

The Multiple Roles plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the mu_add_roles_in_signup_meta() and mu_add_roles_in_signup_meta_recently() functions. This makes it possible for unauthenticated attackers to add additional roles to users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Multiple Roles

CVE-2021-4402

MEDIUM CVSS 4.3 2023-07-01
Scroll to top