Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,248
Critical1,013
High3,368
Medium11,615
Reset
Showing 13241-13260 of 16248 records
Threat Entry Updated 2026-04-08

CVE-2021-4400 - Better Search Plugin

The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the bsearch_process_settings_import() and bsearch_process_settings_export() functions. This makes it possible for unauthenticated attackers to import and export settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Better Search

CVE-2021-4400

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4399 - Edwiser Bridge Plugin

The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,2.0.6. This is due to missing or incorrect nonce validation on the user_data_synchronization_initiater(), course_synchronization_initiater(), users_link_to_moodle_synchronization(), connection_test_initiater(), admin_menus(), and subscribe_handler() function. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Edwiser Bridge

CVE-2021-4399

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4398 - Amministrazione Trasparente Plugin

The Amministrazione Trasparente plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.1. This is due to missing or incorrect nonce validation on the at_save_aturl_meta() function. This makes it possible for unauthenticated attackers to update meta data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Amministrazione Trasparente

CVE-2021-4398

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4397 - Staff Directory Plugin

The Staff Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Staff Directory

CVE-2021-4397

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4396 - Rucy Plugin

The Rucy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.4.4. This is due to missing or incorrect nonce validation on the save_rc_post_meta() function. This makes it possible for unauthenticated attackers to save post meta via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rucy

CVE-2021-4396

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4395 - Abandoned Cart Recovery For Woocommerce Plugin

The Abandoned Cart Recovery for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the get_items() and extra_tablenav() functions. This makes it possible for unauthenticated attackers to perform read-only actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Abandoned Cart Recovery For Woocommerce

CVE-2021-4395

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4394 - Locations Plugin

The Locations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to update custom field meta data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Locations

CVE-2021-4394

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4393 - Ecommerce Product Catalog Plugin

The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.17. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save manual digital orders via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ecommerce Product Catalog

CVE-2021-4393

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4392 - Ecommerce Product Catalog Plugin

The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.43. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to save product meta data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ecommerce Product Catalog

CVE-2021-4392

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4391 - Woo Gift Cards Lite Plugin

The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the mwb_wgm_save_post() function. This makes it possible for unauthenticated attackers to modify product gift card details via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Woo Gift Cards Lite

CVE-2021-4391

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4390 - Contact Form 7 Style Plugin

The Contact Form 7 Style plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on the manage_wp_posts_be_qe_save_post() function. This makes it possible for unauthenticated attackers to quick edit templates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Contact Form 7 Style

CVE-2021-4390

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4389 - Wp Travel Plugin

The WP Travel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.6. This is due to missing or incorrect nonce validation on the save_meta_data() function. This makes it possible for unauthenticated attackers to save metadata for travel posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Travel

CVE-2021-4389

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4388 - Opal Estate Plugin

The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missing capability checks on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers to set and remove featured properties.

PLUGIN Opal Estate

CVE-2021-4388

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4387 - Opal Estate Plugin

The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or incorrect nonce validation on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers to set and remove featured properties via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Opal Estate

CVE-2021-4387

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4386 - Wp Security Questions Plugin

The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Security Questions

CVE-2021-4386

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4385 - Wp Private Content Plus Plugin

The WP Private Content Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_groups() function. This makes it possible for unauthenticated attackers to add new group members via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Private Content Plus

CVE-2021-4385

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2026-04-08

CVE-2021-4384 - Photo Contest Plugin

The WordPress Photo Gallery – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the load_images_thumbnail() and edit_gallery() functions. This makes it possible for unauthenticated attackers to edit galleries via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Photo Contest

CVE-2021-4384

MEDIUM CVSS 4.3 2023-07-01
Threat Entry Updated 2024-11-21

CVE-2023-3249 - Web3 Crypto Wallet Login Nft Token Gating Plugin

The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

PLUGIN Web3 Crypto Wallet Login Nft Token Gating

CVE-2023-3249

CRITICAL CVSS 9.8 2023-06-30
Threat Entry Updated 2024-11-21

CVE-2023-3063 - Sp Project Document Manager Plugin

The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with subscriber privileges or above, to change user passwords and potentially take over administrator accounts.

PLUGIN Sp Project Document Manager

CVE-2023-3063

HIGH CVSS 8.8 2023-06-30
Threat Entry Updated 2024-11-21

CVE-2023-2834 - Bookit Plugin

The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

PLUGIN Bookit

CVE-2023-2834

CRITICAL CVSS 9.8 2023-06-30
Scroll to top