Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,248
Critical1,013
High3,368
Medium11,615
Reset
Showing 13261-13280 of 16248 records
Threat Entry Updated 2024-11-21

CVE-2023-3447 - Ldap Integration Plugin

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for unauthenticated attackers to extract potentially sensitive information from the LDAP directory.

PLUGIN Ldap Integration

CVE-2023-3447

HIGH CVSS 8.6 2023-06-29
Threat Entry Updated 2024-11-21

CVE-2023-2982 - Wordpress Social Login And Register Discord Google Twitter Linkedin Plugin

The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the email address associated with that user. This was partially patched in version 7.6.4 and fully patched in version 7.6.5.

PLUGIN Wordpress Social Login And Register Discord Google Twitter Linkedin

CVE-2023-2982

CRITICAL CVSS 9.8 2023-06-29
Threat Entry Updated 2024-11-21

CVE-2023-1602 - Short Url Plugin

The Short URL plugin for WordPress is vulnerable to stored Cross-Site Scripting via the 'comment' parameter due to insufficient input sanitization and output escaping in versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Short Url

CVE-2023-1602

MEDIUM CVSS 4.4 2023-06-29
Threat Entry Updated 2024-11-21

CVE-2023-3407 - Subscribe2 Plugin

The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.40. This is due to missing or incorrect nonce validation when sending test emails. This makes it possible for unauthenticated attackers to send test emails with custom content to users on sites running a vulnerable version of this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Subscribe2

CVE-2023-3407

MEDIUM CVSS 4.3 2023-06-28
Threat Entry Updated 2024-11-21

CVE-2023-1844 - Subscribe2 Plugin

The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and including, 10.40. This makes it possible for author-level attackers to send emails with arbitrary content and attachments to site users.

PLUGIN Subscribe2

CVE-2023-1844

MEDIUM CVSS 4.3 2023-06-28
Threat Entry Updated 2024-11-21

CVE-2023-3427 - Salon Booking System Plugin

The Salon Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.6. This is due to missing or incorrect nonce validation on the 'save_customer' function. This makes it possible for unauthenticated attackers to change the admin role to customer or change the user meta to arbitrary values via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Salon Booking System

CVE-2023-3427

MEDIUM CVSS 5.4 2023-06-28
Threat Entry Updated 2024-11-21

CVE-2023-2996 - Before 12 Plugin

The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.

PLUGIN Before 12

CVE-2023-2996

HIGH CVSS 8.8 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2877 - Formidable Forms Plugin

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.

PLUGIN Formidable Forms

CVE-2023-2877

HIGH CVSS 8.8 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2628 - Before 3 Plugin

The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc, create/update various users (patients, doctors etc)

PLUGIN Before 3

CVE-2023-2628

HIGH CVSS 8.8 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2842 - Wp Inventory Manager Plugin

The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack

PLUGIN Wp Inventory Manager

CVE-2023-2842

HIGH CVSS 8.1 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2744 - Before 1 Plugin

The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Before 1

CVE-2023-2744

HIGH CVSS 7.2 2023-06-27
Threat Entry Updated 2025-05-05

CVE-2023-2743 - Before 1 Plugin

The ERP WordPress plugin before 1.12.4 does not sanitise and escape the employee_name parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 1

CVE-2023-2743

MEDIUM CVSS 6.1 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2624 - Before 3 Plugin

The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator

PLUGIN Before 3

CVE-2023-2624

MEDIUM CVSS 6.1 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2795 - Before 0 Plugin

The CodeColorer WordPress plugin before 0.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 0

CVE-2023-2795

MEDIUM CVSS 4.8 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2711 - Ultimate Product Catalog Plugin

The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Ultimate Product Catalog

CVE-2023-2711

MEDIUM CVSS 4.8 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2627 - Before 3 Plugin

The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings

PLUGIN Before 3

CVE-2023-2627

MEDIUM CVSS 4.3 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2601 - Before 2 Plugin

The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin via CSRF.

PLUGIN Before 2

CVE-2023-2601

CRITICAL CVSS 9.8 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2068 - File Manager Advanced Shortcode Plugin

The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

PLUGIN File Manager Advanced Shortcode

CVE-2023-2068

CRITICAL CVSS 9.8 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2023-2592 - Before 3 Plugin

The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Before 3

CVE-2023-2592

HIGH CVSS 7.2 2023-06-27
Scroll to top