Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,248
Critical1,013
High3,368
Medium11,615
Reset
Showing 13321-13340 of 16248 records
Threat Entry Updated 2025-04-23

CVE-2023-2600 - Custom Base Terms Plugin

The Custom Base Terms WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Custom Base Terms

CVE-2023-2600

MEDIUM CVSS 4.8 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2527 - Before 1 Plugin

The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

PLUGIN Before 1

CVE-2023-2527

MEDIUM CVSS 4.8 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2401 - Before 1 Plugin

The QuBot WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2023-2401

MEDIUM CVSS 4.8 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2221 - Wp Custom Cursors Plugin

The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

PLUGIN Wp Custom Cursors

CVE-2023-2221

HIGH CVSS 7.2 2023-06-19
Threat Entry Updated 2024-11-21

CVE-2023-0489 - Sideonline Plugin

The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Sideonline

CVE-2023-0489

MEDIUM CVSS 5.4 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-0368 - Responsive Tabs For Wpbakery Page Builder Plugin

The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Responsive Tabs For Wpbakery Page Builder

CVE-2023-0368

MEDIUM CVSS 5.4 2023-06-19
Threat Entry Updated 2024-11-21

CVE-2023-3295 - Unlimited Elements For Elementor Plugin

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The issue was partially patched in version 1.5.66 and fully patched in 1.5.67. CVE-2023-31231 appears to be a duplicate of this issue.

PLUGIN Unlimited Elements For Elementor

CVE-2023-3295

HIGH CVSS 8.8 2023-06-17
Threat Entry Updated 2024-11-21

CVE-2023-3203 - Mstore Api Plugin

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_limit_product function. This makes it possible for unauthenticated attackers to update limit the number of product per category to use cache data in home screen via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Mstore Api

CVE-2023-3203

MEDIUM CVSS 4.3 2023-06-14
Threat Entry Updated 2024-11-21

CVE-2023-3201 - Mstore Api Plugin

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticated attackers to update new order title via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Mstore Api

CVE-2023-3201

MEDIUM CVSS 4.3 2023-06-14
Threat Entry Updated 2024-11-21

CVE-2023-3200 - Mstore Api Plugin

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_message function. This makes it possible for unauthenticated attackers to update new order message via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Mstore Api

CVE-2023-3200

MEDIUM CVSS 4.3 2023-06-14
Threat Entry Updated 2024-11-21

CVE-2023-3198 - Mstore Api Plugin

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_message function. This makes it possible for unauthenticated attackers to update status order message via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Mstore Api

CVE-2023-3198

MEDIUM CVSS 4.3 2023-06-14
Threat Entry Updated 2024-11-21

CVE-2023-2278 - Wp Directory Kit Plugin

The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Wp Directory Kit

CVE-2023-2278

CRITICAL CVSS 9.8 2023-06-13
Threat Entry Updated 2024-11-21

CVE-2023-2351 - Wp Directory Kit Plugin

The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_admin' function in versions up to, and including, 1.2.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to delete or change plugin settings, import demo data, delete Directory Kit related posts and terms, and install arbitrary plugins. A partial patch was introduced in version 1.2.0.

PLUGIN Wp Directory Kit

CVE-2023-2351

MEDIUM CVSS 6.5 2023-06-13
Threat Entry Updated 2024-11-21

CVE-2023-2277 - Wp Directory Kit Plugin

The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the 'insert' function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious JavaScript via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Directory Kit

CVE-2023-2277

MEDIUM CVSS 6.1 2023-06-13
Threat Entry Updated 2024-11-21

CVE-2023-2563 - Contact Forms Plugin

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Contact Forms

CVE-2023-2563

MEDIUM CVSS 4.3 2023-06-13
Threat Entry Updated 2024-11-21

CVE-2023-2568 - Photo Gallery By Ays Plugin

The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Photo Gallery By Ays

CVE-2023-2568

MEDIUM CVSS 6.1 2023-06-12
Threat Entry Updated 2024-11-21

CVE-2023-2398 - Icegram Engage Plugin

The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Icegram Engage

CVE-2023-2398

MEDIUM CVSS 6.1 2023-06-12
Threat Entry Updated 2025-05-05

CVE-2023-2362 - Herd Effects Plugin

The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back in an attribute, leading to…

PLUGIN Herd Effects

CVE-2023-2362

MEDIUM CVSS 6.1 2023-06-12
Scroll to top