Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,248
Critical1,013
High3,368
Medium11,615
Reset
Showing 13381-13400 of 16248 records
Threat Entry Updated 2024-11-21

CVE-2023-2086 - Essential Blocks Plugin

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

PLUGIN Essential Blocks

CVE-2023-2086

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2085 - Essential Blocks Plugin

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

PLUGIN Essential Blocks

CVE-2023-2085

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2067 - Announcement Notification Banner Bulletin Plugin

The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce validation on the 'bulletinwp_update_bulletin_status', 'bulletinwp_update_bulletin', 'bulletinwp_update_settings', 'bulletinwp_update_status', 'bulletinwp_export_bulletins', and 'bulletinwp_import_bulletins' functions in versions up to, and including, 3.7.0. This makes it possible for unauthenticated attackers to modify the plugin's settings, modify bulletins, create new bulletins, and more, via a forged request granted they can trick a site's user into performing an action such as clicking on a link.

PLUGIN Announcement Notification Banner Bulletin

CVE-2023-2067

MEDIUM CVSS 6.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2084 - Essential Blocks Plugin

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin settings. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

PLUGIN Essential Blocks

CVE-2023-2084

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2083 - Essential Blocks Plugin

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to save plugin settings. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

PLUGIN Essential Blocks

CVE-2023-2083

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2066 - Announcement Notification Banner Bulletin Plugin

The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'bulletinwp_update_bulletin_status', 'bulletinwp_update_bulletin', 'bulletinwp_update_settings', 'bulletinwp_update_status', 'bulletinwp_export_bulletins', and 'bulletinwp_import_bulletins' functions functions in versions up to, and including, 3.6.0. This makes it possible for authenticated attackers with subscriber-level access, and above, to modify the plugin's settings, modify bulletins, create new bulletins, and more.

PLUGIN Announcement Notification Banner Bulletin

CVE-2023-2066

MEDIUM CVSS 6.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2031 - Locatoraid Plugin

The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Locatoraid

CVE-2023-2031

MEDIUM CVSS 5.4 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1978 - Shiftcontroller Plugin

The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the query string in versions up to, and including, 4.9.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Shiftcontroller

CVE-2023-1978

MEDIUM CVSS 6.1 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1917 - Powerpress Plugin

The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: A partial fix for the issue was introduced in version 10.0.1, and an additional patch (version 10.0.2) was released to address a workaround.

PLUGIN Powerpress

CVE-2023-1917

MEDIUM CVSS 5.4 2023-06-09
Threat Entry Updated 2024-11-25

CVE-2023-1910 - Getwid Plugin

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function in versions up to, and including, 1.8.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to flush the remote template cache. Cached template information can also be accessed via this endpoint but these are not considered sensitive as they are publicly accessible from the developer's site.

PLUGIN Getwid

CVE-2023-1910

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1888 - Directorist Plugin

The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset the password of an arbitrary user and gain elevated (e.g., administrator) privileges.

PLUGIN Directorist

CVE-2023-1888

HIGH CVSS 8.8 2023-06-09
Threat Entry Updated 2024-11-25

CVE-2023-1895 - Getwid Plugin

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Getwid

CVE-2023-1895

HIGH CVSS 8.5 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1889 - Directorist Plugin

The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts.

PLUGIN Directorist

CVE-2023-1889

MEDIUM CVSS 6.5 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1843 - Metform Elementor Contact Form Builder Plugin

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update due to a missing capability check on the permalink_setup function in versions up to, and including, 3.3.0. This makes it possible for unauthenticated attackers to change the permalink structure.

PLUGIN Metform Elementor Contact Form Builder

CVE-2023-1843

MEDIUM CVSS 6.5 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1615 - Ultimate Addons For Contact Form 7 Plugin

The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including, 3.1.23. This makes it possible for authenticated attackers of any authorization level to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ultimate Addons For Contact Form 7

CVE-2023-1615

HIGH CVSS 8.8 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1430 - Fluentcrm Plugin

The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.7.40 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists and manage subscriptions, granted they gain access to any targeted subscribers email address.

PLUGIN Fluentcrm

CVE-2023-1430

MEDIUM CVSS 5.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1807 - Stax Plugin

The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.3. This is due to missing or incorrect nonce validation on the toggle_widget function. This makes it possible for unauthenticated attackers to enable or disable Elementor widgets via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Stax

CVE-2023-1807

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1404 - Weaver Show Posts Plugin

The Weaver Show Posts Plugin for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up to, and including, 1.6. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Weaver Show Posts

CVE-2023-1404

MEDIUM CVSS 6.4 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1375 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized cache deletion in versions up to, and including, 1.1.2 due to a missing capability check in the deleteCacheToolbar function . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the site's cache.

PLUGIN Wp Fastest Cache

CVE-2023-1375

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1016 - Intuitive Custom Post Order Plugin

The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.3, due to insufficient escaping on the user supplied 'objects' and 'tags' parameters and lack of sufficient preparation in the 'update_options' function as well as the 'refresh' function which runs queries on the same values. This allows authenticated attackers, with administrator permissions, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note that this attack may only be practical on…

PLUGIN Intuitive Custom Post Order

CVE-2023-1016

MEDIUM CVSS 6.6 2023-06-09
Scroll to top