Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,304
Critical1,017
High3,377
Medium11,647
Reset
Showing 13421-13440 of 16304 records
Threat Entry Updated 2024-11-21

CVE-2023-2556 - Wordpress Currency Switcher Plugin

The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the anonymous function for the wpcs_sd_delete action in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete an arbitrary custom drop-down currency switcher.

PLUGIN Wordpress Currency Switcher

CVE-2023-2556

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2555 - Wordpress Currency Switcher Professional Plugin

The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create a custom drop-down currency switcher.

PLUGIN Wordpress Currency Switcher Professional

CVE-2023-2555

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2025-03-20

CVE-2023-2414 - Scheduling Calendar For Wordpress By Vcita Plugin

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to modify the plugins settings, upload arbitrary files, and inject malicious JavaScript (before 4.3.2).

PLUGIN Scheduling Calendar For Wordpress By Vcita

CVE-2023-2414

MEDIUM CVSS 5.4 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2452 - Advanced Woo Search Plugin

The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Advanced Woo Search

CVE-2023-2452

MEDIUM CVSS 4.4 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2450 - Fibosearch Plugin

The FiboSearch - AJAX Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.23.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Fibosearch

CVE-2023-2450

MEDIUM CVSS 4.4 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2280 - Wp Directory Kit Plugin

The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_public' function in versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to delete or change plugin settings, import demo data, delete Directory Kit related posts and terms, and install arbitrary plugins. A partial patch was introduced in version 1.2.0 and an additional partial patch was introduced in version 1.2.2, but the issue was not fully patched until 1.2.3.

PLUGIN Wp Directory Kit

CVE-2023-2280

MEDIUM CVSS 6.5 2023-06-09
Threat Entry Updated 2025-03-21

CVE-2023-2305 - Download Manager Plugin

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Download Manager

CVE-2023-2305

MEDIUM CVSS 6.4 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2402 - Photo Gallery Slideshow Masonry Tiled Gallery Plugin

The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Photo Gallery Slideshow Masonry Tiled Gallery

CVE-2023-2402

MEDIUM CVSS 6.1 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2289 - Wordpress Vertical Image Slider Plugin

The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wordpress Vertical Image Slider

CVE-2023-2289

MEDIUM CVSS 6.1 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2249 - Wpforo Forum Plugin

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.

PLUGIN Wpforo Forum

CVE-2023-2249

HIGH CVSS 8.8 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2237 - Wp Replicate Post Plugin

The WP Replicate Post plugin for WordPress is vulnerable to SQL Injection via the post_id parameter in versions up to, and including, 4.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for contributor-level attackers or higher to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Replicate Post

CVE-2023-2237

HIGH CVSS 8.8 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2275 - Woocommerce Multivendor Marketplace Plugin

The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'get_item', 'get_order_notes' and 'add_order_note' functions in versions up to, and including, 1.5.3. This makes it possible for authenticated attackers with subscriber privileges or above, to view the order details and order notes, and add order notes.

PLUGIN Woocommerce Multivendor Marketplace

CVE-2023-2275

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2184 - Wp Responsive Tabs Plugin

The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Responsive Tabs

CVE-2023-2184

MEDIUM CVSS 6.1 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2159 - Cmp Plugin

The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default setting) allows users to visit a site placed in maintenance mode thus bypassing the plugin's provided feature.

PLUGIN Cmp

CVE-2023-2159

MEDIUM CVSS 5.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2189 - Stax Plugin

The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the toggle_widget function in versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to enable or disable Elementor widgets.

PLUGIN Stax

CVE-2023-2189

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2087 - Essential Blocks Plugin

The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.6. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Essential Blocks

CVE-2023-2087

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2086 - Essential Blocks Plugin

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

PLUGIN Essential Blocks

CVE-2023-2086

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2085 - Essential Blocks Plugin

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

PLUGIN Essential Blocks

CVE-2023-2085

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2067 - Announcement Notification Banner Bulletin Plugin

The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce validation on the 'bulletinwp_update_bulletin_status', 'bulletinwp_update_bulletin', 'bulletinwp_update_settings', 'bulletinwp_update_status', 'bulletinwp_export_bulletins', and 'bulletinwp_import_bulletins' functions in versions up to, and including, 3.7.0. This makes it possible for unauthenticated attackers to modify the plugin's settings, modify bulletins, create new bulletins, and more, via a forged request granted they can trick a site's user into performing an action such as clicking on a link.

PLUGIN Announcement Notification Banner Bulletin

CVE-2023-2067

MEDIUM CVSS 6.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2084 - Essential Blocks Plugin

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin settings. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

PLUGIN Essential Blocks

CVE-2023-2084

MEDIUM CVSS 4.3 2023-06-09
Scroll to top