Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,304
Critical1,017
High3,377
Medium11,647
Reset
Showing 13441-13460 of 16304 records
Threat Entry Updated 2024-11-21

CVE-2023-2083 - Essential Blocks Plugin

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to save plugin settings. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

PLUGIN Essential Blocks

CVE-2023-2083

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2066 - Announcement Notification Banner Bulletin Plugin

The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'bulletinwp_update_bulletin_status', 'bulletinwp_update_bulletin', 'bulletinwp_update_settings', 'bulletinwp_update_status', 'bulletinwp_export_bulletins', and 'bulletinwp_import_bulletins' functions functions in versions up to, and including, 3.6.0. This makes it possible for authenticated attackers with subscriber-level access, and above, to modify the plugin's settings, modify bulletins, create new bulletins, and more.

PLUGIN Announcement Notification Banner Bulletin

CVE-2023-2066

MEDIUM CVSS 6.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2031 - Locatoraid Plugin

The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Locatoraid

CVE-2023-2031

MEDIUM CVSS 5.4 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1978 - Shiftcontroller Plugin

The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the query string in versions up to, and including, 4.9.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Shiftcontroller

CVE-2023-1978

MEDIUM CVSS 6.1 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1917 - Powerpress Plugin

The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: A partial fix for the issue was introduced in version 10.0.1, and an additional patch (version 10.0.2) was released to address a workaround.

PLUGIN Powerpress

CVE-2023-1917

MEDIUM CVSS 5.4 2023-06-09
Threat Entry Updated 2024-11-25

CVE-2023-1910 - Getwid Plugin

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function in versions up to, and including, 1.8.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to flush the remote template cache. Cached template information can also be accessed via this endpoint but these are not considered sensitive as they are publicly accessible from the developer's site.

PLUGIN Getwid

CVE-2023-1910

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1888 - Directorist Plugin

The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset the password of an arbitrary user and gain elevated (e.g., administrator) privileges.

PLUGIN Directorist

CVE-2023-1888

HIGH CVSS 8.8 2023-06-09
Threat Entry Updated 2024-11-25

CVE-2023-1895 - Getwid Plugin

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Getwid

CVE-2023-1895

HIGH CVSS 8.5 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1889 - Directorist Plugin

The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts.

PLUGIN Directorist

CVE-2023-1889

MEDIUM CVSS 6.5 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1843 - Metform Elementor Contact Form Builder Plugin

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update due to a missing capability check on the permalink_setup function in versions up to, and including, 3.3.0. This makes it possible for unauthenticated attackers to change the permalink structure.

PLUGIN Metform Elementor Contact Form Builder

CVE-2023-1843

MEDIUM CVSS 6.5 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1615 - Ultimate Addons For Contact Form 7 Plugin

The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including, 3.1.23. This makes it possible for authenticated attackers of any authorization level to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ultimate Addons For Contact Form 7

CVE-2023-1615

HIGH CVSS 8.8 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1430 - Fluentcrm Plugin

The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.7.40 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists and manage subscriptions, granted they gain access to any targeted subscribers email address.

PLUGIN Fluentcrm

CVE-2023-1430

MEDIUM CVSS 5.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1807 - Stax Plugin

The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.3. This is due to missing or incorrect nonce validation on the toggle_widget function. This makes it possible for unauthenticated attackers to enable or disable Elementor widgets via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Stax

CVE-2023-1807

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1404 - Weaver Show Posts Plugin

The Weaver Show Posts Plugin for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up to, and including, 1.6. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Weaver Show Posts

CVE-2023-1404

MEDIUM CVSS 6.4 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1375 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized cache deletion in versions up to, and including, 1.1.2 due to a missing capability check in the deleteCacheToolbar function . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the site's cache.

PLUGIN Wp Fastest Cache

CVE-2023-1375

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1016 - Intuitive Custom Post Order Plugin

The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.3, due to insufficient escaping on the user supplied 'objects' and 'tags' parameters and lack of sufficient preparation in the 'update_options' function as well as the 'refresh' function which runs queries on the same values. This allows authenticated attackers, with administrator permissions, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note that this attack may only be practical on…

PLUGIN Intuitive Custom Post Order

CVE-2023-1016

MEDIUM CVSS 6.6 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-1169 - Ooohboi Steroids For Elementor Plugin

The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site.

PLUGIN Ooohboi Steroids For Elementor

CVE-2023-1169

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-0993 - Shield Security Plugin

The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action in versions up to, and including, 17.0.17. This allows authenticated attackers to add arbitrary audit log entries indicating that a theme or plugin has been edited, and is also a vector for Cross-Site Scripting via CVE-2023-0992.

PLUGIN Shield Security

CVE-2023-0993

MEDIUM CVSS 4.3 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-0992 - Shield Security Plugin

The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shield Security

CVE-2023-0992

HIGH CVSS 7.2 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-0832 - Under Construction Plugin

The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the install_weglot function called via the admin_action_install_weglot action. This makes it possible for unauthenticated attackers to perform an unauthorized install of the Weglot Translate plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Under Construction

CVE-2023-0832

MEDIUM CVSS 4.3 2023-06-09
Scroll to top