Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13521-13540 of 16306 records
Threat Entry Updated 2026-04-08

CVE-2021-4350 - Frontend File Manager Plugin

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possible for unauthenticated attackers to send emails using the site with a custom subject, recipient email, and body with unsanitized HTML content. This effectively lets the attacker use the site as a spam relay.

PLUGIN Frontend File Manager

CVE-2021-4350

HIGH CVSS 7.2 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4345 - Ulisting Plugin

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities.

PLUGIN Ulisting

CVE-2021-4345

MEDIUM CVSS 6.5 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4344 - Frontend File Manager Plugin

The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This makes it possible for unauthenticated or authenticated attackers to access the information and privileges of other users, including 'guest users', in their own category (authenticated, or unauthenticated guests).

PLUGIN Frontend File Manager

CVE-2021-4344

MEDIUM CVSS 6.4 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4351 - Frontend File Manager Plugin

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticated attackers to change the meta data of certain posts and pages.

PLUGIN Frontend File Manager

CVE-2021-4351

MEDIUM CVSS 5.8 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4352 - Jobsearch Wp Job Board Plugin

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.

PLUGIN Jobsearch Wp Job Board

CVE-2021-4352

MEDIUM CVSS 5.3 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4338 - 404 To 301 Plugin

The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to view, create and edit redirections.

PLUGIN 404 To 301

CVE-2021-4338

MEDIUM CVSS 6.4 2023-06-07
Threat Entry Updated 2024-11-21

CVE-2023-2833 - Reviewx Plugin

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_screen_options[option]' and 'wp_screen_options[value]' parameters during a screen option update.

PLUGIN Reviewx

CVE-2023-2833

HIGH CVSS 8.8 2023-06-06
Threat Entry Updated 2024-11-21

CVE-2023-2546 - Wp User Switch Plugin

The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2. This is due to incorrect authentication checking in the 'wpus_allow_user_to_admin_bar_menu' function with the 'wpus_who_switch' cookie value. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator, if they have access to the username.

PLUGIN Wp User Switch

CVE-2023-2546

HIGH CVSS 8.8 2023-06-06
Threat Entry Updated 2025-01-08

CVE-2023-2572 - Survey Maker Plugin

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Survey Maker

CVE-2023-2572

MEDIUM CVSS 6.1 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-2571 - Before 6 Plugin

The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 6

CVE-2023-2571

MEDIUM CVSS 6.1 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-2503 - 10web Social Post Feed Plugin

The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN 10web Social Post Feed

CVE-2023-2503

MEDIUM CVSS 6.1 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-2488 - Before 2023 Does Not Sanitise And Escape Various Parameters Plugin

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape various parameters before outputting them back in admin dashboard pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2023 Does Not Sanitise And Escape Various Parameters

CVE-2023-2488

MEDIUM CVSS 6.1 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-2472 - Email Marketing And Subscribe Forms By Sendinblue Plugin

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Email Marketing And Subscribe Forms By Sendinblue

CVE-2023-2472

MEDIUM CVSS 6.1 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-2337 - Before 2 Plugin

The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-2337

MEDIUM CVSS 6.1 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-2634 - Get Your Number Plugin

The Get your number WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Get Your Number

CVE-2023-2634

MEDIUM CVSS 4.8 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-2489 - Before 2023 Does Not Sanitise And Escape Some Of Its Settings Plugin

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2023 Does Not Sanitise And Escape Some Of Its Settings

CVE-2023-2489

MEDIUM CVSS 4.8 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-0900 - Pricing Table Builder Plugin

The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins.

PLUGIN Pricing Table Builder

CVE-2023-0900

HIGH CVSS 7.2 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-0152 - Wp Multi Store Locator Plugin

The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Wp Multi Store Locator

CVE-2023-0152

MEDIUM CVSS 5.4 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-2224 - Seo By 10web Plugin

The SEO by 10Web WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Seo By 10web

CVE-2023-2224

MEDIUM CVSS 4.8 2023-06-05
Threat Entry Updated 2025-01-08

CVE-2023-0545 - Before 1 Plugin

The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2023-0545

MEDIUM CVSS 4.8 2023-06-05
Scroll to top