Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13561-13580 of 16306 records
Threat Entry Updated 2024-11-21

CVE-2023-1159 - Bookly Plugin

The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Bookly

CVE-2023-1159

MEDIUM CVSS 4.0 2023-06-02
Threat Entry Updated 2024-11-21

CVE-2023-2201 - Web Directory Free Plugin

The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Web Directory Free

CVE-2023-2201

HIGH CVSS 8.8 2023-06-02
Threat Entry Updated 2025-05-06

CVE-2023-2304 - Favorites Plugin

The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_favorites' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Favorites

CVE-2023-2304

MEDIUM CVSS 6.4 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-2836 - Crm Perks Forms Plugin

The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Crm Perks Forms

CVE-2023-2836

MEDIUM CVSS 4.4 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-2434 - Nested Pages Plugin

The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings.

PLUGIN Nested Pages

CVE-2023-2434

LOW CVSS 3.8 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-1661 - Display Post Meta Term Meta Comment Meta And User Meta Plugin

The Display post meta, term meta, comment meta, and user meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post metadata in versions up to, and including, 0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Display Post Meta Term Meta Comment Meta And User Meta

CVE-2023-1661

MEDIUM CVSS 6.4 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-2987 - Wordapp Plugin

The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to the plugin to change the 'validation_token' in the plugin config, providing access to the plugin's remote control functionalities, such as creating an admin access URL, which can be used for privilege escalation.

PLUGIN Wordapp

CVE-2023-2987

CRITICAL CVSS 9.8 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-2549 - Feather Login Page Plugin

The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions starting from 1.0.7 up to, and including, 1.1.1. This is due to missing nonce validation in the 'createTempAccountLink' function. This makes it possible for unauthenticated attackers to create a new user with administrator role via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. An attacker can leverage CVE-2023-2545 to get the login link or request a password reset to the new user's email…

PLUGIN Feather Login Page

CVE-2023-2549

HIGH CVSS 8.8 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-2545 - Feather Login Page Plugin

The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to access the login links, which can be used for privilege escalation.

PLUGIN Feather Login Page

CVE-2023-2545

HIGH CVSS 8.1 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-2435 - Blog In Blog Plugin

The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.1 via a shortcode attribute. This allows editor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Blog In Blog

CVE-2023-2435

HIGH CVSS 7.2 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-2436 - Blog In Blog Plugin

The Blog-in-Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blog_in_blog' shortcode in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Blog In Blog

CVE-2023-2436

MEDIUM CVSS 5.5 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-2547 - Feather Login Page Plugin

The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteUser' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the temp user generated by the plugin.

PLUGIN Feather Login Page

CVE-2023-2547

MEDIUM CVSS 5.4 2023-05-31
Threat Entry Updated 2025-01-10

CVE-2023-2288 - Before 2 Plugin

The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.

PLUGIN Before 2

CVE-2023-2288

HIGH CVSS 8.8 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2518 - Before 6 Plugin

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 6

CVE-2023-2518

MEDIUM CVSS 6.1 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2296 - Before 1 Plugin

The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 1

CVE-2023-2296

MEDIUM CVSS 6.1 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2470 - Add To Feedly Plugin

The Add to Feedly WordPress plugin through 1.2.11 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Add To Feedly

CVE-2023-2470

MEDIUM CVSS 4.8 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2223 - Login Rebuilder Plugin

The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Login Rebuilder

CVE-2023-2223

MEDIUM CVSS 4.8 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2287 - Orbit Fox By Themeisle Plugin

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

PLUGIN Orbit Fox By Themeisle

CVE-2023-2287

MEDIUM CVSS 4.3 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-1938 - Wp Fastest Cache Plugin

The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate user input before using it in the wp_remote_get() function, leading to a Blind SSRF issue

PLUGIN Wp Fastest Cache

CVE-2023-1938

HIGH CVSS 8.8 2023-05-30
Scroll to top