Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13581-13600 of 16306 records
Threat Entry Updated 2025-01-10

CVE-2023-0766 - Newsletter Popup Plugin

The Newsletter Popup WordPress plugin through 1.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks as the wp_newsletter_show_localrecord page is not protected with a nonce.

PLUGIN Newsletter Popup

CVE-2023-0766

HIGH CVSS 8.8 2023-05-30
Threat Entry Updated 2025-04-23

CVE-2023-0329 - Elementor Website Builder Plugin

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

PLUGIN Elementor Website Builder

CVE-2023-0329

HIGH CVSS 7.2 2023-05-30
Threat Entry Updated 2025-03-21

CVE-2023-1524 - Download Manager Plugin

The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.

PLUGIN Download Manager

CVE-2023-1524

MEDIUM CVSS 6.5 2023-05-30
Threat Entry Updated 2025-01-09

CVE-2023-2023 - Custom 404 Pro Plugin

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

PLUGIN Custom 404 Pro

CVE-2023-2023

MEDIUM CVSS 6.1 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-0733 - Newsletter Popup Plugin

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks

PLUGIN Newsletter Popup

CVE-2023-0733

MEDIUM CVSS 6.1 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-0443 - Anywhere Elementor Plugin

The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.

PLUGIN Anywhere Elementor

CVE-2023-0443

MEDIUM CVSS 5.3 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2111 - Lead Generation For Plugin

The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL query without escaping it first in the plugin's report API endpoint, which could allow administrators in multi-site configuration to leak sensitive information from the site's database.

PLUGIN Lead Generation For

CVE-2023-2111

MEDIUM CVSS 4.9 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2113 - Before 3 Plugin

The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export, allowing high privileged users (such as an administrator) to inject arbitrary javascript into the admin panel, even when the unfiltered_html capability is disabled, such as in a multisite setup.

PLUGIN Before 3

CVE-2023-2113

MEDIUM CVSS 4.8 2023-05-30
Threat Entry Updated 2025-01-10

CVE-2023-2117 - Image Optimizer By 10web Plugin

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

PLUGIN Image Optimizer By 10web

CVE-2023-2117

LOW CVSS 2.7 2023-05-30
Threat Entry Updated 2024-11-21

CVE-2023-2734 - Mstore Api Plugin

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

PLUGIN Mstore Api

CVE-2023-2734

CRITICAL CVSS 9.8 2023-05-25
Threat Entry Updated 2024-11-21

CVE-2023-2733 - Mstore Api Plugin

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

PLUGIN Mstore Api

CVE-2023-2733

CRITICAL CVSS 9.8 2023-05-25
Threat Entry Updated 2024-11-21

CVE-2023-2732 - Mstore Api Plugin

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

PLUGIN Mstore Api

CVE-2023-2732

CRITICAL CVSS 9.8 2023-05-25
Threat Entry Updated 2024-11-21

CVE-2023-2500 - Go Pricing Plugin

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortcode 'data' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Go Pricing

CVE-2023-2500

HIGH CVSS 8.8 2023-05-25
Threat Entry Updated 2024-11-21

CVE-2023-2496 - Go Pricing Plugin

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Go Pricing

CVE-2023-2496

HIGH CVSS 7.1 2023-05-24
Threat Entry Updated 2024-11-21

CVE-2023-2498 - Go Pricing Plugin

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.19 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Go Pricing

CVE-2023-2498

MEDIUM CVSS 6.4 2023-05-24
Threat Entry Updated 2024-11-21

CVE-2023-2494 - Go Pricing Plugin

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_postdata' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to modify access to the plugin when it should only be the administrator's privilege.

PLUGIN Go Pricing

CVE-2023-2494

MEDIUM CVSS 4.6 2023-05-24
Threat Entry Updated 2024-11-21

CVE-2023-2276 - Wcfm Membership Plugin

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.

PLUGIN Wcfm Membership

CVE-2023-2276

CRITICAL CVSS 9.8 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2736 - Groundhogg Plugin

The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.8. This is due to missing nonce validation in the 'ajax_edit_contact' function. This makes it possible for authenticated attackers to receive the auto login link via shortcode and then modify the assigned user to the auto login link to elevate verified user privileges via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Groundhogg

CVE-2023-2736

HIGH CVSS 7.5 2023-05-20
Scroll to top