Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13601-13620 of 16306 records
Threat Entry Updated 2024-11-21

CVE-2023-2717 - Groundhogg Plugin

The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.8. This is due to missing nonce validation on the 'enable_safe_mode' function. This makes it possible for unauthenticated attackers to enable safe mode, which disables all other plugins, via a forged request if they can successfully trick an administrator into performing an action such as clicking on a link. A warning message about safe mode is displayed to the admin, which can be easily disabled.

PLUGIN Groundhogg

CVE-2023-2717

MEDIUM CVSS 5.4 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2716 - Groundhogg Plugin

The Groundhogg plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'ajax_upload_file' function in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload a file to the contact, and then lists all the other uploaded files related to the contact.

PLUGIN Groundhogg

CVE-2023-2716

MEDIUM CVSS 5.4 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2735 - Groundhogg Plugin

The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gh_form' shortcode in versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Please note this only works with legacy contact forms.

PLUGIN Groundhogg

CVE-2023-2735

MEDIUM CVSS 4.9 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2715 - Groundhogg Plugin

The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_ticket' function in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers to create a support ticket that sends the website's data to the plugin developer, and it is also possible to create an admin access with an auto login link that is also sent to the plugin developer with the ticket. It only works if the plugin is activated with a valid license.

PLUGIN Groundhogg

CVE-2023-2715

MEDIUM CVSS 4.3 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2714 - Groundhogg Plugin

The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_license' functions in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the license key and support license key, but it can only be changed to a valid license key.

PLUGIN Groundhogg

CVE-2023-2714

MEDIUM CVSS 4.3 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2704 - Bp Social Connect Plugin

The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

PLUGIN Bp Social Connect

CVE-2023-2704

CRITICAL CVSS 9.8 2023-05-19
Threat Entry Updated 2024-11-21

CVE-2023-2757 - Waiting Plugin

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level attackers to access functions to save plugin data that can potentially lead to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Waiting

CVE-2023-2757

HIGH CVSS 7.4 2023-05-18
Threat Entry Updated 2024-11-21

CVE-2023-2706 - Otp Login Woocommerce Gravity Forms Plugin

The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to obtain login codes for administrators. This does require an attacker have access to the phone number configured for an account, which can be obtained via social engineering or reconnaissance.

PLUGIN Otp Login Woocommerce Gravity Forms

CVE-2023-2706

HIGH CVSS 8.1 2023-05-17
Threat Entry Updated 2024-11-21

CVE-2023-2608 - Multiple Page Generator Plugin

The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to missing nonce verification on the projects_list function and insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries leading to resource exhaustion via a forged request granted they can trick an administrator into performing…

PLUGIN Multiple Page Generator

CVE-2023-2608

LOW CVSS 3.1 2023-05-17
Threat Entry Updated 2024-11-21

CVE-2023-2528 - Contact Form Plugin

The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.24. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Contact Form

CVE-2023-2528

MEDIUM CVSS 5.4 2023-05-17
Threat Entry Updated 2024-11-21

CVE-2023-2499 - Registrationmagic Plugin

The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

PLUGIN Registrationmagic

CVE-2023-2499

CRITICAL CVSS 9.8 2023-05-16
Threat Entry Updated 2024-11-21

CVE-2023-2548 - Registrationmagic Plugin

The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers, with administrator-level permissions and above, to change user passwords and potentially take over super-administrator accounts in multisite setup.

PLUGIN Registrationmagic

CVE-2023-2548

MEDIUM CVSS 6.6 2023-05-16
Threat Entry Updated 2024-11-21

CVE-2023-2710 - Video Carousel Slider With Lightbox Plugin

The video carousel slider with lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Video Carousel Slider With Lightbox

CVE-2023-2710

MEDIUM CVSS 6.1 2023-05-16
Threat Entry Updated 2024-11-21

CVE-2023-2708 - Video Gallery Plugin

The Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Video Gallery

CVE-2023-2708

MEDIUM CVSS 6.1 2023-05-16
Threat Entry Updated 2025-01-24

CVE-2023-2180 - Kiwiz Invoices Certification Pdf System Plugin

The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)

PLUGIN Kiwiz Invoices Certification Pdf System

CVE-2023-2180

HIGH CVSS 7.5 2023-05-15
Threat Entry Updated 2025-01-24

CVE-2023-0812 - Ldap Integration Plugin

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.

PLUGIN Ldap Integration

CVE-2023-0812

HIGH CVSS 7.5 2023-05-15
Threat Entry Updated 2025-01-24

CVE-2023-1549 - Ad Inserter Plugin

The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

PLUGIN Ad Inserter

CVE-2023-1549

HIGH CVSS 7.2 2023-05-15
Threat Entry Updated 2025-01-24

CVE-2023-2179 - Woocommerce Order Status Change Notifier Plugin

The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example

PLUGIN Woocommerce Order Status Change Notifier

CVE-2023-2179

MEDIUM CVSS 6.5 2023-05-15
Threat Entry Updated 2025-01-24

CVE-2023-1915 - Thumbnail Carousel Slider Plugin

The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting vulnerability which could be used against high privilege users such as admin.

PLUGIN Thumbnail Carousel Slider

CVE-2023-1915

MEDIUM CVSS 6.1 2023-05-15
Scroll to top