Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13661-13680 of 16306 records
Threat Entry Updated 2025-01-29

CVE-2023-0526 - Post Shortcode Plugin

The Post Shortcode WordPress plugin through 2.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Post Shortcode

CVE-2023-0526

MEDIUM CVSS 5.4 2023-05-08
Threat Entry Updated 2025-02-04

CVE-2023-0280 - Ultimate Carousel For Elementor Plugin

The Ultimate Carousel For Elementor WordPress plugin through 2.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Ultimate Carousel For Elementor

CVE-2023-0280

MEDIUM CVSS 5.4 2023-05-08
Threat Entry Updated 2025-01-28

CVE-2023-0268 - Mega Addons For Wpbakery Page Builder Plugin

The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Mega Addons For Wpbakery Page Builder

CVE-2023-0268

MEDIUM CVSS 5.4 2023-05-08
Threat Entry Updated 2025-05-05

CVE-2023-0544 - Wp Login Box Plugin

The WP Login Box WordPress plugin through 2.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wp Login Box

CVE-2023-0544

MEDIUM CVSS 4.8 2023-05-08
Threat Entry Updated 2025-01-29

CVE-2023-0267 - Ultimate Carousel For Wpbakery Page Builder Plugin

The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Ultimate Carousel For Wpbakery Page Builder

CVE-2023-0267

MEDIUM CVSS 5.4 2023-05-08
Threat Entry Updated 2025-01-30

CVE-2023-1196 - Advanced Custom Fields Plugin

The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present.

PLUGIN Advanced Custom Fields

CVE-2023-1196

HIGH CVSS 8.8 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1730 - Before 3 Plugin

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

PLUGIN Before 3

CVE-2023-1730

CRITICAL CVSS 9.8 2023-05-02
Threat Entry Updated 2025-03-21

CVE-2023-1809 - Download Manager Plugin

The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.

PLUGIN Download Manager

CVE-2023-1809

HIGH CVSS 7.5 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1669 - Before 6 Plugin

The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

PLUGIN Before 6

CVE-2023-1669

HIGH CVSS 7.2 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1805 - Product Catalog Feed By Pixelyoursite Plugin

The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Product Catalog Feed By Pixelyoursite

CVE-2023-1805

MEDIUM CVSS 6.1 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1804 - Product Catalog Feed By Pixelyoursite Plugin

The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.

PLUGIN Product Catalog Feed By Pixelyoursite

CVE-2023-1804

MEDIUM CVSS 6.1 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1861 - Limit Login Attempts Plugin

The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks

PLUGIN Limit Login Attempts

CVE-2023-1861

MEDIUM CVSS 5.4 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1614 - Wp Custom Author Url Plugin

The WP Custom Author URL WordPress plugin before 1.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Wp Custom Author Url

CVE-2023-1614

MEDIUM CVSS 4.8 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1554 - Quick Paypal Payments Plugin

The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Quick Paypal Payments

CVE-2023-1554

MEDIUM CVSS 4.8 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1911 - Blocksy Companion Plugin

The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example

PLUGIN Blocksy Companion

CVE-2023-1911

MEDIUM CVSS 4.3 2023-05-02
Scroll to top