Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13681-13700 of 16306 records
Threat Entry Updated 2025-01-30

CVE-2023-0924 - Popup Plugin

The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (such as an Administrator) to upload arbitrary files, even when modifying the file system is disallowed, such as in a multisite install.

PLUGIN Popup

CVE-2023-0924

HIGH CVSS 7.2 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1125 - Ruby Help Desk Plugin

The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.

PLUGIN Ruby Help Desk

CVE-2023-1125

MEDIUM CVSS 6.5 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1546 - Before 2 Plugin

The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2023-1546

MEDIUM CVSS 6.1 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-0891 - Before 2 Plugin

The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0891

MEDIUM CVSS 5.4 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1525 - Site Reviews Plugin

The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Site Reviews

CVE-2023-1525

MEDIUM CVSS 4.8 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1090 - Smtp Mailing Queue Plugin

The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Smtp Mailing Queue

CVE-2023-1090

MEDIUM CVSS 4.8 2023-05-02
Threat Entry Updated 2025-01-30

CVE-2023-1021 - Amr Ical Events List Plugin

The amr ical events lists WordPress plugin through 6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Amr Ical Events List

CVE-2023-1021

MEDIUM CVSS 4.8 2023-05-02
Threat Entry Updated 2024-11-21

CVE-2023-2297 - Profile Builder Plugin

The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (wppb_front_end_password_recovery). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-0814, or another vulnerability like SQL Injection in another plugin or theme installed on…

PLUGIN Profile Builder

CVE-2023-2297

CRITICAL CVSS 9.8 2023-04-27
Threat Entry Updated 2025-02-04

CVE-2023-1020 - Wp Live Chat Shoutbox Plugin

The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

PLUGIN Wp Live Chat Shoutbox

CVE-2023-1020

CRITICAL CVSS 9.8 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-1624 - Before 2 Plugin

The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be deleted is inside the expected folder. This could allow attackers to make users with the wpcode_activate_snippets capability delete arbitrary log files on the server, including outside of the blog folders

PLUGIN Before 2

CVE-2023-1624

MEDIUM CVSS 6.5 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-1623 - Custom Post Type Ui Plugin

The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to make a logged in admin send such information to an arbitrary email address via a CSRF attack.

PLUGIN Custom Post Type Ui

CVE-2023-1623

MEDIUM CVSS 6.5 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-1129 - Wp Fevents Book Plugin

The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users.

PLUGIN Wp Fevents Book

CVE-2023-1129

MEDIUM CVSS 6.5 2023-04-24
Threat Entry Updated 2025-03-18

CVE-2023-1435 - Ajax Search Pro Plugin

The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Ajax Search Pro

CVE-2023-1435

MEDIUM CVSS 6.1 2023-04-24
Threat Entry Updated 2025-03-18

CVE-2023-1420 - Ajax Search Lite Plugin

The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Ajax Search Lite

CVE-2023-1420

MEDIUM CVSS 6.1 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-1324 - Easy Forms For Mailchimp Plugin

The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Easy Forms For Mailchimp

CVE-2023-1324

MEDIUM CVSS 6.1 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-0899 - Wp Live Chat Shoutbox Plugin

The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputting it back in the Shoutbox, leading to Stored Cross-Site Scripting which could be used against high privilege users such as admins.

PLUGIN Wp Live Chat Shoutbox

CVE-2023-0899

MEDIUM CVSS 6.1 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-1126 - Wp Fevents Book Plugin

The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks

PLUGIN Wp Fevents Book

CVE-2023-1126

MEDIUM CVSS 5.4 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-1414 - Before 8 Plugin

The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours

PLUGIN Before 8

CVE-2023-1414

MEDIUM CVSS 4.3 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-0388 - Random Text Plugin

The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers.

PLUGIN Random Text

CVE-2023-0388

HIGH CVSS 8.8 2023-04-24
Scroll to top