Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13701-13720 of 16306 records
Threat Entry Updated 2025-02-04

CVE-2023-0424 - Ms Reviews Plugin

The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks

PLUGIN Ms Reviews

CVE-2023-0424

MEDIUM CVSS 5.4 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-0418 - Video Central Plugin

The Video Central for WordPress plugin through 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Video Central

CVE-2023-0418

MEDIUM CVSS 5.4 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-0276 - Weaver Xtreme Theme Support Plugin

The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Weaver Xtreme Theme Support

CVE-2023-0276

MEDIUM CVSS 5.4 2023-04-24
Threat Entry Updated 2025-02-04

CVE-2023-0420 - Custom Post Type And Taxonomy Gui Manager Plugin

The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising as well as escaping in some parameters, allowing attackers to make a logged in admin put Stored Cross-Site Scripting payloads via CSRF

PLUGIN Custom Post Type And Taxonomy Gui Manager

CVE-2023-0420

MEDIUM CVSS 4.8 2023-04-24
Threat Entry Updated 2024-11-21

CVE-2023-30616 - Designed To Make Form Creation Easier Plugin

Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a missing nonce check. There is potential for a Cross Site Request Forgery for all form blocks, since it allows to send requests to the forms from any website without a user noticing. Users are advised to upgrade to version 1.0.2. There are no known workarounds for this vulnerability.

PLUGIN Designed To Make Form Creation Easier

CVE-2023-30616

MEDIUM CVSS 6.5 2023-04-20
Threat Entry Updated 2024-11-21

CVE-2023-2170 - Taxopress Plugin

The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Taxopress

CVE-2023-2170

MEDIUM CVSS 5.5 2023-04-19
Threat Entry Updated 2024-11-21

CVE-2023-2169 - Taxopress Plugin

The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Taxopress

CVE-2023-2169

MEDIUM CVSS 5.5 2023-04-19
Threat Entry Updated 2024-11-21

CVE-2023-2168 - Taxopress Plugin

The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Taxopress

CVE-2023-2168

MEDIUM CVSS 5.5 2023-04-19
Threat Entry Updated 2024-11-21

CVE-2023-2120 - Thumbnail Carousel Slider Plugin

The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Thumbnail Carousel Slider

CVE-2023-2120

MEDIUM CVSS 6.1 2023-04-18
Threat Entry Updated 2024-11-21

CVE-2023-2119 - Responsive Filterable Portfolio Plugin

The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Responsive Filterable Portfolio

CVE-2023-2119

MEDIUM CVSS 6.1 2023-04-18
Threat Entry Updated 2025-02-06

CVE-2023-1371 - W4 Post List Plugin

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them

PLUGIN W4 Post List

CVE-2023-1371

MEDIUM CVSS 6.5 2023-04-17
Threat Entry Updated 2025-02-06

CVE-2023-1331 - Before 1 Plugin

The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.

PLUGIN Before 1

CVE-2023-1331

MEDIUM CVSS 6.5 2023-04-17
Threat Entry Updated 2024-11-21

CVE-2023-1274 - Before 3 Plugin

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks

PLUGIN Before 3

CVE-2023-1274

MEDIUM CVSS 6.5 2023-04-17
Threat Entry Updated 2025-02-06

CVE-2023-1473 - Slider Gallery And Carousel Plugin

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Slider Gallery And Carousel

CVE-2023-1473

MEDIUM CVSS 6.1 2023-04-17
Threat Entry Updated 2025-04-23

CVE-2023-1413 - Before 8 Plugin

The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 8

CVE-2023-1413

MEDIUM CVSS 6.1 2023-04-17
Threat Entry Updated 2025-02-06

CVE-2023-1373 - W4 Post List Plugin

The W4 Post List WordPress plugin before 2.4.6 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

PLUGIN W4 Post List

CVE-2023-1373

MEDIUM CVSS 6.1 2023-04-17
Threat Entry Updated 2025-02-06

CVE-2023-1282 - D Drop Multiple File Upload Pro Contact Form 7 With Remote Storage Integrations Plugin

The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.

PLUGIN D Drop Multiple File Upload Pro Contact Form 7 With Remote Storage Integrations

CVE-2023-1282

MEDIUM CVSS 6.1 2023-04-17
Threat Entry Updated 2025-03-05

CVE-2023-1325 - Easy Forms For Mailchimp Plugin

The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Easy Forms For Mailchimp

CVE-2023-1325

MEDIUM CVSS 5.4 2023-04-17
Threat Entry Updated 2025-02-06

CVE-2023-1427 - Photo Gallery By 10web Plugin

- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.

PLUGIN Photo Gallery By 10web

CVE-2023-1427

MEDIUM CVSS 4.9 2023-04-17
Threat Entry Updated 2025-03-05

CVE-2023-0765 - Gallery By Bestwebsoft Plugin

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be installed for this vulnerability to be exploitable.

PLUGIN Gallery By Bestwebsoft

CVE-2023-0765

HIGH CVSS 8.8 2023-04-17
Scroll to top