Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13721-13740 of 16306 records
Threat Entry Updated 2025-02-06

CVE-2023-0277 - Wc Fields Factory Plugin

The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

PLUGIN Wc Fields Factory

CVE-2023-0277

HIGH CVSS 7.2 2023-04-17
Threat Entry Updated 2025-02-06

CVE-2023-0889 - Themeflection Numbers Plugin

Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. As a result, it could allow any authenticated users, such as subscriber, to update arbitrary blog options, such as enabling registration and set the default role to administrator

PLUGIN Themeflection Numbers

CVE-2023-0889

MEDIUM CVSS 6.5 2023-04-17
Threat Entry Updated 2025-02-06

CVE-2023-0764 - Gallery By Bestwebsoft Plugin

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.

PLUGIN Gallery By Bestwebsoft

CVE-2023-0764

MEDIUM CVSS 5.4 2023-04-17
Threat Entry Updated 2025-02-06

CVE-2023-0374 - W4 Post List Plugin

The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN W4 Post List

CVE-2023-0374

MEDIUM CVSS 5.4 2023-04-17
Threat Entry Updated 2025-03-03

CVE-2023-0367 - Before 3 Plugin

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2023-0367

MEDIUM CVSS 5.4 2023-04-17
Threat Entry Updated 2024-11-21

CVE-2023-2027 - Zm Ajax Login Register Plugin

The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

PLUGIN Zm Ajax Login Register

CVE-2023-2027

CRITICAL CVSS 9.8 2023-04-15
Threat Entry Updated 2024-11-21

CVE-2023-28121 - Woocommerce Payments Plugin

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

PLUGIN Woocommerce Payments

CVE-2023-28121

CRITICAL CVSS 9.8 2023-04-12
Threat Entry Updated 2024-11-21

CVE-2023-1874 - Wp Data Access Plugin

The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of authorization checks on the multiple_roles_update function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wpda_role[]' parameter during a profile update. This requires the 'Enable role management' setting to be enabled for the site.

PLUGIN Wp Data Access

CVE-2023-1874

HIGH CVSS 7.5 2023-04-12
Threat Entry Updated 2025-02-11

CVE-2023-1381 - Wp Meta Seo Plugin

The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.

PLUGIN Wp Meta Seo

CVE-2023-1381

HIGH CVSS 8.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-1478 - Before 3 Plugin

The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

PLUGIN Before 3

CVE-2023-1478

CRITICAL CVSS 9.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-1406 - Before 3 Plugin

The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.

PLUGIN Before 3

CVE-2023-1406

HIGH CVSS 8.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-1425 - Before 2 Plugin

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins

PLUGIN Before 2

CVE-2023-1425

HIGH CVSS 7.2 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-1426 - Wp Tiles Plugin

The WP Tiles WordPress plugin through 1.1.2 does not ensure that posts to be displayed are not draft/private, allowing any authenticated users, such as subscriber to retrieve the titles of draft and privates posts for example. AN attacker could also retrieve the title of any other type of post.

PLUGIN Wp Tiles

CVE-2023-1426

MEDIUM CVSS 6.5 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-1122 - Simple Giveaways Plugin

The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its Giveaways options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Simple Giveaways

CVE-2023-1122

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0983 - Stylish Cost Calculator Premium Plugin

The stylish-cost-calculator-premium WordPress plugin before 7.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Stored Cross-Site Scripting which could be used against admins when viewing submissions submitted through the Email Quote Form.

PLUGIN Stylish Cost Calculator Premium

CVE-2023-0983

MEDIUM CVSS 6.1 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0546 - Contact Form Plugin

The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a form which will trigger for any visitor to the form or admins previewing or editing the form.

PLUGIN Contact Form

CVE-2023-0546

MEDIUM CVSS 5.4 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0363 - Scheduled Announcements Widget Plugin

The Scheduled Announcements Widget WordPress plugin before 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Scheduled Announcements Widget

CVE-2023-0363

MEDIUM CVSS 5.4 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0156 - Before 5 Plugin

The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list directories anywhere on the server (to which the web server has access). The plugin only displays the last 50 lines of the file.

PLUGIN Before 5

CVE-2023-0156

MEDIUM CVSS 4.9 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-1121 - Simple Giveaways Plugin

The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Simple Giveaways

CVE-2023-1121

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-1120 - Simple Giveaways Plugin

The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Simple Giveaways

CVE-2023-1120

MEDIUM CVSS 4.8 2023-04-10
Scroll to top