Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13741-13760 of 16306 records
Threat Entry Updated 2025-02-11

CVE-2023-0893 - Before 1 Plugin

The Time Sheets WordPress plugin before 1.29.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2023-0893

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0874 - Before 3 Plugin

The Klaviyo WordPress plugin before 3.0.10 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2023-0874

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0605 - Auto Rename Media On Upload Plugin

The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Auto Rename Media On Upload

CVE-2023-0605

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0423 - Wordpress Amazon S3 Plugin

The WordPress Amazon S3 Plugin WordPress plugin before 1.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Wordpress Amazon S3

CVE-2023-0423

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-05-05

CVE-2023-0422 - Article Directory Plugin

The Article Directory WordPress plugin through 1.3 does not properly sanitize the `publish_terms_text` setting before displaying it in the administration panel, which may enable administrators to conduct Stored XSS attacks in multisite contexts.

PLUGIN Article Directory

CVE-2023-0422

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2025-02-11

CVE-2023-0157 - Before 5 Plugin

The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting this page.

PLUGIN Before 5

CVE-2023-0157

MEDIUM CVSS 4.8 2023-04-10
Threat Entry Updated 2024-11-21

CVE-2023-1931 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the deleteCssAndJsCacheToolbar function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to perform cache deletion.

PLUGIN Wp Fastest Cache

CVE-2023-1931

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1930 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the wpfc_clear_cache_of_allsites_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to delete caches.

PLUGIN Wp Fastest Cache

CVE-2023-1930

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1929 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_purgecache_varnish_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to purge the varnish cache.

PLUGIN Wp Fastest Cache

CVE-2023-1929

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1928 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_preload_single_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to initiate cache creation.

PLUGIN Wp Fastest Cache

CVE-2023-1928

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1927 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCssAndJsCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Fastest Cache

CVE-2023-1927

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1926 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Fastest Cache

CVE-2023-1926

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1925 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_clear_cache_of_allsites_callback function. This makes it possible for unauthenticated attackers to clear caches via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Fastest Cache

CVE-2023-1925

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1924 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_toolbar_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Fastest Cache

CVE-2023-1924

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1923 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_remove_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Fastest Cache

CVE-2023-1923

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1922 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_pause_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Fastest Cache

CVE-2023-1922

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1921 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_start_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Fastest Cache

CVE-2023-1921

MEDIUM CVSS 4.3 2023-04-06
Scroll to top