Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13761-13780 of 16306 records
Threat Entry Updated 2024-11-21

CVE-2023-1920 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_purgecache_varnish_callback function. This makes it possible for unauthenticated attackers to purge the varnish cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Fastest Cache

CVE-2023-1920

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1919 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache-related settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Fastest Cache

CVE-2023-1919

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1918 - Wp Fastest Cache Plugin

The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_callback function. This makes it possible for unauthenticated attackers to invoke a cache building action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Fastest Cache

CVE-2023-1918

MEDIUM CVSS 4.3 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1912 - Limit Login Attempts Plugin

The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the plugin's settings page. This only works when the plugin prioritizes use of the X-FORWARDED-FOR header, which can be configured in its settings.

PLUGIN Limit Login Attempts

CVE-2023-1912

HIGH CVSS 7.2 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1913 - Maps Widget For Google Maps Plugin

The Maps Widget for Google Maps for WordPress is vulnerable to Stored Cross-Site Scripting via widget settings in versions up to, and including, 4.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Maps Widget For Google Maps

CVE-2023-1913

MEDIUM CVSS 4.4 2023-04-06
Threat Entry Updated 2024-11-21

CVE-2023-1868 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via the yrc_clear_cache GET parameter in versions up to, and including, 1.2.3. This makes it possible for unauthenticated attackers to clear the plugin's cache.

PLUGIN Yourchannel

CVE-2023-1868

MEDIUM CVSS 6.5 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1865 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when resetting plugin settings via the yrc_nuke GET parameter in versions up to, and including, 1.2.3. This makes it possible for unauthenticated attackers to delete YouTube channels from the plugin.

PLUGIN Yourchannel

CVE-2023-1865

MEDIUM CVSS 6.5 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1869 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Yourchannel

CVE-2023-1869

MEDIUM CVSS 5.5 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1871 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the deleteLang function. This makes it possible for unauthenticated attackers to reset the plugin's quick language translation settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Yourchannel

CVE-2023-1871

MEDIUM CVSS 5.4 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1867 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to change the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Yourchannel

CVE-2023-1867

MEDIUM CVSS 5.4 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1866 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the clearKeys function. This makes it possible for unauthenticated attackers to reset the plugin's channel settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Yourchannel

CVE-2023-1866

MEDIUM CVSS 5.4 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1870 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the saveLang function. This makes it possible for unauthenticated attackers to change the plugin's quick language translation settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Yourchannel

CVE-2023-1870

MEDIUM CVSS 4.3 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1840 - Spotify Play Button For Wordpress Plugin

The Sp*tify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.07 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Spotify Play Button For Wordpress

CVE-2023-1840

MEDIUM CVSS 4.4 2023-04-04
Threat Entry Updated 2024-11-21

CVE-2023-23977 - Social Comments Plugin

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin for Vkontakte Comments and Disqus Comments plugin

PLUGIN Social Comments

CVE-2023-23977

MEDIUM CVSS 6.5 2023-04-04
Threat Entry Updated 2025-02-14

CVE-2023-1330 - Before 1 Plugin

The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.

PLUGIN Before 1

CVE-2023-1330

MEDIUM CVSS 6.5 2023-04-03
Threat Entry Updated 2025-02-14

CVE-2023-1377 - Solidres Plugin

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Solidres

CVE-2023-1377

MEDIUM CVSS 6.1 2023-04-03
Scroll to top