Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13801-13820 of 16306 records
Threat Entry Updated 2025-02-19

CVE-2023-1087 - Wc Sales Notification Plugin

The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Wc Sales Notification

CVE-2023-1087

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-1086 - Preview Link Generator Plugin

The Preview Link Generator WordPress plugin before 1.0.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Preview Link Generator

CVE-2023-1086

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0505 - Ever Compare Plugin

The Ever Compare WordPress plugin through 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Ever Compare

CVE-2023-0505

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0504 - Before 2 Plugin

The HT Politic WordPress plugin before 2.3.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 2

CVE-2023-0504

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0441 - Gallery Blocks With Lightbox Plugin

The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a default administrator user role.

PLUGIN Gallery Blocks With Lightbox

CVE-2023-0441

HIGH CVSS 8.1 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0502 - Wp News Plugin

The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Wp News

CVE-2023-0502

MEDIUM CVSS 6.5 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0501 - Wp Insurance Plugin

The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Wp Insurance

CVE-2023-0501

MEDIUM CVSS 6.5 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0500 - Wp Film Studio Plugin

The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Wp Film Studio

CVE-2023-0500

MEDIUM CVSS 6.5 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0335 - Wp Shamsi Plugin

The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.

PLUGIN Wp Shamsi

CVE-2023-0335

MEDIUM CVSS 6.5 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0491 - Schedulicity Plugin

The Schedulicity WordPress plugin through 2.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Schedulicity

CVE-2023-0491

MEDIUM CVSS 5.4 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0395 - Menu Shortcode Plugin

The menu shortcode WordPress plugin through 1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Menu Shortcode

CVE-2023-0395

MEDIUM CVSS 5.4 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0503 - Free Woocommerce Theme 99fy Extension Plugin

The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Free Woocommerce Theme 99fy Extension

CVE-2023-0503

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0499 - Before 1 Plugin

The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0499

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0498 - Wp Education Plugin

The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Wp Education

CVE-2023-0498

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-26

CVE-2023-0497 - Ht Portfolio Plugin

The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Ht Portfolio

CVE-2023-0497

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-14

CVE-2023-0496 - Before 1 Plugin

The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Before 1

CVE-2023-0496

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0495 - Ht Slider For Elementor Plugin

The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Ht Slider For Elementor

CVE-2023-0495

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0484 - Gutenberg Blocks Plugin

The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

PLUGIN Gutenberg Blocks

CVE-2023-0484

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2025-02-19

CVE-2023-0467 - Wp Dark Mode Plugin

The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using it to load a PHP template. This leads to Local File Inclusion on servers where non-existent directories may be traversed, or when chained with another vulnerability allowing arbitrary directory creation.

PLUGIN Wp Dark Mode

CVE-2023-0467

MEDIUM CVSS 4.3 2023-03-27
Scroll to top