Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13861-13880 of 16306 records
Threat Entry Updated 2025-02-27

CVE-2023-0538 - Campaign Url Builder Plugin

The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Campaign Url Builder

CVE-2023-0538

MEDIUM CVSS 5.4 2023-03-13
Threat Entry Updated 2024-11-21

CVE-2023-0219 - Before 2 Plugin

The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML.

PLUGIN Before 2

CVE-2023-0219

MEDIUM CVSS 5.4 2023-03-13
Threat Entry Updated 2025-02-27

CVE-2023-0172 - Before 1 Plugin

The Juicer WordPress plugin before 1.11 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0172

MEDIUM CVSS 5.4 2023-03-13
Threat Entry Updated 2025-02-27

CVE-2023-0073 - Client Logo Carousel Plugin

The Client Logo Carousel WordPress plugin through 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Client Logo Carousel

CVE-2023-0073

MEDIUM CVSS 5.4 2023-03-13
Threat Entry Updated 2025-02-27

CVE-2023-0066 - Companion Sitemap Generator Plugin

The Companion Sitemap Generator WordPress plugin through 4.5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Companion Sitemap Generator

CVE-2023-0066

MEDIUM CVSS 5.4 2023-03-13
Threat Entry Updated 2025-02-27

CVE-2023-0844 - Before 2 Plugin

The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 2

CVE-2023-0844

MEDIUM CVSS 4.8 2023-03-13
Threat Entry Updated 2024-11-21

CVE-2023-1372 - Wh Testimonials Plugin

The WH Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as wh_homepage, wh_text_short, wh_text_full and in versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wh Testimonials

CVE-2023-1372

HIGH CVSS 7.2 2023-03-13
Threat Entry Updated 2024-11-21

CVE-2023-1374 - Solidres Plugin

The Solidres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'currency_name' parameter in versions up to, and including, 0.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Solidres

CVE-2023-1374

MEDIUM CVSS 4.4 2023-03-13
Threat Entry Updated 2026-02-13

CVE-2023-1346 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_page_cache function. This makes it possible for unauthenticated attackers to clear the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1346

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1345 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the queue_posts function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1345

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1344 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the uucss_update_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1344

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1343 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the attach_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1343

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1342 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect function. This makes it possible for unauthenticated attackers to connect the site to a new license key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1342

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1341 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated attackers to turn off caching via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1341

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1340 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_uucss_logs function. This makes it possible for unauthenticated attackers to clear plugin logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1340

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1339 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the uucss_update_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to update caching rules.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1339

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1338 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the attach_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify cache rules.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1338

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1337 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1337

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1336 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to disable caching.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1336

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-20

CVE-2023-1335 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the ucss_connect function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to connect a new license key to the site.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1335

MEDIUM CVSS 4.3 2023-03-10
Scroll to top