Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13881-13900 of 16306 records
Threat Entry Updated 2026-02-20

CVE-2023-1334 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the queue_posts function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify the plugin's cache.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1334

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2026-02-13

CVE-2023-1333 - Rapidload Power Up For Autoptimize Plugin

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_page_cache function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete the plugin's cache.

PLUGIN Rapidload Power Up For Autoptimize

CVE-2023-1333

MEDIUM CVSS 4.3 2023-03-10
Threat Entry Updated 2024-11-21

CVE-2023-1263 - Coming Soon Maintenance Plugin

The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode is enabled.

PLUGIN Coming Soon Maintenance

CVE-2023-1263

MEDIUM CVSS 5.3 2023-03-07
Threat Entry Updated 2026-04-08

CVE-2021-4331 - Plus Addons For Elementor Plugin

The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders functionality. As part of the registration form, users can choose which role to set as the default for users upon registration. This field is not hidden for lower-level users so any user with access to the Elementor page builder, such as contributors, can set the default role to administrator. Since contributors can not publish posts,…

PLUGIN Plus Addons For Elementor

CVE-2021-4331

HIGH CVSS 8.8 2023-03-07
Threat Entry Updated 2026-04-08

CVE-2021-4333 - Wp Statistics Plugin

The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing or incorrect nonce validation on the view() function. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Statistics

CVE-2021-4333

MEDIUM CVSS 6.5 2023-03-07
Threat Entry Updated 2026-04-08

CVE-2021-4332 - Plus Addons For Elementor Plugin

The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used file_get_contents with no verification that the file being supplied was an SVG file, so any user with access to the Elementor page builder, such as contributors, could read arbitrary files on the WordPress installation.

PLUGIN Plus Addons For Elementor

CVE-2021-4332

MEDIUM CVSS 6.5 2023-03-07
Threat Entry Updated 2026-04-08

CVE-2021-4330 - Template Kit Import Plugin

The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads due to insufficient validation of file type upon extracting uploaded Zip files in the installFreeTemplateKit and uploadTemplateKitZipFile functions. This makes it possible for attackers with contributor-lever permissions and above to upload arbitrary files and potentially gain remote code execution in versions up to and including 1.0.13 of Template Kit – Import and versions up to and including 2.0.10 of Envato Elements & Download.

PLUGIN Template Kit Import

CVE-2021-4330

HIGH CVSS 8.8 2023-03-07
Threat Entry Updated 2024-11-21

CVE-2023-0377 - Scriptless Social Sharing Plugin

The Scriptless Social Sharing WordPress plugin before 3.2.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Scriptless Social Sharing

CVE-2023-0377

MEDIUM CVSS 5.4 2023-03-06
Threat Entry Updated 2025-03-06

CVE-2023-0212 - Advanced Recent Posts Plugin

The Advanced Recent Posts WordPress plugin through 0.6.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Advanced Recent Posts

CVE-2023-0212

MEDIUM CVSS 5.4 2023-03-06
Threat Entry Updated 2025-03-06

CVE-2023-0165 - Cost Calculator Plugin

The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Cost Calculator

CVE-2023-0165

MEDIUM CVSS 5.4 2023-03-06
Threat Entry Updated 2025-05-05

CVE-2023-0078 - Resume Builder Plugin

The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users

PLUGIN Resume Builder

CVE-2023-0078

MEDIUM CVSS 5.4 2023-03-06
Threat Entry Updated 2024-11-21

CVE-2023-0076 - Download Attachments Plugin

The Download Attachments WordPress plugin before 1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Download Attachments

CVE-2023-0076

MEDIUM CVSS 5.4 2023-03-06
Threat Entry Updated 2025-03-05

CVE-2023-0069 - Wpaudio Mp3 Player Plugin

The WPaudio MP3 Player WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Wpaudio Mp3 Player

CVE-2023-0069

MEDIUM CVSS 5.4 2023-03-06
Threat Entry Updated 2025-03-06

CVE-2023-0068 - Product Gtin Ean Upc Isbn For Woocommerce Plugin

The Product GTIN (EAN, UPC, ISBN) for WooCommerce WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Product Gtin Ean Upc Isbn For Woocommerce

CVE-2023-0068

MEDIUM CVSS 5.4 2023-03-06
Threat Entry Updated 2024-11-21

CVE-2023-0065 - I2 Pros Cons Plugin

The i2 Pros & Cons WordPress plugin through 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN I2 Pros Cons

CVE-2023-0065

MEDIUM CVSS 5.4 2023-03-06
Threat Entry Updated 2025-03-06

CVE-2023-0328 - Before 2 Plugin

The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).

PLUGIN Before 2

CVE-2023-0328

MEDIUM CVSS 4.3 2023-03-06
Threat Entry Updated 2025-03-06

CVE-2023-0064 - Evision Responsive Column Layout Shortcodes Plugin

The eVision Responsive Column Layout Shortcodes WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Evision Responsive Column Layout Shortcodes

CVE-2023-0064

MEDIUM CVSS 5.4 2023-03-06
Threat Entry Updated 2025-03-06

CVE-2023-0063 - Wordpress Shortcodes Plugin

The WordPress Shortcodes WordPress plugin through 1.6.36 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Wordpress Shortcodes

CVE-2023-0063

MEDIUM CVSS 5.4 2023-03-06
Threat Entry Updated 2024-11-21

CVE-2023-0968 - Watu Quiz Plugin

The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Watu Quiz

CVE-2023-0968

MEDIUM CVSS 6.1 2023-03-03
Threat Entry Updated 2024-11-21

CVE-2023-0084 - Metform Elementor Contact Form Builder Plugin

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, which is the submissions page.

PLUGIN Metform Elementor Contact Form Builder

CVE-2023-0084

HIGH CVSS 7.2 2023-03-02
Scroll to top