Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 13921-13940 of 16313 records
Threat Entry Updated 2025-03-18

CVE-2023-0552 - Registration Forms Plugin

The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability

PLUGIN Registration Forms

CVE-2023-0552

MEDIUM CVSS 5.4 2023-02-27
Threat Entry Updated 2024-11-21

CVE-2023-0539 - Gs Insever Portfolio Plugin

The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Gs Insever Portfolio

CVE-2023-0539

MEDIUM CVSS 5.4 2023-02-27
Threat Entry Updated 2025-03-10

CVE-2023-0535 - Donation Block For Paypal Plugin

The Donation Block For PayPal WordPress plugin before 2.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Donation Block For Paypal

CVE-2023-0535

MEDIUM CVSS 5.4 2023-02-27
Threat Entry Updated 2025-03-10

CVE-2023-0548 - Before 2 Plugin

The Namaste! LMS WordPress plugin before 2.5.9.4 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 2

CVE-2023-0548

MEDIUM CVSS 4.8 2023-02-27
Threat Entry Updated 2025-03-11

CVE-2023-0543 - Arigato Autoresponder And Newsletter Plugin

The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Arigato Autoresponder And Newsletter

CVE-2023-0543

MEDIUM CVSS 4.8 2023-02-27
Threat Entry Updated 2025-03-10

CVE-2023-0331 - Correos Oficial Plugin

The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.

PLUGIN Correos Oficial

CVE-2023-0331

HIGH CVSS 7.5 2023-02-27
Threat Entry Updated 2025-03-10

CVE-2023-0279 - Media Library Assistant Plugin

The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Media Library Assistant

CVE-2023-0279

HIGH CVSS 7.2 2023-02-27
Threat Entry Updated 2025-03-10

CVE-2023-0278 - Before 2 Plugin

The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Before 2

CVE-2023-0278

HIGH CVSS 7.2 2023-02-27
Threat Entry Updated 2025-03-10

CVE-2023-0043 - Add User Plugin

The Custom Add User WordPress plugin through 2.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Add User

CVE-2023-0043

MEDIUM CVSS 6.1 2023-02-27
Threat Entry Updated 2025-03-10

CVE-2023-0230 - Vk All In One Expansion Unit Plugin

The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Vk All In One Expansion Unit

CVE-2023-0230

MEDIUM CVSS 5.4 2023-02-27
Threat Entry Updated 2025-03-18

CVE-2023-0168 - Olevmedia Shortcodes Plugin

The Olevmedia Shortcodes WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Olevmedia Shortcodes

CVE-2023-0168

MEDIUM CVSS 5.4 2023-02-27
Threat Entry Updated 2024-11-21

CVE-2023-1068 - Read More Excerpt Link Plugin

The Download Read More Excerpt Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.0. This is due to missing or incorrect nonce validation on the read_more_excerpt_link_menu_options() function. This makes it possible for unauthenticated attackers to update he plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Read More Excerpt Link

CVE-2023-1068

MEDIUM CVSS 4.3 2023-02-27
Threat Entry Updated 2024-11-21

CVE-2023-1029 - Wp Meta Seo Plugin

The WP Meta SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.3. This is due to missing or incorrect nonce validation on the regenerateSitemaps function. This makes it possible for unauthenticated attackers to regenerate Sitemaps via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Meta Seo

CVE-2023-1029

MEDIUM CVSS 4.3 2023-02-24
Threat Entry Updated 2024-11-21

CVE-2023-0586 - All In One Seo Plugin

The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Contributor+ role to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN All In One Seo

CVE-2023-0586

MEDIUM CVSS 6.4 2023-02-24
Threat Entry Updated 2024-11-21

CVE-2023-0585 - All In One Seo Plugin

The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Administrator role or above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN All In One Seo

CVE-2023-0585

MEDIUM CVSS 4.4 2023-02-24
Threat Entry Updated 2024-11-21

CVE-2023-26326 - Buddyforms Plugin

The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present.

PLUGIN Buddyforms

CVE-2023-26326

CRITICAL CVSS 9.8 2023-02-23
Threat Entry Updated 2024-11-21

CVE-2023-26325 - Reviewx Plugin

The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.

PLUGIN Reviewx

CVE-2023-26325

HIGH CVSS 8.8 2023-02-23
Threat Entry Updated 2024-11-21

CVE-2023-0942 - Japanized For Woocommerce Plugin

The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Japanized For Woocommerce

CVE-2023-0942

MEDIUM CVSS 6.1 2023-02-21
Threat Entry Updated 2025-03-14

CVE-2023-0559 - Gs Portfolio For Envato Plugin

The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Gs Portfolio For Envato

CVE-2023-0559

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0541 - Gs Books Showcase Plugin

The GS Books Showcase WordPress plugin before 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Gs Books Showcase

CVE-2023-0541

MEDIUM CVSS 5.4 2023-02-21
Scroll to top