Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 13941-13960 of 16313 records
Threat Entry Updated 2025-03-13

CVE-2023-0540 - Gs Filterable Portfolio Plugin

The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Gs Filterable Portfolio

CVE-2023-0540

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-14

CVE-2023-0492 - Gs Products Slider For Woocommerce Plugin

The GS Products Slider for WooCommerce WordPress plugin before 1.5.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Gs Products Slider For Woocommerce

CVE-2023-0492

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0453 - Wp Private Messaging Plugin

The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.

PLUGIN Wp Private Messaging

CVE-2023-0453

MEDIUM CVSS 4.3 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0232 - Before 2 Plugin

The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.

PLUGIN Before 2

CVE-2023-0232

CRITICAL CVSS 9.8 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0442 - Loan Comparison Plugin

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a crafted URL.

PLUGIN Loan Comparison

CVE-2023-0442

MEDIUM CVSS 6.1 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0428 - Watu Quiz Plugin

The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Watu Quiz

CVE-2023-0428

MEDIUM CVSS 6.1 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0419 - Shortcode For Font Awesome Plugin

The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Shortcode For Font Awesome

CVE-2023-0419

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-14

CVE-2023-0380 - Easy Digital Downloads Plugin

The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Easy Digital Downloads

CVE-2023-0380

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-06-10

CVE-2023-0378 - Before 5 Plugin

The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 5

CVE-2023-0378

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0375 - Easy Affiliate Links Plugin

The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Easy Affiliate Links

CVE-2023-0375

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-14

CVE-2023-0372 - Before 0 Plugin

The EmbedStories WordPress plugin before 0.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 0

CVE-2023-0372

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-13

CVE-2023-0371 - Before 1 Plugin

The EmbedSocial WordPress plugin before 1.1.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0371

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0366 - Loan Comparison Plugin

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Loan Comparison

CVE-2023-0366

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0285 - Real Media Library Plugin

The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Real Media Library

CVE-2023-0285

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-14

CVE-2023-0271 - Wp Font Awesome Plugin

The WP Font Awesome WordPress plugin before 1.7.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Wp Font Awesome

CVE-2023-0271

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0231 - Before 2 Plugin

The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2023-0231

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0429 - Before 3 Plugin

The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2023-0429

MEDIUM CVSS 4.8 2023-02-21
Threat Entry Updated 2024-11-21

CVE-2023-0067 - Timed Content Plugin

The Timed Content WordPress plugin before 2.73 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Timed Content

CVE-2023-0067

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2025-03-12

CVE-2023-0059 - Before 1 Plugin

The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0059

MEDIUM CVSS 5.4 2023-02-21
Threat Entry Updated 2024-11-21

CVE-2023-0895 - Wp Coder Plugin

The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Coder

CVE-2023-0895

HIGH CVSS 7.2 2023-02-17
Scroll to top