Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 13961-13980 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2023-0814 - Profile Builder Plugin

The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to retrieve sensitive user meta that can be used to gain access to a high privileged user account. This does require the Usermeta shortcode be enabled to be exploited.

PLUGIN Profile Builder

CVE-2023-0814

MEDIUM CVSS 6.5 2023-02-14
Threat Entry Updated 2025-03-21

CVE-2023-0379 - Spotlight Social Feeds Plugin

The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Spotlight Social Feeds

CVE-2023-0379

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0373 - Lightweight Accordion Plugin

The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Lightweight Accordion

CVE-2023-0373

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0362 - Themify Portfolio Post Plugin

Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Themify Portfolio Post

CVE-2023-0362

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0405 - Ai Training Plugin

The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts.

PLUGIN Ai Training

CVE-2023-0405

MEDIUM CVSS 4.3 2023-02-13
Threat Entry Updated 2024-11-21

CVE-2023-0263 - Wp Yelp Review Slider Plugin

The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

PLUGIN Wp Yelp Review Slider

CVE-2023-0263

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0262 - Wp Airbnb Review Slider Plugin

The WP Airbnb Review Slider WordPress plugin before 3.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

PLUGIN Wp Airbnb Review Slider

CVE-2023-0262

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0261 - Wp Tripadvisor Review Slider Plugin

The WP TripAdvisor Review Slider WordPress plugin before 10.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

PLUGIN Wp Tripadvisor Review Slider

CVE-2023-0261

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0260 - Wp Review Slider Plugin

The WP Review Slider WordPress plugin before 12.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

PLUGIN Wp Review Slider

CVE-2023-0260

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0259 - Wp Google Review Slider Plugin

The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

PLUGIN Wp Google Review Slider

CVE-2023-0259

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0255 - Enable Media Replace Plugin

The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

PLUGIN Enable Media Replace

CVE-2023-0255

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0220 - Pinpoint Booking System Plugin

The Pinpoint Booking System WordPress plugin before 2.9.9.2.9 does not validate and escape one of its shortcode attributes before using it in a SQL statement, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.

PLUGIN Pinpoint Booking System

CVE-2023-0220

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2025-03-20

CVE-2023-0360 - Location Weather Plugin

The Location Weather WordPress plugin before 1.3.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Location Weather

CVE-2023-0360

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0333 - Templatesnext Toolkit Plugin

The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using them to generate an HTML tag, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Templatesnext Toolkit

CVE-2023-0333

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0275 - Easy Accept Payments For Paypal Plugin

The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Easy Accept Payments For Paypal

CVE-2023-0275

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0270 - Yamaps For Plugin

The YaMaps for WordPress Plugin WordPress plugin before 0.6.26 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Yamaps For

CVE-2023-0270

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-20

CVE-2023-0177 - Social Like Box And Page By Wpdevart Plugin

The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Social Like Box And Page By Wpdevart

CVE-2023-0177

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0098 - Before 115 Does Not Escape Some Parameters Plugin

The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

PLUGIN Before 115 Does Not Escape Some Parameters

CVE-2023-0098

HIGH CVSS 8.8 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0080 - Customer Reviews For Woocommerce Plugin

The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file…

PLUGIN Customer Reviews For Woocommerce

CVE-2023-0080

HIGH CVSS 8.8 2023-02-13
Scroll to top