Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 13981-14000 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2023-0159 - Extensive Vc Addons For Wpbakery Page Builder Plugin

The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains.

PLUGIN Extensive Vc Addons For Wpbakery Page Builder

CVE-2023-0159

HIGH CVSS 7.5 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0169 - Before 3 Plugin

The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 3

CVE-2023-0169

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0166 - Product Slider For Woocommerce By Pickplugins

The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Product Slider For Woocommerce By Pickplugins

CVE-2023-0166

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0151 - Utubevideo Gallery Plugin

The uTubeVideo Gallery WordPress plugin before 2.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Utubevideo Gallery

CVE-2023-0151

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0075 - Amazonjs Plugin

The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Amazonjs

CVE-2023-0075

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0061 - Me Product Reviews For Woocommerce Plugin

The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Me Product Reviews For Woocommerce

CVE-2023-0061

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-03-21

CVE-2023-0060 - Responsive Gallery Grid Plugin

The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Responsive Gallery Grid

CVE-2023-0060

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2025-01-14

CVE-2023-0034 - Before 1 Plugin

The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0034

MEDIUM CVSS 5.4 2023-02-13
Threat Entry Updated 2024-11-21

CVE-2023-0726 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0726

MEDIUM CVSS 5.4 2023-02-08
Threat Entry Updated 2024-11-21

CVE-2023-0725 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0725

MEDIUM CVSS 5.4 2023-02-08
Threat Entry Updated 2024-11-21

CVE-2023-0724 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0724

MEDIUM CVSS 5.4 2023-02-08
Threat Entry Updated 2024-11-21

CVE-2023-0722 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0722

MEDIUM CVSS 5.4 2023-02-08
Threat Entry Updated 2024-11-21

CVE-2023-0720 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0720

MEDIUM CVSS 5.4 2023-02-08
Threat Entry Updated 2024-11-21

CVE-2023-0717 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0717

MEDIUM CVSS 5.4 2023-02-08
Threat Entry Updated 2024-11-21

CVE-2023-0716 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0716

MEDIUM CVSS 5.4 2023-02-08
Threat Entry Updated 2024-11-21

CVE-2023-0715 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0715

MEDIUM CVSS 5.4 2023-02-08
Threat Entry Updated 2024-11-21

CVE-2023-0711 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the view state of the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0711

MEDIUM CVSS 5.4 2023-02-08
Threat Entry Updated 2024-11-21

CVE-2023-0685 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin..

PLUGIN Wicked Folders

CVE-2023-0685

MEDIUM CVSS 5.4 2023-02-08
Threat Entry Updated 2024-11-21

CVE-2023-0684 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as changing the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0684

MEDIUM CVSS 5.4 2023-02-08
Scroll to top