Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14001-14020 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2023-0718 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0718

MEDIUM CVSS 5.4 2023-02-08
Threat Entry Updated 2024-11-21

CVE-2023-0731 - Interactive Geo Maps Plugin

The Interactive Geo Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the action content parameter in versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Interactive Geo Maps

CVE-2023-0731

MEDIUM CVSS 6.4 2023-02-07
Threat Entry Updated 2024-11-21

CVE-2023-0730 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0730

MEDIUM CVSS 5.4 2023-02-07
Threat Entry Updated 2024-11-21

CVE-2023-0727 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0727

MEDIUM CVSS 5.4 2023-02-07
Threat Entry Updated 2024-11-21

CVE-2023-0723 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_object function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0723

MEDIUM CVSS 5.4 2023-02-07
Threat Entry Updated 2024-11-21

CVE-2023-0719 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0719

MEDIUM CVSS 5.4 2023-02-07
Threat Entry Updated 2024-11-21

CVE-2023-0712 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0712

MEDIUM CVSS 5.4 2023-02-07
Threat Entry Updated 2024-11-21

CVE-2023-0728 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0728

MEDIUM CVSS 5.4 2023-02-07
Threat Entry Updated 2024-11-21

CVE-2023-0713 - Wicked Folders Plugin

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

PLUGIN Wicked Folders

CVE-2023-0713

MEDIUM CVSS 5.4 2023-02-07
Threat Entry Updated 2025-03-25

CVE-2023-0234 - Siteground Security Plugin

The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.

PLUGIN Siteground Security

CVE-2023-0234

HIGH CVSS 8.8 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0236 - Before 2 Plugin

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-0236

MEDIUM CVSS 6.1 2023-02-06
Threat Entry Updated 2025-03-26

CVE-2023-0282 - Before 1 Plugin

The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0282

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0252 - Contextual Related Posts Plugin

The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Contextual Related Posts

CVE-2023-0252

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-26

CVE-2023-0178 - Annual Archive Plugin

The Annual Archive WordPress plugin before 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Annual Archive

CVE-2023-0178

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0176 - Giveaways And Contests By Rafflepress Plugin

The Giveaways and Contests by RafflePress WordPress plugin before 1.11.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Giveaways And Contests By Rafflepress

CVE-2023-0176

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0174 - Before 8 Plugin

The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 8

CVE-2023-0174

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0173 - Drop Sales Funnel Builder For Plugin

The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Drop Sales Funnel Builder For

CVE-2023-0173

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0171 - Countdown Widget Plugin

The jQuery T(-) Countdown Widget WordPress plugin before 2.3.24 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Countdown Widget

CVE-2023-0171

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0170 - Html5 Audio Player Plugin

The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Html5 Audio Player

CVE-2023-0170

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0154 - Before 1 Plugin

The GamiPress WordPress plugin before 1.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0154

MEDIUM CVSS 5.4 2023-02-06
Scroll to top