Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14021-14040 of 16313 records
Threat Entry Updated 2025-03-25

CVE-2023-0153 - Vimeo Video Autoplay Automute Plugin

The Vimeo Video Autoplay Automute WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Vimeo Video Autoplay Automute

CVE-2023-0153

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0150 - Before 1 Plugin

The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-0150

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0149 - Before 0 Plugin

The WordPrezi WordPress plugin before 0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 0

CVE-2023-0149

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0148 - Gallery Factory Lite Plugin

The Gallery Factory Lite WordPress plugin through 2.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Gallery Factory Lite

CVE-2023-0148

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0147 - Flexible Captcha Plugin

The Flexible Captcha WordPress plugin through 4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Flexible Captcha

CVE-2023-0147

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0146 - Naver Map Plugin

The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Naver Map

CVE-2023-0146

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-26

CVE-2023-0144 - Event Manager And Tickets Selling Plugin For Woocommerce

The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Event Manager And Tickets Selling Plugin For Woocommerce

CVE-2023-0144

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0143 - Send Pdf For Contact Form 7 Plugin

The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

PLUGIN Send Pdf For Contact Form 7

CVE-2023-0143

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0096 - Before 1 Plugin

The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0096

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0095 - Page View Count Plugin

The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Page View Count

CVE-2023-0095

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0082 - Before 7 Plugin

The ExactMetrics WordPress plugin before 7.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 7

CVE-2023-0082

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0081 - Before 8 Plugin

The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 8

CVE-2023-0081

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0072 - Wc Vendors Marketplace Plugin

The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Wc Vendors Marketplace

CVE-2023-0072

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0070 - Before 1 Plugin

The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0070

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2025-03-25

CVE-2023-0062 - Ean For Woocommerce Plugin

The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Ean For Woocommerce

CVE-2023-0062

MEDIUM CVSS 5.4 2023-02-06
Threat Entry Updated 2024-11-21

CVE-2023-0619 - Kraken Io Image Optimizer Plugin

The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset image optimizations.

PLUGIN Kraken Io Image Optimizer

CVE-2023-0619

MEDIUM CVSS 6.5 2023-02-01
Threat Entry Updated 2025-04-21

CVE-2023-0097 - List Category Posts Plugin

The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN List Category Posts

CVE-2023-0097

MEDIUM CVSS 5.4 2023-01-30
Threat Entry Updated 2025-03-27

CVE-2023-0074 - Wp Social Widget Plugin

The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Wp Social Widget

CVE-2023-0074

MEDIUM CVSS 5.4 2023-01-30
Threat Entry Updated 2025-03-27

CVE-2023-0071 - Wp Tabs Plugin

The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Wp Tabs

CVE-2023-0071

MEDIUM CVSS 5.4 2023-01-30
Threat Entry Updated 2025-03-27

CVE-2023-0033 - Before 1 Plugin

The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

PLUGIN Before 1

CVE-2023-0033

MEDIUM CVSS 5.4 2023-01-30
Scroll to top