Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14061-14080 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2023-0403 - Social Warfare Plugin

The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.0. This is due to missing or incorrect nonce validation on several AJAX actions. This makes it possible for unauthenticated attackers to delete post meta information and reset network access tokens, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Social Warfare

CVE-2023-0403

MEDIUM CVSS 5.4 2023-01-19
Threat Entry Updated 2024-11-21

CVE-2023-0402 - Social Warfare Plugin

The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete post meta information and reset network access tokens.

PLUGIN Social Warfare

CVE-2023-0402

MEDIUM CVSS 5.4 2023-01-19
Threat Entry Updated 2024-11-21

CVE-2023-0385 - Custom 404 Pro Plugin

The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on the custom_404_pro_admin_init function. This makes it possible for unauthenticated attackers to delete logs, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Custom 404 Pro

CVE-2023-0385

MEDIUM CVSS 4.3 2023-01-18
Threat Entry Updated 2024-11-21

CVE-2023-0295 - Launchpad Coming Soon Maintenance Mode Plugin

The Launchpad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Launchpad Coming Soon Maintenance Mode

CVE-2023-0295

MEDIUM CVSS 5.5 2023-01-13
Threat Entry Updated 2024-11-21

CVE-2023-0294 - Mediamatic Plugin

The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.1. This is due to missing or incorrect nonce validation on its AJAX actions function. This makes it possible for unauthenticated attackers to change image categories used by the plugin, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Mediamatic

CVE-2023-0294

HIGH CVSS 8.8 2023-01-13
Threat Entry Updated 2024-11-21

CVE-2023-0293 - Mediamatic Plugin

The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change image categories, which it uses to arrange them in folder views.

PLUGIN Mediamatic

CVE-2023-0293

MEDIUM CVSS 4.3 2023-01-13
Threat Entry Updated 2024-11-21

CVE-2023-0254 - Simple Membership Wp User Import Plugin

The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Simple Membership Wp User Import

CVE-2023-0254

HIGH CVSS 7.2 2023-01-12
Threat Entry Updated 2024-11-21

CVE-2023-0162 - Cpo Companion Plugin

The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type settings parameters in versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cpo Companion

CVE-2023-0162

MEDIUM CVSS 5.5 2023-01-10
Threat Entry Updated 2024-11-21

CVE-2023-0088 - Swifty Page Manager Plugin

The Swifty Page Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on several AJAX actions handling page creation and deletion among other things. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Swifty Page Manager

CVE-2023-0088

HIGH CVSS 8.8 2023-01-05
Threat Entry Updated 2024-11-21

CVE-2023-0087 - Swifty Page Manager Plugin

The Swifty Page Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘spm_plugin_options_page_tree_max_width’ parameter in versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Swifty Page Manager

CVE-2023-0087

MEDIUM CVSS 5.5 2023-01-05
Threat Entry Updated 2024-11-21

CVE-2023-0086 - Jetwidgets For Elementor Plugin

The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.12. This is due to missing nonce validation on the save() function. This makes it possible for unauthenticated attackers to to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This can be used to enable SVG uploads that could make Cross-Site Scripting possible.

PLUGIN Jetwidgets For Elementor

CVE-2023-0086

MEDIUM CVSS 5.4 2023-01-05
Threat Entry Updated 2025-04-07

CVE-2023-22622 - Cron Plugin

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

PLUGIN Cron

CVE-2023-22622

MEDIUM CVSS 5.3 2023-01-05
Threat Entry Updated 2024-11-21

CVE-2023-0038 - Survey Maker Plugin

The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts when submitting quizzes that will execute whenever a user accesses the submissions page.

PLUGIN Survey Maker

CVE-2023-0038

HIGH CVSS 7.2 2023-01-03
Threat Entry Updated 2025-04-14

CVE-2021-24942 - Menu Item Visibility Control Plugin

The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened environment.

PLUGIN Menu Item Visibility Control

CVE-2021-24942

HIGH CVSS 7.2 2022-12-26
Threat Entry Updated 2025-10-29

CVE-2021-31693 - Photo Gallery Plugin

The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-46889. NOTE: VMware information, previously connected to this CVE ID because of a typo, is at CVE-2022-31693.

PLUGIN Photo Gallery

CVE-2021-31693

MEDIUM CVSS 6.1 2022-11-29
Threat Entry Updated 2025-04-25

CVE-2021-25059 - Before 2 Plugin

The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.

PLUGIN Before 2

CVE-2021-25059

MEDIUM CVSS 4.3 2022-11-28
Threat Entry Updated 2025-04-30

CVE-2021-24649 - Wp User Frontend Plugin

The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary file access issue for example, or if the blog is using the default keys) to create an account with any role they want, such as admin

PLUGIN Wp User Frontend

CVE-2021-24649

CRITICAL CVSS 9.8 2022-11-21
Scroll to top