Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14081-14100 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2022-3852 - Vr Calendar Sync Plugin

The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Vr Calendar Sync

CVE-2022-3852

HIGH CVSS 8.8 2022-11-03
Threat Entry Updated 2024-11-21

CVE-2022-3776 - Restaurant Menu – Food Ordering System – Table Reservation Plugin

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as forms_action, set_option, & chosen_options to name a few . This makes it possible for unauthenticated attackers to perform a variety of administrative actions like modifying forms, via a forged request granted they can trick a site administrator into performing an action such as clicking on a…

PLUGIN Restaurant Menu – Food Ordering System – Table Reservation

CVE-2022-3776

HIGH CVSS 8.8 2022-11-03
Threat Entry Updated 2024-11-21

CVE-2022-2696 - Menu Ordering Reservations Plugin

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal permissions to perform a wide variety of actions such as modifying the plugin's settings and modifying the ordering system preferences.

PLUGIN Menu Ordering Reservations

CVE-2022-2696

MEDIUM CVSS 6.3 2022-11-03
Threat Entry Updated 2025-05-06

CVE-2022-3254 - Wordpress Classifieds Plugin

The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection

PLUGIN Wordpress Classifieds

CVE-2022-3254

CRITICAL CVSS 9.8 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3357 - Smart Slider 3 Plugin

The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues when a user import (intentionally or not) a malicious file, and a suitable gadget chain is present on the site.

PLUGIN Smart Slider 3

CVE-2022-3357

HIGH CVSS 8.8 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3360 - Before 4 Plugin

The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to PHP Object Injection when a suitable gadget is present, leadint to remote code execution (RCE). To successfully exploit this vulnerability attackers must have knowledge of the site secrets, allowing them to generate a valid hash via the wp_hash() function.

PLUGIN Before 4

CVE-2022-3360

HIGH CVSS 8.1 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3380 - Before 0 Plugin

The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

PLUGIN Before 0

CVE-2022-3380

HIGH CVSS 7.2 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3374 - Ocean Extra Plugin

The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.

PLUGIN Ocean Extra

CVE-2022-3374

HIGH CVSS 7.2 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3366 - Publishpress Capabilities Plugin

The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.

PLUGIN Publishpress Capabilities

CVE-2022-3366

HIGH CVSS 7.2 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3334 - Easy Wp Smtp Plugin

The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

PLUGIN Easy Wp Smtp

CVE-2022-3334

HIGH CVSS 7.2 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3419 - Automatic User Roles Switcher Plugin

The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator

PLUGIN Automatic User Roles Switcher

CVE-2022-3419

MEDIUM CVSS 6.5 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3440 - Rock Convert Plugin

The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting

PLUGIN Rock Convert

CVE-2022-3440

MEDIUM CVSS 6.1 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3441 - Rock Convert Plugin

The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Rock Convert

CVE-2022-3441

MEDIUM CVSS 4.8 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3420 - Official Integration For Billingo Plugin

The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks.

PLUGIN Official Integration For Billingo

CVE-2022-3420

MEDIUM CVSS 4.8 2022-10-31
Scroll to top