Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14101-14120 of 16313 records
Threat Entry Updated 2025-05-06

CVE-2022-3408 - Wp Word Count Plugin

The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Wp Word Count

CVE-2022-3408

MEDIUM CVSS 4.8 2022-10-31
Threat Entry Updated 2025-05-08

CVE-2022-2627 - Newspaper Plugin

The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting.

PLUGIN Newspaper

CVE-2022-2627

MEDIUM CVSS 6.1 2022-10-31
Threat Entry Updated 2025-05-07

CVE-2022-2190 - Gallery Plugin For

The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

PLUGIN Gallery Plugin For

CVE-2022-2190

MEDIUM CVSS 6.1 2022-10-31
Threat Entry Updated 2025-05-07

CVE-2022-2167 - Newspaper Plugin

The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting

PLUGIN Newspaper

CVE-2022-2167

MEDIUM CVSS 6.1 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3096 - Wp Total Hacks Plugin

The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.

PLUGIN Wp Total Hacks

CVE-2022-3096

MEDIUM CVSS 5.4 2022-10-31
Threat Entry Updated 2025-05-06

CVE-2022-3237 - Wp Contact Slider Plugin

The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Wp Contact Slider

CVE-2022-3237

MEDIUM CVSS 4.8 2022-10-31
Threat Entry Updated 2025-05-05

CVE-2022-3708 - Web Stories Plugin

The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This makes it possible for authenticated users to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Web Stories

CVE-2022-3708

CRITICAL CVSS 9.6 2022-10-28
Threat Entry Updated 2024-11-21

CVE-2022-3401 - Bricks Plugin

The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocks in website content in versions 1.2 to 1.5.3. This, combined with the missing authorization vulnerability (CVE-2022-3400), makes it possible for authenticated attackers with minimal permissions, such as a subscriber, can edit any page, post, or template on the vulnerable WordPress website and inject a code execution block that can be used to achieve remote code execution.

PLUGIN Bricks

CVE-2022-3401

HIGH CVSS 8.8 2022-10-28
Threat Entry Updated 2024-11-21

CVE-2022-3402 - Log Http Requests Plugin

The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers who can trick a site's administrator into performing an action like clicking on a link, or an authenticated user with access to a page that sends a request using user-supplied data via the server, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Log Http Requests

CVE-2022-3402

MEDIUM CVSS 6.1 2022-10-28
Threat Entry Updated 2024-11-21

CVE-2022-3400 - Bricks Plugin

The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website.

PLUGIN Bricks

CVE-2022-3400

MEDIUM CVSS 6.5 2022-10-28
Threat Entry Updated 2024-11-21

CVE-2022-2864 - Demon Image Annotation Plugin

The demon image annotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7. This is due to missing nonce validation in the ~/includes/settings.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Demon Image Annotation

CVE-2022-2864

HIGH CVSS 8.8 2022-10-28
Threat Entry Updated 2025-05-07

CVE-2022-3395 - Wp All Export Pro Plugin

The WP All Export Pro WordPress plugin before 1.7.9 uses the contents of the cc_sql POST parameter directly as a database query, allowing users which has been given permission to run exports to execute arbitrary SQL statements, leading to a SQL Injection vulnerability. By default only users with the Administrator role can perform exports, but this can be delegated to lower privileged users as well.

PLUGIN Wp All Export Pro

CVE-2022-3395

HIGH CVSS 8.8 2022-10-25
Threat Entry Updated 2025-05-07

CVE-2022-3394 - Wp All Export Pro Plugin

The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only administrators can run exports, but the privilege can be delegated to lower privileged users.

PLUGIN Wp All Export Pro

CVE-2022-3394

HIGH CVSS 7.2 2022-10-25
Threat Entry Updated 2025-05-09

CVE-2022-3335 - Kadence Woocommerce Email Designer Plugin

The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

PLUGIN Kadence Woocommerce Email Designer

CVE-2022-3335

HIGH CVSS 7.2 2022-10-25
Scroll to top