Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2022-3282 - Drag And Drop Multiple File Upload Plugin
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.
CVE-2022-3282
CVE-2022-3151 - Wp Custom Cursors Plugin
The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.
CVE-2022-3151
CVE-2022-3126 - Frontend File Manager Plugin
The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf
CVE-2022-3126
CVE-2022-3244 - Before 6 Plugin
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce
CVE-2022-3244
CVE-2022-2834 - Before 4 Plugin
The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings
CVE-2022-2834
CVE-2022-2574 - Meks Easy Social Share Plugin
The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2574
CVE-2022-2563 - Before 2 Plugin
The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2563
CVE-2022-41623 - Dropshipping And Fulfillment For Aliexpress And Woocommerce Plugin
Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin
CVE-2022-41623
CVE-2022-38086 - Shortcodes Ultimate Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Shortcodes Ultimate plugin
CVE-2022-38086
CVE-2021-36915 - Profile Builder Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin
CVE-2021-36915
CVE-2021-36913 - Redirection For Contact Form 7 Plugin
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin
CVE-2021-36913
CVE-2021-36899 - Asset CleanUp: Page Speed Booster (WordPress plugin)
Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Booster plugin
CVE-2021-36899
CVE-2022-33978 - Fontmeister Plugin
Reflected Cross-Site Scripting (XSS) vulnerability FontMeister plugin
CVE-2022-33978
CVE-2022-3154 - Woo Billingo Plus Plugin
The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin's license
CVE-2022-3154
CVE-2022-3208 - Simple File List Plugin
The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make a logged in admin create new page and change it's content via a CSRF attack.
CVE-2022-3208
CVE-2022-3209 - Soledad Plugin
The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.
CVE-2022-3209
CVE-2022-3137 - Before 1 Plugin
The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file
CVE-2022-3137
CVE-2022-3220 - Advanced Comment Form Plugin
The Advanced Comment Form WordPress plugin before 1.2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-3220
CVE-2022-3207 - Simple File List Plugin
The Simple File List WordPress plugin before 4.4.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-3207
CVE-2022-3136 - Social Rocket Plugin
The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-3136
