Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14181-14200 of 16313 records
Threat Entry Updated 2025-05-21

CVE-2022-3119 - Oauth Client Single Sign On Plugin

The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address

PLUGIN Oauth Client Single Sign On

CVE-2022-3119

HIGH CVSS 7.5 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-3076 - Cm Download Manager Plugin

The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.

PLUGIN Cm Download Manager

CVE-2022-3076

HIGH CVSS 7.2 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2022-3135 - Seo Smart Links Plugin

The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Seo Smart Links

CVE-2022-3135

MEDIUM CVSS 4.8 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-3074 - Slider Hero Plugin

The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.

PLUGIN Slider Hero

CVE-2022-3074

MEDIUM CVSS 4.8 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-3098 - Login Block Ips Plugin

The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Login Block Ips

CVE-2022-3098

MEDIUM CVSS 4.3 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-2987 - Before 3 Plugin

The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers could set their own LDAP server to be used to authenticated users, therefore bypassing the current authentication

PLUGIN Before 3

CVE-2022-2987

HIGH CVSS 7.5 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2022-2903 - Ninja Forms Contact Form Plugin

The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

PLUGIN Ninja Forms Contact Form

CVE-2022-2903

HIGH CVSS 7.2 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2022-2352 - Email Log Plugin

The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.

PLUGIN Email Log

CVE-2022-2352

HIGH CVSS 7.2 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-3062 - Simple File List Plugin

The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

PLUGIN Simple File List

CVE-2022-3062

MEDIUM CVSS 6.1 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2022-2404 - Wp Popup Builder Plugin

The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Wp Popup Builder

CVE-2022-2404

MEDIUM CVSS 6.1 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-3025 - Altcoin Faucet Plugin

The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

PLUGIN Altcoin Faucet

CVE-2022-3025

MEDIUM CVSS 5.4 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-3024 - Simple Bitcoin Faucets Plugin

The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

PLUGIN Simple Bitcoin Faucets

CVE-2022-3024

MEDIUM CVSS 5.4 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2022-1755 - Before 2 Plugin

The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2022-1755

MEDIUM CVSS 5.4 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2022-1613 - Restricted Site Access Plugin

The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.

PLUGIN Restricted Site Access

CVE-2022-1613

MEDIUM CVSS 5.3 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2022-2926 - Download Manager Plugin

The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory

PLUGIN Download Manager

CVE-2022-2926

MEDIUM CVSS 4.9 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-3070 - Generate Pdf Plugin

The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Generate Pdf

CVE-2022-3070

MEDIUM CVSS 4.8 2022-09-26
Threat Entry Updated 2025-05-22

CVE-2022-3069 - Before 3 Plugin

The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2022-3069

MEDIUM CVSS 4.8 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2022-2405 - Wp Popup Builder Plugin

The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup

PLUGIN Wp Popup Builder

CVE-2022-2405

MEDIUM CVSS 4.3 2022-09-26
Threat Entry Updated 2025-05-21

CVE-2021-24890 - Scripts Organizer Plugin

The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file

PLUGIN Scripts Organizer

CVE-2021-24890

HIGH CVSS 8.8 2022-09-26
Scroll to top