Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2022-37342 - Add Actions And Filters Plugin
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability Add Shortcodes Actions And Filters plugin
CVE-2022-37342
CVE-2022-37328 - Timeline Awesome Plugin
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin
CVE-2022-37328
CVE-2022-40213 - Gs Testimonial Plugin
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin
CVE-2022-40213
CVE-2022-2937 - Image Hover Effects Ultimate Plugin
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Description values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers, however, if a site admin makes the plugin's features available to…
CVE-2022-2937
CVE-2022-38095 - Advanced Dynamic Pricing For Woocommerce Plugin
Cross-Site Request Forgery (CSRF) vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce plugin
CVE-2022-38095
CVE-2022-37330 - Wha Crossword Plugin
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA Crossword plugin
CVE-2022-37330
CVE-2022-36798 - Mega Addons For Visual Composer Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Topdigitaltrends Mega Addons For WPBakery Page Builder plugin
CVE-2022-36798
CVE-2022-3144 - Wordfence Plugin
The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to inject malicious web scripts into the setting that executes whenever a user accesses a page displaying the affected setting on sites running a vulnerable version.
CVE-2022-3144
CVE-2022-37339 - Meet My Team Plugin
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin
CVE-2022-37339
CVE-2022-37338 - Blossom Recipe Maker Plugin
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin
CVE-2022-37338
CVE-2022-38703 - Maxbuttons Plugin
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin
CVE-2022-38703
CVE-2022-40217 - Wpide Plugin
Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin
CVE-2022-40217
CVE-2022-36386 - Wp All Import Plugin
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin
CVE-2022-36386
CVE-2022-38073 - Awesome Support Plugin
Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin
CVE-2022-38073
CVE-2022-36383 - Wha Wordsearch Plugin
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Word Search Puzzles game plugin
CVE-2022-36383
CVE-2022-36365 - WHA Crossword (WordPress plugin)
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Crossword plugin
CVE-2022-36365
CVE-2022-36390 - Calendar Event Plugin
Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin
CVE-2022-36390
CVE-2022-40219 - Favicon Switcher Plugin
Cross-Site Request Forgery (CSRF) vulnerability in SedLex FavIcon Switcher plugin
CVE-2022-40219
CVE-2022-2840 - Zephyr Project Manager Plugin
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
CVE-2022-2840
CVE-2022-3142 - Before 7 Plugin
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.
CVE-2022-3142
