Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2022-2669 - Wp Taxonomy Import Plugin
The WP Taxonomy Import WordPress plugin through 1.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-2669
CVE-2022-2655 - Classified Listing Pro Plugin
The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2022-2655
CVE-2022-2654 - Classified Listing Plugin
The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting
CVE-2022-2654
CVE-2022-2737 - Before 2 Plugin
The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2737
CVE-2022-2635 - Before 3 Plugin
The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2635
CVE-2022-2575 - Wbw Currency Switcher For Woocommerce Plugin
The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2575
CVE-2022-2351 - Before 2 Plugin
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.
CVE-2022-2351
CVE-2022-38139 - Rd Station Plugin
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in RD Station plugin
CVE-2022-38139
CVE-2022-38135 - Photospace Plugin
Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin
CVE-2022-38135
CVE-2022-40191 - Mega Forms Plugin
Authenticated (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Ali Khallad's Contact Form By Mega Forms plugin
CVE-2022-40191
CVE-2022-38144 - Wpforo Plugin
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin
CVE-2022-38144
CVE-2022-38067 - Calendar Event Plugin
Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin
CVE-2022-38067
CVE-2022-38093 - All In One Seo Plugin
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin
CVE-2022-38093
CVE-2022-38070 - Pop Up Pop Up Plugin
Privilege Escalation (subscriber+) vulnerability in Pop-up plugin
CVE-2022-38070
CVE-2022-38068 - Export Post Info Plugin
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apasionados Export Post Info plugin
CVE-2022-38068
CVE-2022-38059 - Access Code Feeder Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Alexey Trofimov's Access Code Feeder plugin
CVE-2022-38059
CVE-2022-37411 - Captcha Code Authentication Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza's Captcha Code plugin
CVE-2022-37411
CVE-2022-37412 - Better Delete Revision Plugin
Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Galerio & Urda's Better Delete Revision plugin
CVE-2022-37412
CVE-2022-37404 - Add2fav Plugin
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christian Salazar's add2fav plugin
CVE-2022-37404
CVE-2022-37403 - Add User Role Plugin
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nikhil Vaghela's Add User Role plugin
CVE-2022-37403
