Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2022-37335 - Wha Wordsearch Plugin
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in WHA's Word Search Puzzles game plugin
CVE-2022-37335
CVE-2022-38058 - Wp Shamsi Plugin
Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin
CVE-2022-38058
CVE-2022-37405 - Better Font Awesome Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Mickey Kay's Better Font Awesome plugin
CVE-2022-37405
CVE-2022-37407 - Photoblocks Grid Gallery Plugin
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin
CVE-2022-37407
CVE-2022-36376 - Seo Plugin
Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin
CVE-2022-36376
CVE-2022-36793 - Wp Shop Original Plugin
Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin
CVE-2022-36793
CVE-2022-35277 - Getresponse Integration Plugin
Cross-Site Request Forgery (CSRF) vulnerability in GetResponse plugin
CVE-2022-35277
CVE-2022-36356 - Culture Object Plugin
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy / Thirty8 Digital Culture Object plugin
CVE-2022-36356
CVE-2022-35725 - Wp Forecast Plugin
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hans Matzen's wp-forecast plugin
CVE-2022-35725
CVE-2022-35275 - Woo Order Export Lite Plugin
Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For WooCommerce plugin
CVE-2022-35275
CVE-2022-36422 - Wp Postratings Plugin
Rating increase/decrease via race condition in Lester 'GaMerZ' Chan WP-PostRatings plugin
CVE-2022-36422
CVE-2022-37344 - Accommodation System Plugin
Missing Access Control vulnerability in PHP Crafts Accommodation System plugin
CVE-2022-37344
CVE-2022-36387 - About Me Plugin
Broken Access Control vulnerability in Alessio Caiazza's About Me plugin
CVE-2022-36387
CVE-2022-36427 - About Rentals Plugin
Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin
CVE-2022-36427
CVE-2022-3026 - Wp Users Exporter Plugin
The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via the 'Export Users' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into profile information like First Names that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
CVE-2022-3026
CVE-2022-34867 - Wp Libre Form Plugin
Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin
CVE-2022-34867
CVE-2022-2936 - Image Hover Effects Ultimate Plugin
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers, however, if a site admin makes the plugin's features available to lower privileged…
CVE-2022-2936
CVE-2022-2935 - Image Hover Effects Ultimate Plugin
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image URL value that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers, however, if a site admin makes the plugin's features available to…
CVE-2022-2935
CVE-2022-2941 - Wp Useronline Plugin
The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. This is due to the fact that all fields in the "Naming Conventions" section do not properly sanitize user input, nor escape it on output. This makes it possible for authenticated attackers, with administrative privileges, to inject JavaScript code into the setting that will execute whenever a user accesses the injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
CVE-2022-2941
CVE-2022-36425 - Beaver Builder Lite Version Plugin
Broken Access Control vulnerability in Beaver Builder plugin
CVE-2022-36425
