Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14301-14320 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2022-2939 - Wp Cerber Security Plugin

The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to improper validation on the value supplied through the 'author' parameter found in the ~/cerber-load.php file. In vulnerable versions, the plugin only blocks requests if the value supplied is numeric, making it possible for attackers to supply additional non-numeric characters to bypass the protection. The non-numeric characters are stripped and the user requested is displayed. This can be used by unauthenticated attackers…

PLUGIN Wp Cerber Security

CVE-2022-2939

MEDIUM CVSS 5.3 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2945 - Ajax Load More Plugin

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Ajax Load More

CVE-2022-2945

MEDIUM CVSS 4.9 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2943 - Ajax Load More Plugin

The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for authenticated attackers, with administrative privileges, to download arbitrary files hosted on the server that may contain sensitive content, such as the wp-config.php file.

PLUGIN Ajax Load More

CVE-2022-2943

MEDIUM CVSS 4.9 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2542 - Ucontext For Clickbank Plugin

The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ucontext For Clickbank

CVE-2022-2542

HIGH CVSS 8.8 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2541 - Ucontext For Amazon Plugin

The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ucontext For Amazon

CVE-2022-2541

HIGH CVSS 8.8 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2540 - Link Optimizer Lite Plugin

The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 1.4.5. This is due to missing nonce validation on the admin_page function found in the ~/admin.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Link Optimizer Lite

CVE-2022-2540

HIGH CVSS 8.8 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2518 - Stockists Manager Plugin

The Stockists Manager for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2.1. This is due to missing nonce validation on the stockist_settings_main() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Stockists Manager

CVE-2022-2518

HIGH CVSS 8.8 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2633 - All In One Video Gallery Plugin

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users to download sensitive files hosted on the affected server and forge requests to the server.

PLUGIN All In One Video Gallery

CVE-2022-2633

HIGH CVSS 7.5 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2718 - Joomsport Sports League Results Management Plugin

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafields page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrative privileges, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Joomsport Sports League Results Management

CVE-2022-2718

HIGH CVSS 7.2 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2717 - Joomsport Sports League Results Management Plugin

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrative privileges, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Joomsport Sports League Results Management

CVE-2022-2717

HIGH CVSS 7.2 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2934 - Beaver Builder Plugin

The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image URL' value found in the Media block in versions up to, and including, 2.5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the Beaver Builder editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Beaver Builder

CVE-2022-2934

MEDIUM CVSS 6.4 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2716 - Beaver Builder Plugin

The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Editor' block in versions up to, and including, 2.5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the Beaver Builder editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Beaver Builder

CVE-2022-2716

MEDIUM CVSS 6.4 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2695 - Beaver Builder Plugin

The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter added to images via the media uploader in versions up to, and including, 2.5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the Beaver Builder editor and the ability to upload media files to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Beaver Builder

CVE-2022-2695

MEDIUM CVSS 6.4 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2517 - Beaver Builder Plugin

The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Caption - On Hover' value associated with images in versions up to, and including, 2.5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the Beaver Builder editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Beaver Builder

CVE-2022-2517

MEDIUM CVSS 6.4 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2516 - Visual Composer Website Builder Plugin

The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Visual Composer Website Builder

CVE-2022-2516

MEDIUM CVSS 6.4 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2515 - Simple Banner Plugin

The Simple Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `pro_version_activation_code` parameter in versions up to, and including, 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, including those without administrative capabilities when access is granted to those users, to inject arbitrary web scripts in page that will execute whenever a user role having access to "Simple Banner" accesses the plugin's settings.

PLUGIN Simple Banner

CVE-2022-2515

MEDIUM CVSS 6.4 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2473 - Wp Useronline Plugin

The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][text]' parameter in versions up to, and including, 2.87.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative capabilities and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The only affects multi-site installations and installations where unfiltered_html is disabled.

PLUGIN Wp Useronline

CVE-2022-2473

MEDIUM CVSS 5.5 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2436 - Download Manager Plugin

The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.

PLUGIN Download Manager

CVE-2022-2436

HIGH CVSS 8.8 2022-09-06
Scroll to top