Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14321-14340 of 16313 records
Threat Entry Updated 2025-05-05

CVE-2022-2434 - String Locator Plugin

The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to, and including 2.5.0. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an action such as clicking on a link, that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in…

PLUGIN String Locator

CVE-2022-2434

HIGH CVSS 8.8 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2432 - Ecwid Ecommerce Shopping Cart Plugin

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ecwid Ecommerce Shopping Cart

CVE-2022-2432

HIGH CVSS 8.8 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2233 - Banner Cycler Plugin

The Banner Cycler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing nonce protection on the pabc_admin_slides_postback() function found in the ~/admin/admin.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site’s administrator into performing an action such as clicking on a link

PLUGIN Banner Cycler

CVE-2022-2233

HIGH CVSS 8.8 2022-09-06
Threat Entry Updated 2025-03-21

CVE-2022-2431 - Download Manager Plugin

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it possible for contributor level users and above to supply an arbitrary file path via the 'file[files]' parameter when creating a download post and once the user deletes the post the supplied arbitrary file will be deleted. This can be used by attackers to…

PLUGIN Download Manager

CVE-2022-2431

HIGH CVSS 8.1 2022-09-06
Threat Entry Updated 2025-08-21

CVE-2022-2433 - Ajax Load More Plugin

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an action such as clicking on a link, that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that…

PLUGIN Ajax Load More

CVE-2022-2433

HIGH CVSS 7.5 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2442 - Migration Backup Staging Plugin

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.

PLUGIN Migration Backup Staging

CVE-2022-2442

HIGH CVSS 7.2 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2438 - Broken Link Checker Plugin

The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 1.11.16. This makes it possible for authenticated attackers with administrative privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.

PLUGIN Broken Link Checker

CVE-2022-2438

HIGH CVSS 7.2 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2429 - Ultimate Sms Notifications For Woocommerce Plugin

The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First Name that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

PLUGIN Ultimate Sms Notifications For Woocommerce

CVE-2022-2429

MEDIUM CVSS 6.5 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2430 - Visual Composer Website Builder Plugin

The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Visual Composer Website Builder

CVE-2022-2430

MEDIUM CVSS 6.4 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2462 - Transposh Translation Filter For Wordpress Plugin

The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.8.1. This is due to insufficient permissions checking on the 'tp_history' AJAX action and insufficient restriction on the data returned in the response. This makes it possible for unauthenticated users to exfiltrate usernames of individuals who have translated text.

PLUGIN Transposh Translation Filter For Wordpress

CVE-2022-2462

MEDIUM CVSS 5.3 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2461 - Transposh Wordpress Translation Plugin

The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.8.1. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.

PLUGIN Transposh Wordpress Translation

CVE-2022-2461

MEDIUM CVSS 5.3 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-1628 - Simple Seo Plugin

The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and including 1.7.91, due to insufficient sanitization or escaping on the SEO social and standard title parameters. This can be exploited by authenticated users with Contributor and above permissions to inject arbitrary web scripts into posts/pages that execute whenever an administrator access the page.

PLUGIN Simple Seo

CVE-2022-1628

MEDIUM CVSS 6.4 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2083 - Simple Sign On Plugin

The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site.

PLUGIN Simple Sign On

CVE-2022-2083

HIGH CVSS 7.5 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2565 - Before 4 Plugin

The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against admins

PLUGIN Before 4

CVE-2022-2565

HIGH CVSS 7.2 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2543 - Before 2 Plugin

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts

PLUGIN Before 2

CVE-2022-2543

MEDIUM CVSS 6.1 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2775 - Fast Flow Plugin

The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Fast Flow

CVE-2022-2775

MEDIUM CVSS 5.5 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2597 - Post Grid Plugin

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts

PLUGIN Post Grid

CVE-2022-2597

MEDIUM CVSS 5.4 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2376 - Before 7 Plugin

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

PLUGIN Before 7

CVE-2022-2376

MEDIUM CVSS 5.3 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2271 - Wp Database Backup Plugin

The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wp Database Backup

CVE-2022-2271

MEDIUM CVSS 4.8 2022-09-05
Scroll to top