Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14341-14360 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2022-2657 - Multivendor Marketplace Solution For Woocommerce Plugin

The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by WPScan when verifying the issue) for example. Other unauthenticated attacks are also possible, either directly or via CSRF

PLUGIN Multivendor Marketplace Solution For Woocommerce

CVE-2022-2657

MEDIUM CVSS 4.3 2022-09-05
Threat Entry Updated 2024-11-21

CVE-2022-2559 - Fluent Support Plugin

The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users

PLUGIN Fluent Support

CVE-2022-2559

HIGH CVSS 7.2 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2261 - Before 3 Plugin

The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.

PLUGIN Before 3

CVE-2022-2261

HIGH CVSS 7.2 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2638 - Export All Urls Plugin

The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server

PLUGIN Export All Urls

CVE-2022-2638

MEDIUM CVSS 6.5 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2538 - Security Enhancer Plugin

The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an attribute of a backend page, leading to a Reflected Cross-Site Scripting

PLUGIN Security Enhancer

CVE-2022-2538

MEDIUM CVSS 6.1 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2537 - Packing Slips Plugin

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.

PLUGIN Packing Slips

CVE-2022-2537

MEDIUM CVSS 6.1 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2373 - Simply Schedule Appointments Plugin

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address

PLUGIN Simply Schedule Appointments

CVE-2022-2373

MEDIUM CVSS 5.3 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2034 - Before 4 Plugin

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers

PLUGIN Before 4

CVE-2022-2034

MEDIUM CVSS 5.3 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2374 - Simply Schedule Appointments Plugin

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Simply Schedule Appointments

CVE-2022-2374

MEDIUM CVSS 4.8 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2267 - Mailchimp For Woocommerce Plugin

The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

PLUGIN Mailchimp For Woocommerce

CVE-2022-2267

MEDIUM CVSS 4.3 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2080 - Sensei Lms Plugin

The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the teacher and student

PLUGIN Sensei Lms

CVE-2022-2080

MEDIUM CVSS 4.3 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-2556 - Mailchimp For Woocommerce Plugin

The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

PLUGIN Mailchimp For Woocommerce

CVE-2022-2556

LOW CVSS 2.7 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-1123 - Before 3 Plugin

The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitize some parameters before inserting them into SQL queries. As a result, high privilege users could perform SQL injection attacks.

PLUGIN Before 3

CVE-2022-1123

HIGH CVSS 7.2 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-1663 - Stop Spam Comments Plugin

The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment section, allowing threat authors to easily collect the value and add it to the request.

PLUGIN Stop Spam Comments

CVE-2022-1663

MEDIUM CVSS 6.5 2022-08-29
Scroll to top