Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14401-14420 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2022-2383 - Feed Them Social Plugin

The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Feed Them Social

CVE-2022-2383

MEDIUM CVSS 6.1 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2375 - Wp Sticky Button Plugin

The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues

PLUGIN Wp Sticky Button

CVE-2022-2375

MEDIUM CVSS 5.4 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2312 - Student Result Or Employee Database Plugin

The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site scripting

PLUGIN Student Result Or Employee Database

CVE-2022-2312

MEDIUM CVSS 5.4 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2361 - Wp Social Chat Plugin

The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks.

PLUGIN Wp Social Chat

CVE-2022-2361

MEDIUM CVSS 4.8 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2389 - Marketing Automation By Autonami Plugin

The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to create automations

PLUGIN Marketing Automation By Autonami

CVE-2022-2389

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2382 - Product Slider For Woocommerce Plugin

The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.

PLUGIN Product Slider For Woocommerce

CVE-2022-2382

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2377 - Before 7 Plugin

The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog

PLUGIN Before 7

CVE-2022-2377

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2276 - Wp Edit Menu Plugin

The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow unauthenticated attackers to delete arbitrary posts/pages from the blog

PLUGIN Wp Edit Menu

CVE-2022-2276

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2275 - Wp Edit Menu Plugin

The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make a logged in admin delete arbitrary posts/pages from the blog via a CSRF attack

PLUGIN Wp Edit Menu

CVE-2022-2275

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2198 - Wpqa Builder Plugin

The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read other users private message using the message id, which can easily be brute forced.

PLUGIN Wpqa Builder

CVE-2022-2198

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2172 - Before 3 Plugin

The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logged in admin change settings via a CSRF attack.

PLUGIN Before 3

CVE-2022-2172

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-1932 - Rezgo Online Booking Plugin

The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting, which can be exploited either via a LFI in an AJAX action, or direct call to the affected file

PLUGIN Rezgo Online Booking

CVE-2022-1932

MEDIUM CVSS 6.1 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-1322 - Coming Soon Plugin

The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Coming Soon

CVE-2022-1322

MEDIUM CVSS 4.8 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-0446 - Simple Banner Plugin

The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Simple Banner

CVE-2022-0446

MEDIUM CVSS 4.8 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-1251 - Ask Me Plugin

The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.

PLUGIN Ask Me

CVE-2022-1251

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2021-24910 - Transposh Wordpress Translation Plugin

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

PLUGIN Transposh Wordpress Translation

CVE-2021-24910

MEDIUM CVSS 6.1 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2021-24912 - Transposh Wordpress Translation Plugin

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sanitisation in the tk0 parameter, this could lead to a Stored Cross-Site Scripting issue which will be executed in the context of a logged in admin

PLUGIN Transposh Wordpress Translation

CVE-2021-24912

MEDIUM CVSS 5.4 2022-08-22
Scroll to top