Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2022-2189 - Wp Video Lightbox Plugin
The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
CVE-2022-2189
CVE-2022-2115 - Popup Anything Plugin
The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting
CVE-2022-2115
CVE-2022-2072 - Name Directory Plugin
The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well
CVE-2022-2072
CVE-2022-2071 - Name Directory Plugin
The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.
CVE-2022-2071
CVE-2022-0899 - Header Footer Code Manager Plugin
The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.
CVE-2022-0899
CVE-2022-2299 - Allow Svg Files Plugin
The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
CVE-2022-2299
CVE-2022-0594 - Related Posts Plugin
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.
CVE-2022-0594
CVE-2022-2341 - Simple Page Transition Plugin
The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2341
CVE-2022-2340 - W Dalil Plugin
The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2340
CVE-2022-2239 - Before 2 Plugin
The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-2239
CVE-2022-34839 - Wp Oauth2 Server Plugin
Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin
CVE-2022-34839
CVE-2022-34853 - Team Plugin
Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin
CVE-2022-34853
CVE-2022-30998 - Homepage Product Organizer For Woocommerce Plugin
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin
CVE-2022-30998
CVE-2022-33960 - Social Share Buttons Plugin
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin
CVE-2022-33960
CVE-2022-27235 - Social Share Buttons Plugin
Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin
CVE-2022-27235
CVE-2022-29495 - Popup Builder Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin
CVE-2022-29495
CVE-2022-33901 - Multisafepay Plugin For Woocommerce
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin
CVE-2022-33901
CVE-2022-34650 - Team Plugin
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin
CVE-2022-34650
CVE-2022-33191 - Testimonials Plugin
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Chinmoy Paul's Testimonials plugin
CVE-2022-33191
CVE-2022-34487 - Shortcode Addons Plugin
Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin
CVE-2022-34487
