Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2022-33198 - Accordions Plugin
Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin
CVE-2022-33198
CVE-2022-28700 - Givewp Plugin
Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin
CVE-2022-28700
CVE-2022-31475 - Givewp Plugin
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin
CVE-2022-31475
CVE-2022-30536 - Wp Maintenance Plugin
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin
CVE-2022-30536
CVE-2022-30337 - Wp Meta Seo Plugin
Cross-Site Request Forgery (CSRF) vulnerability in JoomUnited WP Meta SEO plugin
CVE-2022-30337
CVE-2022-28666 - Custom Product Tabs For Woocommerce Plugin
Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin
CVE-2022-28666
CVE-2022-32289 - Popup Builder Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin
CVE-2022-32289
CVE-2022-29454 - Better Messages Plugin
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin
CVE-2022-29454
CVE-2021-36849 - Social Media Share Buttons Plugin
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons plugin
CVE-2021-36849
CVE-2022-2437 - Feed Them Social Plugin
The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
CVE-2022-2437
CVE-2022-2444 - Visualizer Plugin
The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data' parameter in versions up to, and including 3.7.9. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the…
CVE-2022-2444
CVE-2022-2443 - Freemind Wp Browser Plugin
The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2. This is due to missing nonce protection on the FreemindOptions() function found in the ~/freemind-wp-browser.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site's administrator into performing an action such as clicking on a link.
CVE-2022-2443
CVE-2022-2435 - Anymind Widget Plugin
The AnyMind Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1. This is due to missing nonce protection on the createDOMStructure() function found in the ~/anymind-widget-id.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site’s administrator into performing an action such as clicking on a link.
CVE-2022-2435
CVE-2022-2224 - Gallery For Social Photo Plugin
The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_duplicate_feed. This make it possible for unauthenticated attackers to duplicate existing posts or pages granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2022-2224
CVE-2022-2223 - Image Slider Plugin
The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 due to failure to properly check for the existence of a nonce in the function ewic_duplicate_slider. This make it possible for unauthenticated attackers to duplicate existing posts or pages granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2022-2223
CVE-2022-2117 - Givewp Plugin
The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled. This functionality has been completely removed in version 2.20.2.
CVE-2022-2117
CVE-2022-2039 - Free Live Chat Support Plugin
The Free Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.11. This is due to missing nonce protection on the livesupporti_settings() function found in the ~/livesupporti.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site's administrator into performing an action such as clicking on a link.
CVE-2022-2039
CVE-2022-2001 - Dx Share Selection Plugin
The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing nonce protection on the dxss_admin_page() function found in the ~/dx-share-selection.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site's administrator into performing an action such as clicking on a link.
CVE-2022-2001
CVE-2022-1912 - Button Widget Smartsoft Plugin
The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation on the smartsoftbutton_settings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2022-1912
CVE-2022-2108 - Buddypress Group Reviews Plugin
The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.
CVE-2022-2108
