Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14601-14620 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-2099 - Before 6 Plugin

The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

PLUGIN Before 6

CVE-2022-2099

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2144 - Jquery Validation For Contact Form 7 Plugin

The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack

PLUGIN Jquery Validation For Contact Form 7

CVE-2022-2144

MEDIUM CVSS 4.3 2022-07-17
Threat Entry Updated 2026-01-23

CVE-2022-1952 - Restaurant And Car Rental Plugin

The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.

PLUGIN Restaurant And Car Rental

CVE-2022-1952

CRITICAL CVSS 9.8 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-2091 - Cache Images Plugin

The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via a CSRF attack.

PLUGIN Cache Images

CVE-2022-2091

MEDIUM CVSS 6.5 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-2092 - Packing Slips Plugin

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks.

PLUGIN Packing Slips

CVE-2022-2092

MEDIUM CVSS 6.1 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-2093 - Wp Duplicate Page Plugin

The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Wp Duplicate Page

CVE-2022-2093

MEDIUM CVSS 4.8 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-2089 - Bold Page Builder Plugin

The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Bold Page Builder

CVE-2022-2089

MEDIUM CVSS 4.8 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-2050 - Before 2 Plugin

The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when unfiltered_html is disallowed

PLUGIN Before 2

CVE-2022-2050

MEDIUM CVSS 4.8 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-2123 - Wp Opt In Plugin

The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used for sending spam emails.

PLUGIN Wp Opt In

CVE-2022-2123

MEDIUM CVSS 4.3 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1957 - Comment License Plugin

The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Comment License

CVE-2022-1957

MEDIUM CVSS 4.3 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1956 - Shortcut Macros Plugin

The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its settings, which could allow any authenticated users, such as subscriber, to update them.

PLUGIN Shortcut Macros

CVE-2022-1956

MEDIUM CVSS 4.3 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1057 - Pricing Deals For Woocommerce Plugin

The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

PLUGIN Pricing Deals For Woocommerce

CVE-2022-1057

CRITICAL CVSS 9.8 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1732 - Rename Wp Login Plugin

The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login URL, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Rename Wp Login

CVE-2022-1732

MEDIUM CVSS 6.5 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1599 - Admin Management Xtended Plugin

The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.

PLUGIN Admin Management Xtended

CVE-2022-1599

MEDIUM CVSS 6.5 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1576 - Before 2 Plugin

The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack

PLUGIN Before 2

CVE-2022-1576

MEDIUM CVSS 6.5 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1951 - Core Plugin For Kitestudio

The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputting them back in a response of an AJAX action, available to both unauthenticated and authenticated users when a premium theme from the vendor is active, leading to a Reflected Cross-Site Scripting.

PLUGIN Core Plugin For Kitestudio

CVE-2022-1951

MEDIUM CVSS 6.1 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1937 - Awin Data Feed Plugin

The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

PLUGIN Awin Data Feed

CVE-2022-1937

MEDIUM CVSS 6.1 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1474 - Wp Event Manager Plugin

The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Wp Event Manager

CVE-2022-1474

MEDIUM CVSS 6.1 2022-07-11
Scroll to top