Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14661-14680 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1653 - Social Share Buttons By Supsystic Plugin

The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks.

PLUGIN Social Share Buttons By Supsystic

CVE-2022-1653

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1627 - My Private Site Plugin

The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN My Private Site

CVE-2022-1627

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1625 - New User Approve Plugin

The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided restrictions) and to change plugin settings by tricking admin users into visiting specially crafted websites.

PLUGIN New User Approve

CVE-2022-1625

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1573 - Html2wp Plugin

The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them

PLUGIN Html2wp

CVE-2022-1573

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1326 - Form Contact Form Plugin

The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Form Contact Form

CVE-2022-1326

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1321 - S Google Authenticator Plugin

The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

PLUGIN S Google Authenticator

CVE-2022-1321

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1113 - Flower Delivery Plugin

The Flower Delivery by Florist One WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setups)

PLUGIN Flower Delivery

CVE-2022-1113

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1095 - No External Links Plugin

The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN No External Links

CVE-2022-1095

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1029 - Limit Login Attempts Plugin

The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

PLUGIN Limit Login Attempts

CVE-2022-1029

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1028 - Wordpress Security Plugin

The WordPress Security Firewall, Malware Scanner, Secure Login and Backup plugin before 4.2.1 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

PLUGIN Wordpress Security

CVE-2022-1028

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1010 - Before 1 Plugin

The Login using WordPress Users ( WP as SAML IDP ) WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2022-1010

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-0875 - Google Authenticator Plugin

The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

PLUGIN Google Authenticator

CVE-2022-0875

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-0444 - Restore And Migrate Wordpress Sites With The Xcloner Plugin

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.

PLUGIN Restore And Migrate Wordpress Sites With The Xcloner

CVE-2022-0444

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1905 - Events Made Easy Plugin

The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN Events Made Easy

CVE-2022-1905

CRITICAL CVSS 9.8 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1939 - Allow Svg Files Plugin

The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they are not allowed to

PLUGIN Allow Svg Files

CVE-2022-1939

HIGH CVSS 7.2 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1832 - Capa Protect Plugin

The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable the applied protection.

PLUGIN Capa Protect

CVE-2022-1832

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1831 - Wplite Plugin

The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Wplite

CVE-2022-1831

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1830 - Amazon Einzeltitellinks Plugin

The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

PLUGIN Amazon Einzeltitellinks

CVE-2022-1830

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1829 - Inline Google Maps Plugin

The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

PLUGIN Inline Google Maps

CVE-2022-1829

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1828 - Pdf24 Articles To Pdf Plugin

The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Pdf24 Articles To Pdf

CVE-2022-1828

MEDIUM CVSS 6.5 2022-06-20
Scroll to top