Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14681-14700 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1945 - Maintenance Mode By Colorlib Plugin

The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered_html is disallowed (for example in multisite setup)

PLUGIN Maintenance Mode By Colorlib

CVE-2022-1945

MEDIUM CVSS 4.8 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1915 - Wp Zillow Review Slider Plugin

The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite)

PLUGIN Wp Zillow Review Slider

CVE-2022-1915

MEDIUM CVSS 4.8 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1896 - Before 1 Plugin

The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability is disallowed.

PLUGIN Before 1

CVE-2022-1896

MEDIUM CVSS 4.8 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1889 - Before 7 Plugin

The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed

PLUGIN Before 7

CVE-2022-1889

MEDIUM CVSS 4.8 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1895 - Before 1 Plugin

The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack

PLUGIN Before 1

CVE-2022-1895

MEDIUM CVSS 4.3 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1801 - Very Simple Contact Form Plugin

The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for spam bots.

PLUGIN Very Simple Contact Form

CVE-2022-1801

HIGH CVSS 7.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1614 - Wp Email Plugin

The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.

PLUGIN Wp Email

CVE-2022-1614

HIGH CVSS 7.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1472 - Better Find And Replace Plugin

The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection

PLUGIN Better Find And Replace

CVE-2022-1472

HIGH CVSS 7.2 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1827 - Pdf24 Articles To Pdf Plugin

The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Pdf24 Articles To Pdf

CVE-2022-1827

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1826 - Cross Linker Plugin

The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which could allow attackers to make a logged in admin perform such action via a CSRF attack

PLUGIN Cross Linker

CVE-2022-1826

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1630 - Before 2 Plugin

The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in admin delete logs via a CSRF attack

PLUGIN Before 2

CVE-2022-1630

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1610 - Seamless Donations Plugin

The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Seamless Donations

CVE-2022-1610

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2021-25121 - Rating By Bestwebsoft Plugin

The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service on the post/page when a user submit such rating

PLUGIN Rating By Bestwebsoft

CVE-2021-25121

MEDIUM CVSS 6.5 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1818 - Multi Page Toolkit Plugin

The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

PLUGIN Multi Page Toolkit

CVE-2022-1818

MEDIUM CVSS 5.4 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1717 - Custom Share Buttons With Floating Sidebar Plugin

The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

PLUGIN Custom Share Buttons With Floating Sidebar

CVE-2022-1717

MEDIUM CVSS 4.8 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1266 - Carousel Ultimate Plugin

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Carousel Ultimate

CVE-2022-1266

MEDIUM CVSS 4.8 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-0663 - Email By Printfriendly Plugin

The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text settings, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Email By Printfriendly

CVE-2022-0663

MEDIUM CVSS 4.8 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2022-1603 - Mail Subscribe List Plugin

The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users from the subscribed list

PLUGIN Mail Subscribe List

CVE-2022-1603

MEDIUM CVSS 4.3 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2021-25104 - Before 1 Plugin

The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-25104

MEDIUM CVSS 6.1 2022-06-20
Threat Entry Updated 2024-11-21

CVE-2021-25088 - Xml Sitemaps Plugin

The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Xml Sitemaps

CVE-2021-25088

MEDIUM CVSS 4.8 2022-06-20
Scroll to top