Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14721-14740 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1820 - Keep Backup Daily Plugin

The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Keep Backup Daily

CVE-2022-1820

MEDIUM CVSS 6.1 2022-06-13
Threat Entry Updated 2025-05-05

CVE-2022-1961 - Google Tag Manager Plugin

The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~/public/frontend.php` file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Google Tag Manager

CVE-2022-1961

MEDIUM CVSS 5.5 2022-06-13
Threat Entry Updated 2025-05-05

CVE-2022-1750 - Sticky Popup Plugin

The Sticky Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ popup_title' parameter in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin level capabilities and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This issue mostly affects sites where unfiltered_html has been disabled for administrators and on multi-site installations where unfiltered_html is disabled for administrators.

PLUGIN Sticky Popup

CVE-2022-1750

MEDIUM CVSS 5.5 2022-06-13
Threat Entry Updated 2025-01-31

CVE-2022-0209 - Mitsol Social Post Feed Plugin

The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Mitsol Social Post Feed

CVE-2022-0209

MEDIUM CVSS 4.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1918 - Toolbar To Share Plugin

The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0. This is due to missing nonce validation on the plugin_toolbar_comparte page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Toolbar To Share

CVE-2022-1918

HIGH CVSS 8.8 2022-06-13
Threat Entry Updated 2025-05-05

CVE-2022-1900 - Copify Plugin

The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. This is due to missing nonce validation on the CopifySettings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Copify

CVE-2022-1900

HIGH CVSS 8.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1800 - Before 1 Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.

PLUGIN Before 1

CVE-2022-1800

HIGH CVSS 7.2 2022-06-13
Threat Entry Updated 2025-03-21

CVE-2022-1985 - Download Manager Plugin

The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.

PLUGIN Download Manager

CVE-2022-1985

MEDIUM CVSS 6.1 2022-06-13
Threat Entry Updated 2025-05-05

CVE-2022-1822 - Zephyr Project Manager Plugin

The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Zephyr Project Manager

CVE-2022-1822

MEDIUM CVSS 6.1 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1792 - Quick Subscribe Plugin

The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them

PLUGIN Quick Subscribe

CVE-2022-1792

MEDIUM CVSS 5.4 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1814 - Wp Admin Style Plugin

The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

PLUGIN Wp Admin Style

CVE-2022-1814

MEDIUM CVSS 4.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1793 - Private Files Plugin

The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow attackers to make a logged in admin perform such action via a CSRF attack and make the blog public

PLUGIN Private Files

CVE-2022-1793

MEDIUM CVSS 4.3 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1777 - Before 1 Plugin

The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticated users, such as subscriber. They are are protected with a nonce, however the nonce is leaked on the dashboard. This could allow them to upload arbitrary HTML files as well as delete all files or arbitrary ones.

PLUGIN Before 1

CVE-2022-1777

HIGH CVSS 8.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1765 - Hot Linked Image Cacher Plugin

The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations or licensing rules).

PLUGIN Hot Linked Image Cacher

CVE-2022-1765

HIGH CVSS 8.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1758 - Genki Pre Publish Reminder Plugin

The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS as well as RCE when custom code is added via the plugin settings.

PLUGIN Genki Pre Publish Reminder

CVE-2022-1758

HIGH CVSS 8.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1791 - One Click Plugin Updater

The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check.

PLUGIN One Click Plugin Updater

CVE-2022-1791

HIGH CVSS 8.1 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1779 - Auto Delete Posts Plugin

The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific posts, categories and attachments at once.

PLUGIN Auto Delete Posts

CVE-2022-1779

HIGH CVSS 8.1 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1762 - Before 1 Plugin

The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.

PLUGIN Before 1

CVE-2022-1762

HIGH CVSS 7.5 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1790 - New User Email Set Up Plugin

The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN New User Email Set Up

CVE-2022-1790

MEDIUM CVSS 6.5 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1788 - Change Uploaded File Permissions Plugin

Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.

PLUGIN Change Uploaded File Permissions

CVE-2022-1788

MEDIUM CVSS 6.5 2022-06-13
Scroll to top