Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14741-14760 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1761 - Peter S Collaboration E Mails Plugin

The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more.

PLUGIN Peter S Collaboration E Mails

CVE-2022-1761

MEDIUM CVSS 6.5 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1773 - Wp Athletics Plugin

The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Wp Athletics

CVE-2022-1773

MEDIUM CVSS 6.1 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1787 - Sideblog Plugin

The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

PLUGIN Sideblog

CVE-2022-1787

MEDIUM CVSS 5.4 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1781 - Posttabs Plugin

The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

PLUGIN Posttabs

CVE-2022-1781

MEDIUM CVSS 5.4 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1780 - Latex Plugin

The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack which could also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

PLUGIN Latex

CVE-2022-1780

MEDIUM CVSS 5.4 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1764 - Wp Chgfontsize Plugin

The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

PLUGIN Wp Chgfontsize

CVE-2022-1764

MEDIUM CVSS 5.4 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1763 - Static Page Extended Plugin

Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings

PLUGIN Static Page Extended

CVE-2022-1763

MEDIUM CVSS 5.4 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1759 - Rb Internal Links Plugin

The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform Stored Cross-Site Scripting attacks due to the lack of sanitisation and escaping

PLUGIN Rb Internal Links

CVE-2022-1759

MEDIUM CVSS 5.4 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1772 - Google Places Reviews Plugin

The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.

PLUGIN Google Places Reviews

CVE-2022-1772

MEDIUM CVSS 4.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1694 - Useful Banner Manager Plugin

The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin by submitting a form.

PLUGIN Useful Banner Manager

CVE-2022-1694

MEDIUM CVSS 6.5 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1624 - Latest Tweets Widget Plugin

The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Latest Tweets Widget

CVE-2022-1624

MEDIUM CVSS 6.5 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1612 - Webriti Smtp Mail Plugin

The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Webriti Smtp Mail

CVE-2022-1612

MEDIUM CVSS 6.5 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1608 - Social Locker Plugin

The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Social Locker

CVE-2022-1608

MEDIUM CVSS 6.5 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1605 - Email Users Plugin

The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users

PLUGIN Email Users

CVE-2022-1605

MEDIUM CVSS 6.5 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1756 - Before 7 Plugin

The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.

PLUGIN Before 7

CVE-2022-1756

MEDIUM CVSS 6.1 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1724 - Simple Membership Plugin

The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting

PLUGIN Simple Membership

CVE-2022-1724

MEDIUM CVSS 6.1 2022-06-13
Threat Entry Updated 2025-05-05

CVE-2022-1707 - Google Tag Manager Plugin

The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to an including 1.15. The affected file is ~/public/frontend.php and this could be exploited by unauthenticated attackers.

PLUGIN Google Tag Manager

CVE-2022-1707

MEDIUM CVSS 6.1 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1604 - Before 1 Plugin

The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-1604

MEDIUM CVSS 6.1 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1549 - Wp Athletics Plugin

The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability.

PLUGIN Wp Athletics

CVE-2022-1549

MEDIUM CVSS 5.4 2022-06-13
Scroll to top