Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2022-1014 - Wp Contacts Manager Plugin
The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability.
CVE-2022-1014
CVE-2022-0781 - Nirweb Support Plugin
The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection
CVE-2022-0781
CVE-2022-1221 - Gwyn S Imagemap Selector Plugin
The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.
CVE-2022-1221
CVE-2022-1218 - Domain Replace Plugin
The Domain Replace WordPress plugin through 1.3.8 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2022-1218
CVE-2022-1192 - Turn Off All Comments Plugin
The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2022-1192
CVE-2022-0346 - Xml Sitemap Generator For Google Plugin
The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.
CVE-2022-0346
CVE-2022-1093 - Before 4 Plugin
The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it to the page, allowing a high privilege user such as an administrator to inject arbitrary javascript into the page even when unfiltered html is disallowed.
CVE-2022-1093
CVE-2022-29447 - Hover Effects Plugin
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin
CVE-2022-29447
CVE-2022-29434 - Spiffy Calendar Plugin
Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar
CVE-2022-29434
CVE-2022-29431 - Cpt Base Plugin
Cross-Site Request Forgery (CSRF) vulnerability in KubiQ CPT base plugin
CVE-2022-29431
CVE-2022-29426 - 2j Slideshow Plugin
Authenticated (contributor or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team's Slideshow, Image Slider by 2J plugin
CVE-2022-29426
CVE-2022-29430 - Png To Jpg Plugin
Cross-Site Scripting (XSS) vulnerability in KubiQ's PNG to JPG plugin
CVE-2022-29430
CVE-2022-29427 - Disable Right Click For Wp Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin
CVE-2022-29427
CVE-2022-29428 - Wp Slider Plugin
Cross-Site Scripting (XSS) vulnerability in Muneeb's WP Slider Plugin
CVE-2022-29428
CVE-2022-29432 - Wpdatatables Plugin
Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-Plugins wpDataTables plugin
CVE-2022-29432
CVE-2022-29448 - Herd Effects Plugin
Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin
CVE-2022-29448
CVE-2022-29425 - Checkout Files Upload For Woocommerce Plugin
Cross-Site Scripting (XSS) vulnerability in WP Wham's Checkout Files Upload for WooCommerce plugin
CVE-2022-29425
CVE-2022-29424 - Image Hover Effects Ultimate Plugin
Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image Hover Effects Ultimate plugin
CVE-2022-29424
CVE-2021-36833 - Mailchimp For Wordpress Plugin
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin
CVE-2021-36833
CVE-2022-29446 - Counter Box Plugin
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin
CVE-2022-29446
