Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14901-14920 of 16358 records
Threat Entry Updated 2025-05-05

CVE-2022-1442 - Metform Elementor Contact Form Builder Plugin

The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.

PLUGIN Metform Elementor Contact Form Builder

CVE-2022-1442

HIGH CVSS 7.5 2022-05-10
Threat Entry Updated 2024-11-21

CVE-2022-1476 - All In One Wp Migration Plugin

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site's secret key.

PLUGIN All In One Wp Migration

CVE-2022-1476

MEDIUM CVSS 6.6 2022-05-10
Threat Entry Updated 2025-05-05

CVE-2022-1567 - Wp Js Plugin

The WP-JS plugin for WordPress contains a script called wp-js.php with the function wp_js_admin, that accepts unvalidated user input and echoes it back to the user. This can be used for reflected Cross-Site Scripting in versions up to, and including, 2.0.6.

PLUGIN Wp Js

CVE-2022-1567

MEDIUM CVSS 6.1 2022-05-10
Threat Entry Updated 2024-11-21

CVE-2022-1209 - Ultimate Member Plugin

The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.

PLUGIN Ultimate Member

CVE-2022-1209

MEDIUM CVSS 4.3 2022-05-10
Threat Entry Updated 2024-11-21

CVE-2022-1013 - Personal Dictionary Plugin

The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.

PLUGIN Personal Dictionary

CVE-2022-1013

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0948 - Before 3 Plugin

The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

PLUGIN Before 3

CVE-2022-0948

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0836 - Sema Api Plugin

The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL statements via an AJAX action, leading to SQL Injections exploitable by unauthenticated users

PLUGIN Sema Api

CVE-2022-0836

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0826 - Wp Video Gallery Free Plugin

The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

PLUGIN Wp Video Gallery Free

CVE-2022-0826

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0817 - Badgeos Plugin

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

PLUGIN Badgeos

CVE-2022-0817

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0814 - Para Woocommerce Plugin

The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

PLUGIN Para Woocommerce

CVE-2022-0814

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0592 - Before 6 Plugin

The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

PLUGIN Before 6

CVE-2022-0592

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0625 - Admin Menu Editor Plugin

The Admin Menu Editor WordPress plugin through 1.0.4 does not sanitize and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Admin Menu Editor

CVE-2022-0625

MEDIUM CVSS 6.1 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0898 - Igniteup Plugin

The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored Cross-Site Scripting issues

PLUGIN Igniteup

CVE-2022-0898

MEDIUM CVSS 5.4 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0424 - Popup By Supsystic Plugin

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

PLUGIN Popup By Supsystic

CVE-2022-0424

MEDIUM CVSS 5.3 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-1338 - Easily Generate Rest Api Plugin

The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Easily Generate Rest Api

CVE-2022-1338

MEDIUM CVSS 4.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-1303 - Slide Anything Plugin

The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow high privilege users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Slide Anything

CVE-2022-1303

MEDIUM CVSS 4.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-1104 - Before 1 Plugin

The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2022-1104

MEDIUM CVSS 4.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0874 - Wp Social Buttons Plugin

The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Wp Social Buttons

CVE-2022-0874

MEDIUM CVSS 4.8 2022-05-09
Scroll to top