Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14981-15000 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2021-4225 - Document Manager Plugin

The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows servers, the security checks in place were insufficient, enabling bad actors to potentially upload backdoors on vulnerable sites.

PLUGIN Document Manager

CVE-2021-4225

HIGH CVSS 8.8 2022-04-25
Threat Entry Updated 2025-04-21

CVE-2021-25094 - Before 3 Plugin

The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.

PLUGIN Before 3

CVE-2021-25094

HIGH CVSS 8.1 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2022-0656 - Before 3 Plugin

The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content base64 encoded in the response. As a result, unauthenticated users could read arbitrary files on the web server (such as /etc/passwd, wp-config.php etc)

PLUGIN Before 3

CVE-2022-0656

HIGH CVSS 7.5 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2021-46782 - Pricing Table By Supsystic Plugin

The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Pricing Table By Supsystic

CVE-2021-46782

MEDIUM CVSS 6.1 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2021-46781 - Coming Soon By Supsystic Plugin

The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Coming Soon By Supsystic

CVE-2021-46781

MEDIUM CVSS 6.1 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2021-46780 - Easy Google Maps Plugin

The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Easy Google Maps

CVE-2021-46780

MEDIUM CVSS 6.1 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2022-0398 - Thirstyaffiliates Affiliate Link Manager Plugin

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

PLUGIN Thirstyaffiliates Affiliate Link Manager

CVE-2022-0398

MEDIUM CVSS 5.4 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2022-0634 - Before 3 Plugin

The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks csrf checks, allowing an attacker to trick a logged in user to perform the action by crafting a special request.

PLUGIN Before 3

CVE-2022-0634

MEDIUM CVSS 4.3 2022-04-25
Threat Entry Updated 2025-10-17

CVE-2022-0363 - Before 2 Plugin

The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts.

PLUGIN Before 2

CVE-2022-0363

MEDIUM CVSS 4.3 2022-04-25
Threat Entry Updated 2025-10-17

CVE-2022-0287 - Before 2 Plugin

The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog

PLUGIN Before 2

CVE-2022-0287

MEDIUM CVSS 4.3 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2021-24805 - Dw Question Answer Plugin

The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, allowing attackers to make logged in users perform unwanted actions, such as update a comment or a question status.

PLUGIN Dw Question Answer

CVE-2021-24805

MEDIUM CVSS 4.3 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2021-24800 - Dw Question Answer Plugin

The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.

PLUGIN Dw Question Answer

CVE-2021-24800

MEDIUM CVSS 4.3 2022-04-25
Threat Entry Updated 2025-05-05

CVE-2022-0992 - Security Optimizer Plugin

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA for pending accounts. Upon successful configuration, the attacker is logged in as that user without access to a username/password pair which is the expected first form of authentication. This affects versions up to, and including, 1.2.5.

PLUGIN Security Optimizer

CVE-2022-0992

CRITICAL CVSS 9.8 2022-04-19
Threat Entry Updated 2024-11-21

CVE-2022-1329 - Website Builder Plugin

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

PLUGIN Website Builder

CVE-2022-1329

HIGH CVSS 8.8 2022-04-19
Threat Entry Updated 2024-11-21

CVE-2021-4096 - Fancy Product Designer Plugin

The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including, 4.7.5.

PLUGIN Fancy Product Designer

CVE-2021-4096

HIGH CVSS 8.8 2022-04-19
Threat Entry Updated 2024-11-21

CVE-2022-0993 - Siteground Security Plugin

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects versions up to, and including, 1.2.5.

PLUGIN Siteground Security

CVE-2022-0993

HIGH CVSS 8.1 2022-04-19
Threat Entry Updated 2024-11-21

CVE-2022-1119 - Simple File List Plugin

The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7.

PLUGIN Simple File List

CVE-2022-1119

HIGH CVSS 7.5 2022-04-19
Scroll to top