Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2022-0707 - Easy Digital Downloads Plugin
The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes, which could allow attackers to make a logged admin insert arbitrary notes via a CSRF attack
CVE-2022-0707
CVE-2022-23976 - Access Demo Importer Plugin
Cross-Site Request Forgery (CSRF) in Access Demo Importer
CVE-2022-23976
CVE-2022-23975 - Access Demo Importer Plugin
Cross-Site Request Forgery (CSRF) in Access Demo Importer
CVE-2022-23975
CVE-2022-27847 - Yoo Slider – Image Slider & Video Slider (WordPress plugin)
Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider
CVE-2022-27847
CVE-2022-27846 - Yoo Slider Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider
CVE-2022-27846
CVE-2022-0142 - Visual Form Builder Plugin
The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
CVE-2022-0142
CVE-2022-0141 - Visual Form Builder Plugin
The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks
CVE-2022-0141
CVE-2022-0140 - Visual Form Builder Plugin
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
CVE-2022-0140
CVE-2022-1023 - Podcast Importer Secondline Plugin
The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file
CVE-2022-1023
CVE-2022-1008 - Before 3 Plugin
The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed
CVE-2022-1008
CVE-2022-0949 - Block Bad Bots And Stop Bad Bots Crawlers And Spiders And Anti Spam Protection Plugin
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users, leading to a SQL injection
CVE-2022-0949
CVE-2022-0989 - Ns Watermark For Woocommerce Plugin
An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.
CVE-2022-0989
CVE-2022-0920 - Salon Booking System Plugin
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data
CVE-2022-0920
CVE-2022-0828 - Download Manager Plugin
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.
CVE-2022-0828
CVE-2022-1006 - Advanced Booking Calendar Plugin
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks
CVE-2022-1006
CVE-2022-0914 - Export All Urls Plugin
The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example
CVE-2022-0914
CVE-2022-0447 - Before 2 Plugin
The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting
CVE-2022-0447
CVE-2022-1007 - Advanced Booking Calendar Plugin
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
CVE-2022-1007
CVE-2022-0892 - Export All Urls Plugin
The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-0892
CVE-2022-0531 - Before 0 Plugin
The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting
CVE-2022-0531
