Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15061-15080 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-0537 - Mappress Maps For Plugin

The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet directory, and a .php file extension is added. No validation is performed on the content of the file, triggering an RCE vulnerability by uploading a web shell. Further the name parameter is not sanitized, allowing the payload to be uploaded to any directory to which the server has write…

PLUGIN Mappress Maps For

CVE-2022-0537

HIGH CVSS 7.2 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0830 - Formbuilder Plugin

The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, attackers could make logged in admin update and delete arbitrary forms via a CSRF attack, and put Cross-Site Scripting payloads in them.

PLUGIN Formbuilder

CVE-2022-0830

MEDIUM CVSS 6.5 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0404 - Material Design For Contact Form 7 Plugin

The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options to true, potentially leading to Denial of Service by breaking the site.

PLUGIN Material Design For Contact Form 7

CVE-2022-0404

MEDIUM CVSS 6.5 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0864 - Updraftplus Wordpress Backup Plugin

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

PLUGIN Updraftplus Wordpress Backup

CVE-2022-0864

MEDIUM CVSS 6.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0431 - Insights From Google Pagespeed Plugin

The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting

PLUGIN Insights From Google Pagespeed

CVE-2022-0431

MEDIUM CVSS 6.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0837 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this vulnerability to drain out the account balance by keep sending SMS notification.

PLUGIN Before 1

CVE-2022-0837

MEDIUM CVSS 5.4 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0825 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

PLUGIN Before 1

CVE-2022-0825

MEDIUM CVSS 5.4 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0884 - Before 3 Plugin

The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 3

CVE-2022-0884

MEDIUM CVSS 4.8 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2021-25113 - Dropdown Menu Widget Plugin

The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

PLUGIN Dropdown Menu Widget

CVE-2021-25113

MEDIUM CVSS 5.4 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2021-25048 - Kingcomposer Plugin

The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them

PLUGIN Kingcomposer

CVE-2021-25048

MEDIUM CVSS 5.4 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0846 - Email Petitions Plugin

The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users

PLUGIN Email Petitions

CVE-2022-0846

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0787 - Before 5 Plugin

The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections

PLUGIN Before 5

CVE-2022-0787

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0784 - Title Experiments Free Plugin

The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

PLUGIN Title Experiments Free

CVE-2022-0784

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0679 - Narnoo Distributor Plugin

The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results in the disclosure of arbitrary files as the content of the file is then displayed in the response as JSON data. This could also lead to RCE with various tricks but depends on the underlying system and it's configuration.

PLUGIN Narnoo Distributor

CVE-2022-0679

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0770 - Translate Wordpress With Gtranslate Plugin

The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin cookies by making them open a malicious link or page

PLUGIN Translate Wordpress With Gtranslate

CVE-2022-0770

HIGH CVSS 8.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0499 - Sermon Browser Plugin

The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

PLUGIN Sermon Browser

CVE-2022-0499

HIGH CVSS 8.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0818 - Woocommerce Affiliate Plugin

The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.

PLUGIN Woocommerce Affiliate

CVE-2022-0818

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0680 - Before 1 Plugin

The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configuration_tracker_enable option, which is then displayed in the admin panel without sanitisation and escaping, leading to a Stored Cross-Site Scripting issue

PLUGIN Before 1

CVE-2022-0680

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0647 - Bulk Creator Plugin

The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Bulk Creator

CVE-2022-0647

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0643 - Bank Mellat Plugin

The Bank Mellat WordPress plugin through 1.3.7 does not sanitize and escape the orderId parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Bank Mellat

CVE-2022-0643

MEDIUM CVSS 6.1 2022-03-28
Scroll to top