Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15181-15200 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-0267 - Before 5 Plugin

The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection

PLUGIN Before 5

CVE-2022-0267

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0445 - Eprivacy Cookie Consent Plugin

The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack

PLUGIN Eprivacy Cookie Consent

CVE-2022-0445

MEDIUM CVSS 6.5 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0533 - Before 3 Plugin

The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

PLUGIN Before 3

CVE-2022-0533

MEDIUM CVSS 6.1 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0429 - Malware Scan Plugin

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.

PLUGIN Malware Scan

CVE-2022-0429

MEDIUM CVSS 6.1 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0422 - White Label Cms Plugin

The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue

PLUGIN White Label Cms

CVE-2022-0422

MEDIUM CVSS 6.1 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0347 - Custom Login Page Customizer Plugin

The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

PLUGIN Custom Login Page Customizer

CVE-2022-0347

MEDIUM CVSS 6.1 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0426 - Product Feed Pro For Woocommerce Plugin

The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before outputting it back in an attribute via the woosea_categories_dropdown AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting

PLUGIN Product Feed Pro For Woocommerce

CVE-2022-0426

MEDIUM CVSS 5.4 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0535 - E2pdf Plugin

The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN E2pdf

CVE-2022-0535

MEDIUM CVSS 4.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0448 - Cp Blocks Plugin

The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

PLUGIN Cp Blocks

CVE-2022-0448

MEDIUM CVSS 4.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0389 - Wp Time Slots Booking Form Plugin

The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Wp Time Slots Booking Form

CVE-2022-0389

MEDIUM CVSS 4.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0442 - Before 1 Plugin

The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

PLUGIN Before 1

CVE-2022-0442

MEDIUM CVSS 4.3 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0384 - Video Conferencing With Zoom Plugin

The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog

PLUGIN Video Conferencing With Zoom

CVE-2022-0384

MEDIUM CVSS 4.3 2022-03-07
Threat Entry Updated 2025-03-12

CVE-2021-24952 - Before 4 Plugin

The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement, allowing any authenticated user to perform SQL injection attacks.

PLUGIN Before 4

CVE-2021-24952

HIGH CVSS 8.8 2022-03-07
Threat Entry Updated 2025-03-21

CVE-2021-25087 - Download Manager Plugin

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

PLUGIN Download Manager

CVE-2021-25087

HIGH CVSS 7.5 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0163 - Before 2 Plugin

The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.

PLUGIN Before 2

CVE-2022-0163

MEDIUM CVSS 6.5 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-25098 - Pricing Tables Plugin

The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, which will be put in the trash

PLUGIN Pricing Tables

CVE-2021-25098

MEDIUM CVSS 6.5 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-25039 - Before 2 Plugin

The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 2

CVE-2021-25039

MEDIUM CVSS 6.1 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-25038 - Before 2 Plugin

The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 2

CVE-2021-25038

MEDIUM CVSS 6.1 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24953 - Advanced Iframe Plugin

The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Advanced Iframe

CVE-2021-24953

MEDIUM CVSS 6.1 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0205 - Before 6 Plugin

The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue

PLUGIN Before 6

CVE-2022-0205

MEDIUM CVSS 5.4 2022-03-07
Scroll to top