Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 981-1000 of 1249 records
Threat Entry Updated 2026-04-08

CVE-2021-4434 - Social Warfare Plugin

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.

PLUGIN Social Warfare

CVE-2021-4434

CRITICAL CVSS 10.0 2024-01-17
Threat Entry Updated 2025-06-11

CVE-2023-3211 - Wordpress Database Administrator Plugin

The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

PLUGIN Wordpress Database Administrator

CVE-2023-3211

CRITICAL CVSS 9.8 2024-01-16
Threat Entry Updated 2025-06-13

CVE-2023-0224 - Before 2 Plugin

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks

PLUGIN Before 2

CVE-2023-0224

CRITICAL CVSS 9.8 2024-01-16
Threat Entry Updated 2025-06-11

CVE-2023-6623 - Essential Blocks Plugin

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.

PLUGIN Essential Blocks

CVE-2023-6623

CRITICAL CVSS 9.8 2024-01-15
Threat Entry Updated 2025-06-03

CVE-2023-6049 - Estatik Real Estate Plugin

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog

PLUGIN Estatik Real Estate

CVE-2023-6049

CRITICAL CVSS 9.8 2024-01-15
Threat Entry Updated 2024-11-21

CVE-2023-6979 - Customer Reviews For Woocommerce Plugin

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Customer Reviews For Woocommerce

CVE-2023-6979

CRITICAL CVSS 9.8 2024-01-11
Threat Entry Updated 2025-06-04

CVE-2023-6875 - Post Smtp Plugin

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover.

PLUGIN Post Smtp

CVE-2023-6875

CRITICAL CVSS 9.8 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6567 - Learnpress Plugin

The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Learnpress

CVE-2023-6567

CRITICAL CVSS 9.8 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6316 - Mw Wp Form Plugin

The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Mw Wp Form

CVE-2023-6316

CRITICAL CVSS 9.8 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-6699 - Wp Compress Plugin

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Wp Compress

CVE-2023-6699

CRITICAL CVSS 9.1 2024-01-11
Threat Entry Updated 2025-06-03

CVE-2023-5877 - Affiliate Toolkit Plugin

The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.

PLUGIN Affiliate Toolkit

CVE-2023-5877

CRITICAL CVSS 9.8 2024-01-01
Threat Entry Updated 2024-11-21

CVE-2023-52182 - Ari Stream Quiz Plugin

Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.

PLUGIN Ari Stream Quiz

CVE-2023-52182

CRITICAL CVSS 9.9 2023-12-31
Threat Entry Updated 2024-11-21

CVE-2023-51419 - Bertha Ai Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Bertha.Ai BERTHA AI. Your AI co-pilot for WordPress and Chrome.This issue affects BERTHA AI. Your AI co-pilot for WordPress and Chrome: from n/a through 1.11.10.7.

PLUGIN Bertha Ai

CVE-2023-51419

CRITICAL CVSS 10.0 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-40606 - Kanban Boards For Wordpress Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Kanban for WordPress Kanban Boards for WordPress.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21.

PLUGIN Kanban Boards For Wordpress

CVE-2023-40606

CRITICAL CVSS 9.1 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-5991 - Hotel Booking Lite Plugin

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

PLUGIN Hotel Booking Lite

CVE-2023-5991

CRITICAL CVSS 9.8 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-29384 - Jobwp Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment Plugin – JobWP: from n/a through 2.0.

PLUGIN Jobwp

CVE-2023-29384

CRITICAL CVSS 10.0 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-49750 - Submitting Coupons Theme

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate & Submitting Coupons WordPress Theme.This issue affects Couponis - Affiliate & Submitting Coupons WordPress Theme: from n/a before 2.2.

THEME Submitting Coupons

CVE-2023-49750

CRITICAL CVSS 9.3 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-6272 - Theme My Login 2fa Plugin

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

PLUGIN Theme My Login 2fa

CVE-2023-6272

CRITICAL CVSS 9.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6553 - Backup Migration Plugin

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

PLUGIN Backup Migration

CVE-2023-6553

CRITICAL CVSS 9.8 2023-12-15
Scroll to top