Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 1001-1020 of 1249 records
Threat Entry Updated 2024-11-21

CVE-2023-35039 - Password Reset With Code For Wordpress Rest Api Plugin

Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15.

PLUGIN Password Reset With Code For Wordpress Rest Api

CVE-2023-35039

CRITICAL CVSS 9.8 2023-12-07
Threat Entry Updated 2024-11-21

CVE-2023-5761 - Burst Statistics Plugin

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Burst Statistics

CVE-2023-5761

CRITICAL CVSS 9.8 2023-12-07
Threat Entry Updated 2025-02-20

CVE-2023-5952 - Welcart E Commerce Plugin

The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog

PLUGIN Welcart E Commerce

CVE-2023-5952

CRITICAL CVSS 9.8 2023-12-04
Threat Entry Updated 2024-11-21

CVE-2023-5604 - Asgaros Forum Plugin

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.

PLUGIN Asgaros Forum

CVE-2023-5604

CRITICAL CVSS 9.8 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5559 - 10web Booster Plugin

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

PLUGIN 10web Booster

CVE-2023-5559

CRITICAL CVSS 9.1 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-2449 - Userpro Plugin

The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (userpro_process_form). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-2448 and CVE-2023-2446, or another vulnerability like SQL Injection in another plugin or theme installed on the site to successfully exploit this…

PLUGIN Userpro

CVE-2023-2449

CRITICAL CVSS 9.8 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-2437 - Userpro Plugin

The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email. An attacker can leverage CVE-2023-2448 and CVE-2023-2446 to get the user's email address to successfully exploit this vulnerability.

PLUGIN Userpro

CVE-2023-2437

CRITICAL CVSS 9.8 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5652 - Wp Hotel Booking Plugin

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

PLUGIN Wp Hotel Booking

CVE-2023-5652

CRITICAL CVSS 9.8 2023-11-20
Threat Entry Updated 2024-11-21

CVE-2023-5640 - Article Analytics Plugin

The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection vulnerability.

PLUGIN Article Analytics

CVE-2023-5640

CRITICAL CVSS 9.8 2023-11-20
Threat Entry Updated 2024-11-21

CVE-2023-5340 - Five Star Restaurant Menu And Food Ordering Plugin

The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.

PLUGIN Five Star Restaurant Menu And Food Ordering

CVE-2023-5340

CRITICAL CVSS 9.8 2023-11-20
Threat Entry Updated 2025-02-26

CVE-2023-45074 - Advanced Page Visit Counter Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.

PLUGIN Advanced Page Visit Counter

CVE-2023-45074

CRITICAL CVSS 9.8 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-45069 - Video Gallery Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery Plugin: from n/a through 2.1.3.

PLUGIN Video Gallery

CVE-2023-45069

CRITICAL CVSS 9.8 2023-11-06
Threat Entry Updated 2025-02-26

CVE-2023-35911 - Contact Form Generator Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.

PLUGIN Contact Form Generator

CVE-2023-35911

CRITICAL CVSS 9.8 2023-11-06
Threat Entry Updated 2025-02-19

CVE-2023-36529 - Allows Sql Injection Theme

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress Theme: from n/a through 1.3.4.

THEME Allows Sql Injection

CVE-2023-36529

CRITICAL CVSS 9.8 2023-11-03
Threat Entry Updated 2025-02-19

CVE-2023-26015 - Mappress Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Injection.This issue affects MapPress Maps for WordPress: from n/a through 2.85.4.

PLUGIN Mappress

CVE-2023-26015

CRITICAL CVSS 9.8 2023-11-03
Threat Entry Updated 2024-11-21

CVE-2023-3277 - Mstore Api Plugin

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address. We are disclosing this issue as the developer has not yet released a patch, but continues to release updates and we escalated this issue to the plugin's team 30 days ago.

PLUGIN Mstore Api

CVE-2023-3277

CRITICAL CVSS 9.8 2023-11-03
Threat Entry Updated 2025-02-19

CVE-2023-36508 - Messages Database Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress contact-form-to-db allows SQL Injection.This issue affects Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress: from n/a through 1.7.1.

PLUGIN Messages Database

CVE-2023-36508

CRITICAL CVSS 9.8 2023-10-31
Scroll to top