Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 1021-1040 of 1249 records
Threat Entry Updated 2025-02-19

CVE-2023-24410 - Fastest Contact Form Builder Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPManageNinja LLC Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms fluentform allows SQL Injection.This issue affects Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms: from n/a through 4.3.25.

PLUGIN Fastest Contact Form Builder

CVE-2023-24410

CRITICAL CVSS 9.8 2023-10-31
Threat Entry Updated 2024-11-21

CVE-2023-5843 - Ads By Datafeedr Com Plugin

The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load_ads' function. This allows unauthenticated attackers to execute code on the server. The parameters of the callable function are limited, they cannot be specified arbitrarily.

PLUGIN Ads By Datafeedr Com

CVE-2023-5843

CRITICAL CVSS 9.0 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5199 - Php To Page Plugin

The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and potentially execute code on the server. While subscribers may need to poison log files or otherwise get a file installed in order to achieve remote code execution, author and above users can upload files by default and achieve remote code execution easily.

PLUGIN Php To Page

CVE-2023-5199

CRITICAL CVSS 9.9 2023-10-30
Threat Entry Updated 2024-11-21

CVE-2023-5820 - Thumbnail Slider With Lightbox Plugin

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Thumbnail Slider With Lightbox

CVE-2023-5820

CRITICAL CVSS 9.6 2023-10-27
Threat Entry Updated 2024-11-21

CVE-2023-5414 - Icegram Express Plugin

The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information including those belonging to other sites, for example in shared hosting environments.

PLUGIN Icegram Express

CVE-2023-5414

CRITICAL CVSS 9.1 2023-10-20
Threat Entry Updated 2024-11-21

CVE-2023-4488 - Dropbox Folder Share Plugin

The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PLUGIN Dropbox Folder Share

CVE-2023-4488

CRITICAL CVSS 9.8 2023-10-20
Threat Entry Updated 2025-05-12

CVE-2023-5241 - Wpbot Plugin

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "

PLUGIN Wpbot

CVE-2023-5241

CRITICAL CVSS 9.6 2023-10-19
Threat Entry Updated 2025-05-12

CVE-2023-5212 - Wpbot Plugin

The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files on the server, which makes it possible to take over affected sites as well as others sharing the same hosting account. Version 4.9.1 originally addressed the issue, but it was reintroduced in 4.9.2 and fixed again in 4.9.3.

PLUGIN Wpbot

CVE-2023-5212

CRITICAL CVSS 9.6 2023-10-19
Threat Entry Updated 2025-05-12

CVE-2023-5204 - Wpbot Plugin

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wpbot

CVE-2023-5204

CRITICAL CVSS 9.8 2023-10-19
Threat Entry Updated 2025-04-23

CVE-2023-4666 - Form Maker By 10web Plugin

The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE

PLUGIN Form Maker By 10web

CVE-2023-4666

CRITICAL CVSS 9.8 2023-10-16
Threat Entry Updated 2024-11-21

CVE-2023-5201 - Openhook Plugin

The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php] shortcode setting to be enabled on the vulnerable site.

PLUGIN Openhook

CVE-2023-5201

CRITICAL CVSS 9.9 2023-09-30
Threat Entry Updated 2025-04-23

CVE-2023-4521 - Import Xml And Rss Feeds Plugin

The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

PLUGIN Import Xml And Rss Feeds

CVE-2023-4521

CRITICAL CVSS 9.8 2023-09-25
Threat Entry Updated 2025-04-23

CVE-2023-4490 - Wp Job Portal Plugin

The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

PLUGIN Wp Job Portal

CVE-2023-4490

CRITICAL CVSS 9.8 2023-09-25
Threat Entry Updated 2024-11-21

CVE-2023-4994 - Allow Php In Posts And Pages Plugin

The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.

PLUGIN Allow Php In Posts And Pages

CVE-2023-4994

CRITICAL CVSS 9.9 2023-09-16
Threat Entry Updated 2024-11-21

CVE-2023-4634 - Media Library Assistant Plugin

The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible.

PLUGIN Media Library Assistant

CVE-2023-4634

CRITICAL CVSS 9.8 2023-09-06
Threat Entry Updated 2024-11-21

CVE-2023-3162 - Stripe Payment Plugin For Woocommerce

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows unauthenticated attackers to log in as users who have orders, who are typically customers.

PLUGIN Stripe Payment Plugin For Woocommerce

CVE-2023-3162

CRITICAL CVSS 9.8 2023-08-31
Threat Entry Updated 2024-11-21

CVE-2023-4596 - Forminator Plugin

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Forminator

CVE-2023-4596

CRITICAL CVSS 9.8 2023-08-30
Threat Entry Updated 2024-11-21

CVE-2023-4404 - Charitable Plugin

The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' parameter during a registration.

PLUGIN Charitable

CVE-2023-4404

CRITICAL CVSS 9.8 2023-08-23
Threat Entry Updated 2024-11-21

CVE-2023-3435 - User Activity Log Plugin

The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

PLUGIN User Activity Log

CVE-2023-3435

CRITICAL CVSS 9.8 2023-08-14
Scroll to top