Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 1061-1080 of 1249 records
Threat Entry Updated 2026-04-08

CVE-2021-4360 - Controlled Admin Access Plugin

The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted access.

PLUGIN Controlled Admin Access

CVE-2021-4360

CRITICAL CVSS 9.9 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4370 - Ulisting Plugin

The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to conduct numerous administrative actions, including those less critical than the explicitly outlined ones in our detection.

PLUGIN Ulisting

CVE-2021-4370

CRITICAL CVSS 9.8 2023-06-07
Threat Entry Updated 2024-11-21

CVE-2021-4362 - Kiwi Social Share Plugin

The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated attackers to read and modify arbitrary options on a WordPress site that can be used for complete site takeover. This was a previously fixed vulnerability that was reintroduced in this version.

PLUGIN Kiwi Social Share

CVE-2021-4362

CRITICAL CVSS 9.8 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4357 - Ulisting Plugin

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and pages.

PLUGIN Ulisting

CVE-2021-4357

CRITICAL CVSS 9.1 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4356 - Frontend File Manager Plugin

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticated attackers to download arbitrary files on the site, potentially leading to site takeover.

PLUGIN Frontend File Manager

CVE-2021-4356

CRITICAL CVSS 9.0 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4347 - Advanced Shipment Tracking For Woocommerce Plugin

The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5 was initially released as a fix, but doesn't fully address the issue.

PLUGIN Advanced Shipment Tracking For Woocommerce

CVE-2021-4347

CRITICAL CVSS 9.9 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4346 - Ulisting Plugin

The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing the admin account's email address.

PLUGIN Ulisting

CVE-2021-4346

CRITICAL CVSS 9.8 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4343 - Ulisting Plugin

The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to create accounts, even those with administrator privileges.

PLUGIN Ulisting

CVE-2021-4343

CRITICAL CVSS 9.8 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4341 - Ulisting Plugin

The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPress option in the database.

PLUGIN Ulisting

CVE-2021-4341

CRITICAL CVSS 9.8 2023-06-07
Threat Entry Updated 2026-04-08

CVE-2021-4340 - Ulisting Plugin

The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ulisting

CVE-2021-4340

CRITICAL CVSS 9.8 2023-06-07
Threat Entry Updated 2024-11-21

CVE-2023-2987 - Wordapp Plugin

The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to the plugin to change the 'validation_token' in the plugin config, providing access to the plugin's remote control functionalities, such as creating an admin access URL, which can be used for privilege escalation.

PLUGIN Wordapp

CVE-2023-2987

CRITICAL CVSS 9.8 2023-05-31
Threat Entry Updated 2024-11-21

CVE-2023-2734 - Mstore Api Plugin

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

PLUGIN Mstore Api

CVE-2023-2734

CRITICAL CVSS 9.8 2023-05-25
Threat Entry Updated 2024-11-21

CVE-2023-2733 - Mstore Api Plugin

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

PLUGIN Mstore Api

CVE-2023-2733

CRITICAL CVSS 9.8 2023-05-25
Threat Entry Updated 2024-11-21

CVE-2023-2732 - Mstore Api Plugin

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

PLUGIN Mstore Api

CVE-2023-2732

CRITICAL CVSS 9.8 2023-05-25
Threat Entry Updated 2024-11-21

CVE-2023-2276 - Wcfm Membership Plugin

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.

PLUGIN Wcfm Membership

CVE-2023-2276

CRITICAL CVSS 9.8 2023-05-20
Threat Entry Updated 2024-11-21

CVE-2023-2704 - Bp Social Connect Plugin

The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

PLUGIN Bp Social Connect

CVE-2023-2704

CRITICAL CVSS 9.8 2023-05-19
Threat Entry Updated 2024-11-21

CVE-2023-2499 - Registrationmagic Plugin

The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

PLUGIN Registrationmagic

CVE-2023-2499

CRITICAL CVSS 9.8 2023-05-16
Threat Entry Updated 2026-03-06

CVE-2023-0600 - Before 6 Plugin

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

PLUGIN Before 6

CVE-2023-0600

CRITICAL CVSS 9.8 2023-05-15
Threat Entry Updated 2025-05-12

CVE-2023-1650 - Ai Chatbot Plugin

The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog

PLUGIN Ai Chatbot

CVE-2023-1650

CRITICAL CVSS 9.8 2023-05-08
Threat Entry Updated 2025-01-30

CVE-2023-1730 - Before 3 Plugin

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

PLUGIN Before 3

CVE-2023-1730

CRITICAL CVSS 9.8 2023-05-02
Scroll to top