Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 1161-1180 of 1249 records
Threat Entry Updated 2024-11-21

CVE-2022-0784 - Title Experiments Free Plugin

The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

PLUGIN Title Experiments Free

CVE-2022-0784

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0679 - Narnoo Distributor Plugin

The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results in the disclosure of arbitrary files as the content of the file is then displayed in the response as JSON data. This could also lead to RCE with various tricks but depends on the underlying system and it's configuration.

PLUGIN Narnoo Distributor

CVE-2022-0679

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0479 - Popup Builder Plugin

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link

PLUGIN Popup Builder

CVE-2022-0479

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2021-25070 - Block Bad Bots Plugin

The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue

PLUGIN Block Bad Bots

CVE-2021-25070

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0888 - Ninja Forms File Uploads Extension Plugin

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0

PLUGIN Ninja Forms File Uploads Extension

CVE-2022-0888

CRITICAL CVSS 9.8 2022-03-23
Threat Entry Updated 2024-11-21

CVE-2022-0760 - Simple Link Directory Plugin

The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

PLUGIN Simple Link Directory

CVE-2022-0760

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0747 - Infographic Maker Plugin

The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

PLUGIN Infographic Maker

CVE-2022-0747

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0739 - Bookingpress Plugin

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

PLUGIN Bookingpress

CVE-2022-0739

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0694 - Advanced Booking Calendar Plugin

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

PLUGIN Advanced Booking Calendar

CVE-2022-0694

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0591 - Before 3 Plugin

The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

PLUGIN Before 3

CVE-2022-0591

CRITICAL CVSS 9.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0658 - Before 2 Plugin

The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

PLUGIN Before 2

CVE-2022-0658

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0254 - Wordpress Zero Spam Plugin

The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection

PLUGIN Wordpress Zero Spam

CVE-2022-0254

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0169 - Photo Gallery By 10web Plugin

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

PLUGIN Photo Gallery By 10web

CVE-2022-0169

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-25003 - Before 6 Plugin

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

PLUGIN Before 6

CVE-2021-25003

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0441 - Masterstudy Lms Plugin

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

PLUGIN Masterstudy Lms

CVE-2022-0441

CRITICAL CVSS 9.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0434 - Page View Count Plugin

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

PLUGIN Page View Count

CVE-2022-0434

CRITICAL CVSS 9.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0349 - Before 2 Plugin

The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection

PLUGIN Before 2

CVE-2022-0349

CRITICAL CVSS 9.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0412 - Ti Woocommerce Wishlist Plugin

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

PLUGIN Ti Woocommerce Wishlist

CVE-2022-0412

CRITICAL CVSS 9.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25010 - Post Snippets Plugin

The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues

PLUGIN Post Snippets

CVE-2021-25010

CRITICAL CVSS 9.6 2022-02-28
Scroll to top