Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 1181-1200 of 1249 records
Threat Entry Updated 2024-11-21

CVE-2022-25149 - Wp Statistics Plugin

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

PLUGIN Wp Statistics

CVE-2022-25149

CRITICAL CVSS 9.8 2022-02-24
Threat Entry Updated 2024-11-21

CVE-2022-25148 - Wp Statistics Plugin

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

PLUGIN Wp Statistics

CVE-2022-25148

CRITICAL CVSS 9.8 2022-02-24
Threat Entry Updated 2024-11-21

CVE-2022-0651 - Wp Statistics Plugin

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

PLUGIN Wp Statistics

CVE-2022-0651

CRITICAL CVSS 9.8 2022-02-24
Threat Entry Updated 2024-11-21

CVE-2021-24867 - Ap Companion Plugin

Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion

PLUGIN Ap Companion

CVE-2021-24867

CRITICAL CVSS 9.8 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0513 - Wp Statistics Plugin

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.4. This requires the "Record Exclusions" option to be enabled on the vulnerable site.

PLUGIN Wp Statistics

CVE-2022-0513

CRITICAL CVSS 9.8 2022-02-16
Threat Entry Updated 2024-11-21

CVE-2021-25114 - Paid Memberships Pro Plugin

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

PLUGIN Paid Memberships Pro

CVE-2021-25114

CRITICAL CVSS 9.8 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2022-0320 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploaded files or other LFI to RCE techniques.

PLUGIN Essential Addons For Elementor

CVE-2022-0320

CRITICAL CVSS 9.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24762 - Perfect Survey Plugin

The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

PLUGIN Perfect Survey

CVE-2021-24762

CRITICAL CVSS 9.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24814 - Settings Ajax Action Of The Wordpress Gdpr Plugin

The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. If the victim is an administrator with a valid session cookie, full control of the WordPress instance may be taken (AJAX calls and iframe manipulation are possible because the vulnerable endpoint is on the same…

PLUGIN Settings Ajax Action Of The Wordpress Gdpr

CVE-2021-24814

CRITICAL CVSS 9.6 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25032 - Publishpress Capabilities Plugin

The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.

PLUGIN Publishpress Capabilities

CVE-2021-25032

CRITICAL CVSS 9.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-24849 - Controller Ajax Action Of The Wcfm Marketplace Plugin

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

PLUGIN Controller Ajax Action Of The Wcfm Marketplace

CVE-2021-24849

CRITICAL CVSS 9.8 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-4073 - Registrationmagic Plugin

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

PLUGIN Registrationmagic

CVE-2021-4073

CRITICAL CVSS 9.8 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-24951 - Before 4 Plugin

The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

PLUGIN Before 4

CVE-2021-24951

CRITICAL CVSS 9.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24946 - Modern Events Calendar Lite Plugin

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

PLUGIN Modern Events Calendar Lite

CVE-2021-24946

CRITICAL CVSS 9.8 2021-12-13
Threat Entry Updated 2026-01-16

CVE-2021-24863 - Nd Stop Bad Bots Crawlers And Spiders And Anti Spam Protection Plugin Stopbadbots

The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it, leading to a SQL injection

PLUGIN Nd Stop Bad Bots Crawlers And Spiders And Anti Spam Protection Plugin Stopbadbots

CVE-2021-24863

CRITICAL CVSS 9.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24857 - Totop Link Plugin

The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.

PLUGIN Totop Link

CVE-2021-24857

CRITICAL CVSS 9.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24922 - Pixel Cat Plugin

The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks

PLUGIN Pixel Cat

CVE-2021-24922

CRITICAL CVSS 9.0 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24943 - Registrations For The Events Calendar Plugin

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

PLUGIN Registrations For The Events Calendar

CVE-2021-24943

CRITICAL CVSS 9.8 2021-12-06
Scroll to top