Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2023-2599 - Ldap Login For Intranet Sites Plugin
The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to cause resource exhaustion via a forged request granted they can trick…
CVE-2023-2599
CVE-2023-2434 - Nested Pages Plugin
The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings.
CVE-2023-2434
CVE-2023-2117 - Image Optimizer By 10web Plugin
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.
CVE-2023-2117
CVE-2023-2608 - Multiple Page Generator Plugin
The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to missing nonce verification on the projects_list function and insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries leading to resource exhaustion via a forged request granted they can trick an administrator into performing…
CVE-2023-2608
CVE-2023-23677 - Gtmetrix Plugin
Reflected Cross-Site Scripting (XSS) vulnerability in GTmetrix GTmetrix for WordPress plugin
CVE-2023-23677
CVE-2021-36906 - Quiz And Survey Master Plugin
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin
CVE-2021-36906
CVE-2021-36864 - Quiz And Survey Master Plugin
Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin
CVE-2021-36864
CVE-2021-36865 - Quiz And Survey Master Plugin
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin
CVE-2021-36865
CVE-2022-40215 - Vc Tabs Plugin
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin
CVE-2022-40215
CVE-2022-37328 - Timeline Awesome Plugin
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin
CVE-2022-37328
CVE-2022-38703 - Maxbuttons Plugin
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin
CVE-2022-38703
CVE-2022-2556 - Mailchimp For Woocommerce Plugin
The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example
CVE-2022-2556
CVE-2022-36343 - Enable Svg Webp Ico Upload Plugin
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin
CVE-2022-36343
CVE-2022-33994 - Gutenberg Plugin
The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents are blocked by some similar products, and this behavioral difference might have security relevance to some WordPress site administrators.
CVE-2022-33994
CVE-2022-30536 - Wp Maintenance Plugin
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin
CVE-2022-30536
CVE-2022-29454 - Better Messages Plugin
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin
CVE-2022-29454
CVE-2021-36849 - Social Media Share Buttons Plugin
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons plugin
CVE-2021-36849
CVE-2022-29452 - Export All Urls Plugin
Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin
CVE-2022-29452
CVE-2022-1690 - Note Press Plugin
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection
CVE-2022-1690
CVE-2022-1689 - Note Press Plugin
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQL statement when updating a note via the admin dashboard, leading to an SQL injection
CVE-2022-1689
