Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total196
Critical0
High0
Medium0
Reset
Showing 161-180 of 196 records
Threat Entry Updated 2024-11-21

CVE-2023-2599 - Ldap Login For Intranet Sites Plugin

The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to cause resource exhaustion via a forged request granted they can trick…

PLUGIN Ldap Login For Intranet Sites

CVE-2023-2599

LOW CVSS 3.1 2023-06-09
Threat Entry Updated 2024-11-21

CVE-2023-2434 - Nested Pages Plugin

The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings.

PLUGIN Nested Pages

CVE-2023-2434

LOW CVSS 3.8 2023-05-31
Threat Entry Updated 2025-01-10

CVE-2023-2117 - Image Optimizer By 10web Plugin

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

PLUGIN Image Optimizer By 10web

CVE-2023-2117

LOW CVSS 2.7 2023-05-30
Threat Entry Updated 2024-11-21

CVE-2023-2608 - Multiple Page Generator Plugin

The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to missing nonce verification on the projects_list function and insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries leading to resource exhaustion via a forged request granted they can trick an administrator into performing…

PLUGIN Multiple Page Generator

CVE-2023-2608

LOW CVSS 3.1 2023-05-17
Threat Entry Updated 2024-11-21

CVE-2022-2556 - Mailchimp For Woocommerce Plugin

The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

PLUGIN Mailchimp For Woocommerce

CVE-2022-2556

LOW CVSS 2.7 2022-08-29
Threat Entry Updated 2024-11-21

CVE-2022-33994 - Gutenberg Plugin

The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents are blocked by some similar products, and this behavioral difference might have security relevance to some WordPress site administrators.

PLUGIN Gutenberg

CVE-2022-33994

LOW CVSS 3.0 2022-07-30
Threat Entry Updated 2024-11-21

CVE-2022-1690 - Note Press Plugin

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection

PLUGIN Note Press

CVE-2022-1690

LOW CVSS 2.7 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1689 - Note Press Plugin

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQL statement when updating a note via the admin dashboard, leading to an SQL injection

PLUGIN Note Press

CVE-2022-1689

LOW CVSS 2.7 2022-06-08
Scroll to top