Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,409
Critical1,426
High4,784
Medium12,920
Reset
Showing 15301-15320 of 19409 records
Threat Entry Updated 2024-11-21

CVE-2024-23825 - Tablepress Plugin

TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. That user input is filtered insufficiently, which makes it is possible to send requests to unintended network locations and receive responses. On sites in a cloud environment like AWS, an attacker can potentially make GET requests to the instance's metadata REST API. If the instance's configuration is insecure, this can lead to the exposure of internal data, including credentials. This vulnerability is fixed in 2.2.5.

PLUGIN Tablepress

CVE-2024-23825

LOW CVSS 3.0 2024-01-30
Threat Entry Updated 2024-11-21

CVE-2024-1061 - Html5 Video Player Plugin

The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.

PLUGIN Html5 Video Player

CVE-2024-1061

HIGH CVSS 8.6 2024-01-30
Threat Entry Updated 2024-11-21

CVE-2023-7225 - Mappress Plugin

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions up to, and including, 2.88.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mappress

CVE-2023-7225

MEDIUM CVSS 6.4 2024-01-30
Threat Entry Updated 2025-06-17

CVE-2023-7074 - Wp Social Bookmark Menu Plugin

The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

PLUGIN Wp Social Bookmark Menu

CVE-2023-7074

HIGH CVSS 8.8 2024-01-29
Threat Entry Updated 2025-06-11

CVE-2023-6946 - Autotitle Plugin

The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

PLUGIN Autotitle

CVE-2023-6946

HIGH CVSS 8.8 2024-01-29
Threat Entry Updated 2025-05-29

CVE-2023-6391 - Custom User Css Plugin

The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

PLUGIN Custom User Css

CVE-2023-6391

HIGH CVSS 8.8 2024-01-29
Threat Entry Updated 2025-06-20

CVE-2023-6390 - Wordpress Users Plugin

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

PLUGIN Wordpress Users

CVE-2023-6390

HIGH CVSS 8.8 2024-01-29
Threat Entry Updated 2026-02-20

CVE-2023-6279 - Woostify Sites Library Plugin

The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as subscriber to update arbitrary blog options and set them to 'activated' which could lead to DoS when using a specific option name

PLUGIN Woostify Sites Library

CVE-2023-6279

HIGH CVSS 7.1 2024-01-29
Threat Entry Updated 2025-06-02

CVE-2023-7200 - Before 4 Plugin

The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 4

CVE-2023-7200

MEDIUM CVSS 6.1 2024-01-29
Threat Entry Updated 2025-06-20

CVE-2023-6389 - Wordpress Toolbar Plugin

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

PLUGIN Wordpress Toolbar

CVE-2023-6389

MEDIUM CVSS 6.1 2024-01-29
Threat Entry Updated 2025-06-20

CVE-2023-6278 - Before 2 Plugin

The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 2

CVE-2023-6278

MEDIUM CVSS 6.1 2024-01-29
Threat Entry Updated 2025-06-20

CVE-2023-7089 - Easy Svg Support Plugin

The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

PLUGIN Easy Svg Support

CVE-2023-7089

MEDIUM CVSS 5.4 2024-01-29
Threat Entry Updated 2025-05-29

CVE-2023-6530 - Tj Shortcodes Plugin

The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Tj Shortcodes

CVE-2023-6530

MEDIUM CVSS 5.4 2024-01-29
Threat Entry Updated 2024-11-21

CVE-2023-6503 - Wp Plugin Lister

The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

PLUGIN Wp Plugin Lister

CVE-2023-6503

MEDIUM CVSS 5.4 2024-01-29
Threat Entry Updated 2025-05-29

CVE-2023-7199 - Relevanssi Premium Plugin

The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request

PLUGIN Relevanssi Premium

CVE-2023-7199

MEDIUM CVSS 5.3 2024-01-29
Threat Entry Updated 2025-05-29

CVE-2023-6165 - Restrict Usernames Emails Characters Plugin

The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Restrict Usernames Emails Characters

CVE-2023-6165

MEDIUM CVSS 4.8 2024-01-29
Threat Entry Updated 2025-06-09

CVE-2023-5956 - Wp Adv Quiz Plugin

The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Wp Adv Quiz

CVE-2023-5956

MEDIUM CVSS 4.8 2024-01-29
Threat Entry Updated 2025-06-11

CVE-2023-5943 - Before 1 Plugin

The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Before 1

CVE-2023-5943

MEDIUM CVSS 4.8 2024-01-29
Threat Entry Updated 2025-05-22

CVE-2023-5124 - Before 1 Plugin

The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfiltered_html is disallowed, such as in multi-site WordPress configurations.

PLUGIN Before 1

CVE-2023-5124

MEDIUM CVSS 4.8 2024-01-29
Scroll to top