Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,516
Critical1,453
High4,826
Medium12,961
Reset
Showing 15501-15520 of 19516 records
Threat Entry Updated 2025-06-02

CVE-2023-0376 - Before 1 Plugin

The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-0376

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2024-11-21

CVE-2023-0094 - Upqode Google Maps Plugin

The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Upqode Google Maps

CVE-2023-0094

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2023-0079 - Customer Reviews For Woocommerce Plugin

The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Customer Reviews For Woocommerce

CVE-2023-0079

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-11

CVE-2023-0389 - Calculated Fields Form Plugin

The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Calculated Fields Form

CVE-2023-0389

MEDIUM CVSS 4.8 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2023-2252 - Before 7 Plugin

The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

PLUGIN Before 7

CVE-2023-2252

LOW CVSS 2.7 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2021-24869 - Wp Fastest Cache Plugin

The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading to an SQL injection exploitable by low privilege users such as subscriber

PLUGIN Wp Fastest Cache

CVE-2021-24869

HIGH CVSS 8.8 2024-01-16
Threat Entry Updated 2025-05-12

CVE-2021-24870 - Wp Fastest Cache Plugin

The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload

PLUGIN Wp Fastest Cache

CVE-2021-24870

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2024-11-21

CVE-2021-24567 - Simple Post Plugin

The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.

PLUGIN Simple Post

CVE-2021-24567

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2021-4227 - Ark Commenteditor Plugin

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section

PLUGIN Ark Commenteditor

CVE-2021-4227

MEDIUM CVSS 5.3 2024-01-16
Threat Entry Updated 2025-06-17

CVE-2021-25117 - Wp Postratings Plugin

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.

PLUGIN Wp Postratings

CVE-2021-25117

MEDIUM CVSS 4.8 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2021-24151 - Wp Editor Plugin

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.

PLUGIN Wp Editor

CVE-2021-24151

HIGH CVSS 7.2 2024-01-16
Threat Entry Updated 2025-06-20

CVE-2021-24559 - Before 0 Plugin

The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site Scripting attacks. Furthermore, the data_uri_to_meta AJAX action, available to all authenticated users, only had a CSRF check in place, with the nonce available to users with a role as low as Contributor allowing any user with such role (and above) to set a malicious data-uri in arbitrary QR Code posts, leading to a Stored Cross-Site Scripting issue.

PLUGIN Before 0

CVE-2021-24559

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-02

CVE-2021-24433 - Through 0 Plugin

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use allowed URL protocols, which can lead to stored cross-site scripting by users with a role as low as Contributor

PLUGIN Through 0

CVE-2021-24433

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2025-06-11

CVE-2023-6623 - Essential Blocks Plugin

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.

PLUGIN Essential Blocks

CVE-2023-6623

CRITICAL CVSS 9.8 2024-01-15
Threat Entry Updated 2025-06-03

CVE-2023-6049 - Estatik Real Estate Plugin

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog

PLUGIN Estatik Real Estate

CVE-2023-6049

CRITICAL CVSS 9.8 2024-01-15
Threat Entry Updated 2025-06-11

CVE-2023-6991 - Before 2 Plugin

The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow users with contributor role and above to perform SSRF attacks.

PLUGIN Before 2

CVE-2023-6991

HIGH CVSS 8.8 2024-01-15
Threat Entry Updated 2025-06-20

CVE-2023-5905 - Export Posts With Images Plugin

The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected posts.

PLUGIN Export Posts With Images

CVE-2023-5905

HIGH CVSS 8.1 2024-01-15
Threat Entry Updated 2025-06-11

CVE-2023-6029 - Before 2 Plugin

The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.

PLUGIN Before 2

CVE-2023-6029

HIGH CVSS 7.5 2024-01-15
Scroll to top