Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,522
Critical1,453
High4,828
Medium12,962
Reset
Showing 15641-15660 of 19522 records
Threat Entry Updated 2025-07-11

CVE-2023-6980 - Wp Sms Plugin

The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5. This is due to missing or incorrect nonce validation on the 'delete' action of the wp-sms-subscribers page. This makes it possible for unauthenticated attackers to delete subscribers via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Sms

CVE-2023-6980

MEDIUM CVSS 4.3 2024-01-03
Threat Entry Updated 2024-11-21

CVE-2023-7027 - Post Smtp Plugin

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Post Smtp

CVE-2023-7027

HIGH CVSS 7.2 2024-01-03
Threat Entry Updated 2024-11-21

CVE-2023-6629 - Post Smtp Plugin

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Post Smtp

CVE-2023-6629

MEDIUM CVSS 6.1 2024-01-03
Threat Entry Updated 2025-06-11

CVE-2023-6271 - Backup Migration Plugin

The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.

PLUGIN Backup Migration

CVE-2023-6271

HIGH CVSS 7.5 2024-01-01
Threat Entry Updated 2025-06-18

CVE-2023-6113 - Wp Staging Plugin

The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information about ongoing backups processes, allowing unauthenticated attackers to download said backups later.

PLUGIN Wp Staging

CVE-2023-6113

HIGH CVSS 7.5 2024-01-01
Threat Entry Updated 2025-06-18

CVE-2023-6000 - Popup Builder Plugin

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

PLUGIN Popup Builder

CVE-2023-6000

MEDIUM CVSS 6.1 2024-01-01
Threat Entry Updated 2025-06-18

CVE-2023-6485 - Html5 Video Player Plugin

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins

PLUGIN Html5 Video Player

CVE-2023-6485

MEDIUM CVSS 5.4 2024-01-01
Threat Entry Updated 2025-06-18

CVE-2023-6037 - Wp Tripadvisor Review Slider Plugin

The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wp Tripadvisor Review Slider

CVE-2023-6037

MEDIUM CVSS 4.8 2024-01-01
Threat Entry Updated 2025-06-03

CVE-2023-5877 - Affiliate Toolkit Plugin

The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.

PLUGIN Affiliate Toolkit

CVE-2023-5877

CRITICAL CVSS 9.8 2024-01-01
Threat Entry Updated 2024-11-21

CVE-2023-51547 - Fluent Support Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin.This issue affects Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin: from n/a through 1.7.6.

PLUGIN Fluent Support

CVE-2023-51547

HIGH CVSS 7.6 2023-12-31
Threat Entry Updated 2024-11-21

CVE-2023-52134 - Geo My Wordpress Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.0.2.

PLUGIN Geo My Wordpress

CVE-2023-52134

HIGH CVSS 7.6 2023-12-31
Threat Entry Updated 2024-11-21

CVE-2023-52185 - Everest Backup Plugin

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Everestthemes Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin.This issue affects Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin: from n/a through 2.1.9.

PLUGIN Everest Backup

CVE-2023-52185

MEDIUM CVSS 5.3 2023-12-31
Threat Entry Updated 2024-11-21

CVE-2023-52182 - Ari Stream Quiz Plugin

Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.

PLUGIN Ari Stream Quiz

CVE-2023-52182

CRITICAL CVSS 9.9 2023-12-31
Threat Entry Updated 2024-11-21

CVE-2023-51688 - Ecommerce Product Catalog Plugin

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Plugin for WordPress: from n/a through 3.3.26.

PLUGIN Ecommerce Product Catalog

CVE-2023-51688

MEDIUM CVSS 5.3 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-51419 - Bertha Ai Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Bertha.Ai BERTHA AI. Your AI co-pilot for WordPress and Chrome.This issue affects BERTHA AI. Your AI co-pilot for WordPress and Chrome: from n/a through 1.11.10.7.

PLUGIN Bertha Ai

CVE-2023-51419

CRITICAL CVSS 10.0 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50893 - Impreza Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution Impreza – WordPress Website and WooCommerce Builder allows Reflected XSS.This issue affects Impreza – WordPress Website and WooCommerce Builder: from n/a through 8.17.4.

PLUGIN Impreza

CVE-2023-50893

HIGH CVSS 7.1 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50892 - Allows Reflected Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme allows Reflected XSS.This issue affects TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme: from n/a through 5.9.1.

THEME Allows Reflected Xss

CVE-2023-50892

HIGH CVSS 7.1 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50891 - Vulnerability In Zoho Forms Form Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Form plugin for WordPress – Zoho Forms allows Stored XSS.This issue affects Form plugin for WordPress – Zoho Forms: from n/a through 3.0.1.

PLUGIN Vulnerability In Zoho Forms Form

CVE-2023-50891

MEDIUM CVSS 6.5 2023-12-29
Scroll to top