Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,522
Critical1,453
High4,828
Medium12,962
Reset
Showing 15661-15680 of 19522 records
Threat Entry Updated 2024-11-21

CVE-2023-50889 - Beaver Builder Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder – WordPress Page Builder allows Stored XSS.This issue affects Beaver Builder – WordPress Page Builder: from n/a through 2.7.2.

PLUGIN Beaver Builder

CVE-2023-50889

MEDIUM CVSS 6.5 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50879 - Wordpress Com Editing Toolkit Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress.Com Editing Toolkit allows Stored XSS.This issue affects WordPress.Com Editing Toolkit: from n/a through 3.78784.

PLUGIN Wordpress Com Editing Toolkit

CVE-2023-50879

MEDIUM CVSS 6.5 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-52135 - Ws Form Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WS Form WS Form LITE – Drag & Drop Contact Form Builder for WordPress.This issue affects WS Form LITE – Drag & Drop Contact Form Builder for WordPress: from n/a through 1.9.170.

PLUGIN Ws Form

CVE-2023-52135

HIGH CVSS 7.6 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-51372 - Hashbar Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HashBar – WordPress Notification Bar allows Stored XSS.This issue affects HashBar – WordPress Notification Bar: from n/a through 1.4.1.

PLUGIN Hashbar

CVE-2023-51372

MEDIUM CVSS 5.9 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50896 - Weforms Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weForms weForms – Easy Drag & Drop Contact Form Builder For WordPress allows Stored XSS.This issue affects weForms – Easy Drag & Drop Contact Form Builder For WordPress: from n/a through 1.6.17.

PLUGIN Weforms

CVE-2023-50896

MEDIUM CVSS 5.9 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-40606 - Kanban Boards For Wordpress Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Kanban for WordPress Kanban Boards for WordPress.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21.

PLUGIN Kanban Boards For Wordpress

CVE-2023-40606

CRITICAL CVSS 9.1 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-50845 - Geodirectory Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins GeoDirectory – WordPress Business Directory Plugin, or Classified Directory.This issue affects GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: from n/a through 2.3.28.

PLUGIN Geodirectory

CVE-2023-50845

HIGH CVSS 7.6 2023-12-28
Threat Entry Updated 2024-11-21

CVE-2023-50849 - E2pdf Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.23.

PLUGIN E2pdf

CVE-2023-50849

HIGH CVSS 7.6 2023-12-28
Threat Entry Updated 2024-11-21

CVE-2023-50856 - Funnel Builder Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize Profits.This issue affects Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize Profits: from n/a through 2.14.3.

PLUGIN Funnel Builder

CVE-2023-50856

HIGH CVSS 7.6 2023-12-28
Threat Entry Updated 2024-12-17

CVE-2023-27447 - Wp Sms Plugin

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc.This issue affects WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc: from n/a through 6.0.4.

PLUGIN Wp Sms

CVE-2023-27447

MEDIUM CVSS 5.3 2023-12-28
Threat Entry Updated 2024-11-21

CVE-2023-51501 - Allows Reflected Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Undsgn Uncode - Creative & WooCommerce WordPress Theme allows Reflected XSS.This issue affects Uncode - Creative & WooCommerce WordPress Theme: from n/a through 2.8.6.

THEME Allows Reflected Xss

CVE-2023-51501

HIGH CVSS 7.1 2023-12-28
Threat Entry Updated 2024-11-21

CVE-2023-50874 - Ajax Load More Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney WordPress Infinite Scroll – Ajax Load More allows Stored XSS.This issue affects WordPress Infinite Scroll – Ajax Load More: from n/a through 6.1.0.1.

PLUGIN Ajax Load More

CVE-2023-50874

MEDIUM CVSS 6.5 2023-12-28
Threat Entry Updated 2024-11-21

CVE-2023-51700 - Unofficial Mobile Bankid Integration Plugin

Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability, specifically impacting scenarios where an attacker can manipulate the database. If unauthorized actors gain access to the database, they could exploit this vulnerability to execute object injection attacks. This could lead to unauthorized code execution, data manipulation, or data exfiltration within the WordPress environment. Users of the plugin should upgrade to version 1.0.1 (or later),…

PLUGIN Unofficial Mobile Bankid Integration

CVE-2023-51700

MEDIUM CVSS 6.4 2023-12-27
Threat Entry Updated 2024-11-21

CVE-2023-5991 - Hotel Booking Lite Plugin

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

PLUGIN Hotel Booking Lite

CVE-2023-5991

CRITICAL CVSS 9.8 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5931 - Buddypress And Bbpress Plugin

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server

PLUGIN Buddypress And Bbpress

CVE-2023-5931

HIGH CVSS 8.8 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5674 - Wp Mail Log Plugin

The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

PLUGIN Wp Mail Log

CVE-2023-5674

HIGH CVSS 8.8 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-6250 - Before 2 Plugin

The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag

PLUGIN Before 2

CVE-2023-6250

HIGH CVSS 7.5 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-6114 - Duplicator Pro Plugin

The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.

PLUGIN Duplicator Pro

CVE-2023-6114

HIGH CVSS 7.5 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-5939 - Buddypress And Bbpress Plugin

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users.

PLUGIN Buddypress And Bbpress

CVE-2023-5939

HIGH CVSS 7.2 2023-12-26
Threat Entry Updated 2024-11-21

CVE-2023-6268 - Json Content Importer Plugin

The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Json Content Importer

CVE-2023-6268

MEDIUM CVSS 6.1 2023-12-26
Scroll to top