Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,522
Critical1,453
High4,828
Medium12,962
Reset
Showing 15701-15720 of 19522 records
Threat Entry Updated 2024-11-21

CVE-2023-29096 - Messages Database Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress.This issue affects Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress: from n/a through 1.7.0.

PLUGIN Messages Database

CVE-2023-29096

HIGH CVSS 8.5 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-29432 - Vulnerability In Favethemes Houzez Real Estate

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme.This issue affects Houzez - Real Estate WordPress Theme: from n/a before 2.8.3.

THEME Vulnerability In Favethemes Houzez Real Estate

CVE-2023-29432

HIGH CVSS 8.2 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-28788 - Most Wanted Analytics Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 6.4.2.

PLUGIN Most Wanted Analytics

CVE-2023-28788

HIGH CVSS 7.1 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-30750 - Cm Popup Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.

PLUGIN Cm Popup

CVE-2023-30750

HIGH CVSS 8.5 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-49825 - Soledad Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

PLUGIN Soledad

CVE-2023-49825

HIGH CVSS 8.5 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-47236 - Ipages Flipbook Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum iPages Flipbook For WordPress.This issue affects iPages Flipbook For WordPress: from n/a through 1.4.8.

PLUGIN Ipages Flipbook

CVE-2023-47236

HIGH CVSS 7.6 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-38519 - Mainwp Dashboard Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3.

PLUGIN Mainwp Dashboard

CVE-2023-38519

HIGH CVSS 7.6 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-49750 - Submitting Coupons Theme

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate & Submitting Coupons WordPress Theme.This issue affects Couponis - Affiliate & Submitting Coupons WordPress Theme: from n/a before 2.2.

THEME Submitting Coupons

CVE-2023-49750

CRITICAL CVSS 9.3 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-48764 - Guardgiant Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GuardGiant Brute Force Protection WordPress Brute Force Protection – Stop Brute Force Attacks.This issue affects WordPress Brute Force Protection – Stop Brute Force Attacks: from n/a through 2.2.5.

PLUGIN Guardgiant

CVE-2023-48764

HIGH CVSS 7.6 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-45105 - Affiliate Toolkit Plugin

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.3.9.

PLUGIN Affiliate Toolkit

CVE-2023-45105

MEDIUM CVSS 4.7 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-25715 - Gamipress Plugin

Missing Authorization vulnerability in GamiPress GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress.This issue affects GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress: from n/a through 2.5.6.

PLUGIN Gamipress

CVE-2023-25715

MEDIUM CVSS 5.4 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-5432 - Jquery News Ticker Plugin

The Jquery news ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jquery-news-ticker' shortcode in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Jquery News Ticker

CVE-2023-5432

MEDIUM CVSS 6.4 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-5413 - Image Horizontal Reel Scroll Slideshow Plugin

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ihrss-gallery' shortcode in versions up to, and including, 13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Image Horizontal Reel Scroll Slideshow

CVE-2023-5413

MEDIUM CVSS 6.4 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-6488 - Shortcodes Ultimate Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_button', 'su_members', and 'su_tabs' shortcodes in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shortcodes Ultimate

CVE-2023-6488

MEDIUM CVSS 5.4 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-46154 - E2pdf Plugin

Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.18.

PLUGIN E2pdf

CVE-2023-46154

MEDIUM CVSS 6.6 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-49821 - Wp Live Chat Plugin

Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.

PLUGIN Wp Live Chat

CVE-2023-49821

MEDIUM CVSS 5.4 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6295 - Siteorigin Widgets Bundle Plugin

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

PLUGIN Siteorigin Widgets Bundle

CVE-2023-6295

HIGH CVSS 7.2 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6272 - Theme My Login 2fa Plugin

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

PLUGIN Theme My Login 2fa

CVE-2023-6272

CRITICAL CVSS 9.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-5886 - Wp All Export Pro Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.

PLUGIN Wp All Export Pro

CVE-2023-5886

HIGH CVSS 8.8 2023-12-18
Scroll to top