Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,522
Critical1,453
High4,828
Medium12,962
Reset
Showing 15721-15740 of 19522 records
Threat Entry Updated 2024-11-21

CVE-2023-5882 - Wp All Export Pro Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.

PLUGIN Wp All Export Pro

CVE-2023-5882

HIGH CVSS 8.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-4311 - Vrm360 Plugin

The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode.

PLUGIN Vrm360

CVE-2023-4311

HIGH CVSS 8.8 2023-12-18
Threat Entry Updated 2025-05-20

CVE-2023-4724 - Wp All Export Pro Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server

PLUGIN Wp All Export Pro

CVE-2023-4724

HIGH CVSS 7.2 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6077 - Before 3 Plugin

The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected

PLUGIN Before 3

CVE-2023-6077

MEDIUM CVSS 6.5 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6065 - Quttera Web Malware Scanner Plugin

The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code

PLUGIN Quttera Web Malware Scanner

CVE-2023-6065

MEDIUM CVSS 5.3 2023-12-18
Threat Entry Updated 2025-05-07

CVE-2023-5005 - Autocomplete Location Field Contact Form 7 Plugin

The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-pro WordPress plugin before 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Autocomplete Location Field Contact Form 7

CVE-2023-5005

MEDIUM CVSS 4.8 2023-12-18
Threat Entry Updated 2025-05-07

CVE-2023-6289 - Swift Performance Lite Plugin

The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.

PLUGIN Swift Performance Lite

CVE-2023-6289

MEDIUM CVSS 4.3 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6559 - Mw Wp Form Plugin

The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.

PLUGIN Mw Wp Form

CVE-2023-6559

HIGH CVSS 7.5 2023-12-16
Threat Entry Updated 2024-11-21

CVE-2023-49187 - Allows Reflected Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spoonthemes Adifier - Classified Ads WordPress Theme allows Reflected XSS.This issue affects Adifier - Classified Ads WordPress Theme: from n/a before 3.1.4.

THEME Allows Reflected Xss

CVE-2023-49187

HIGH CVSS 7.1 2023-12-15
Threat Entry Updated 2024-11-21

CVE-2023-49170 - Captainform Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captainform Forms by CaptainForm – Form Builder for WordPress allows Reflected XSS.This issue affects Forms by CaptainForm – Form Builder for WordPress: from n/a through 2.5.3.

PLUGIN Captainform

CVE-2023-49170

HIGH CVSS 7.1 2023-12-15
Threat Entry Updated 2024-11-21

CVE-2023-6553 - Backup Migration Plugin

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

PLUGIN Backup Migration

CVE-2023-6553

CRITICAL CVSS 9.8 2023-12-15
Threat Entry Updated 2024-11-21

CVE-2023-6827 - Essential Real Estate Plugin

The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFonts' function in versions up to, and including, 4.3.5. This makes it possible for authenticated attackers with subscriber-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Essential Real Estate

CVE-2023-6827

HIGH CVSS 7.5 2023-12-15
Threat Entry Updated 2024-11-21

CVE-2023-6826 - E2pdf Plugin

The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1.20.25. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN E2pdf

CVE-2023-6826

HIGH CVSS 7.2 2023-12-15
Threat Entry Updated 2024-11-21

CVE-2023-49841 - Simple List Building Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FancyThemes Optin Forms – Simple List Building Plugin for WordPress allows Stored XSS.This issue affects Optin Forms – Simple List Building Plugin for WordPress: from n/a through 1.3.3.

PLUGIN Simple List Building

CVE-2023-49841

MEDIUM CVSS 5.9 2023-12-14
Threat Entry Updated 2024-11-21

CVE-2023-49827 - Soledad Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme allows Reflected XSS.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

PLUGIN Soledad

CVE-2023-49827

HIGH CVSS 7.1 2023-12-14
Scroll to top