Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,522
Critical1,453
High4,828
Medium12,962
Reset
Showing 15741-15760 of 19522 records
Threat Entry Updated 2024-11-21

CVE-2023-49833 - Spectra Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Spectra – WordPress Gutenberg Blocks: from n/a through 2.7.9.

PLUGIN Spectra

CVE-2023-49833

MEDIUM CVSS 6.5 2023-12-14
Threat Entry Updated 2024-11-21

CVE-2023-49168 - Better Messages Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPlus Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss allows Stored XSS.This issue affects Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss: from n/a through 2.4.0.

PLUGIN Better Messages

CVE-2023-49168

MEDIUM CVSS 6.5 2023-12-14
Threat Entry Updated 2024-11-21

CVE-2023-50371 - Most Wanted Analytics Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows Stored XSS.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 8.0.6.

PLUGIN Most Wanted Analytics

CVE-2023-50371

MEDIUM CVSS 6.5 2023-12-14
Threat Entry Updated 2024-11-21

CVE-2023-6035 - Before 2 Plugin

The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

PLUGIN Before 2

CVE-2023-6035

HIGH CVSS 8.8 2023-12-11
Threat Entry Updated 2025-05-27

CVE-2023-5907 - File Manager Plugin

The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, where site administrators should not be allowed to modify the sites files.

PLUGIN File Manager

CVE-2023-5907

MEDIUM CVSS 6.5 2023-12-11
Threat Entry Updated 2024-11-21

CVE-2023-5750 - Before 3 Plugin

The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2023-5750

MEDIUM CVSS 6.1 2023-12-11
Threat Entry Updated 2024-11-21

CVE-2023-5749 - Before 3 Plugin

The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 3

CVE-2023-5749

MEDIUM CVSS 6.1 2023-12-11
Threat Entry Updated 2024-11-21

CVE-2023-5955 - Contact Form Email Plugin

The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Contact Form Email

CVE-2023-5955

MEDIUM CVSS 4.8 2023-12-11
Threat Entry Updated 2024-11-21

CVE-2023-5940 - Wp Not Login Hide Plugin

The WP Not Login Hide (WPNLH) WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wp Not Login Hide

CVE-2023-5940

MEDIUM CVSS 4.8 2023-12-11
Threat Entry Updated 2024-11-21

CVE-2023-5757 - Wp Crowdfunding Plugin

The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wp Crowdfunding

CVE-2023-5757

MEDIUM CVSS 4.8 2023-12-11
Threat Entry Updated 2025-02-20

CVE-2023-6120 - Welcart E Commerce Plugin

The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 via the upload_certificate_file function. This makes it possible for administrators to upload .pem or .crt files to arbitrary locations on the server.

PLUGIN Welcart E Commerce

CVE-2023-6120

MEDIUM CVSS 4.1 2023-12-09
Threat Entry Updated 2024-11-21

CVE-2023-5756 - Digital Publications By Supsystic Plugin

The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Digital Publications By Supsystic

CVE-2023-5756

MEDIUM CVSS 5.4 2023-12-09
Threat Entry Updated 2024-11-21

CVE-2023-47548 - Integrate Google Drive Plugin

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site: from n/a through 1.3.2.

PLUGIN Integrate Google Drive

CVE-2023-47548

MEDIUM CVSS 4.7 2023-12-07
Threat Entry Updated 2024-11-21

CVE-2023-48325 - Landing Page Builder Plugin

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.This issue affects Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages: from n/a through 1.5.1.5.

PLUGIN Landing Page Builder

CVE-2023-48325

MEDIUM CVSS 4.7 2023-12-07
Threat Entry Updated 2024-11-21

CVE-2023-35039 - Password Reset With Code For Wordpress Rest Api Plugin

Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15.

PLUGIN Password Reset With Code For Wordpress Rest Api

CVE-2023-35039

CRITICAL CVSS 9.8 2023-12-07
Threat Entry Updated 2024-11-21

CVE-2023-35909 - Ninja Forms Plugin

Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: from n/a through 3.6.25.

PLUGIN Ninja Forms

CVE-2023-35909

MEDIUM CVSS 5.3 2023-12-07
Threat Entry Updated 2024-11-21

CVE-2023-41804 - Starter Templates Plugin

Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.

PLUGIN Starter Templates

CVE-2023-41804

HIGH CVSS 7.1 2023-12-07
Threat Entry Updated 2024-11-21

CVE-2023-5761 - Burst Statistics Plugin

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Burst Statistics

CVE-2023-5761

CRITICAL CVSS 9.8 2023-12-07
Threat Entry Updated 2024-11-21

CVE-2023-5714 - System Dashboard Plugin

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve data key specs.

PLUGIN System Dashboard

CVE-2023-5714

MEDIUM CVSS 4.3 2023-12-07
Threat Entry Updated 2024-11-21

CVE-2023-5713 - System Dashboard Plugin

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve potentially sensitive option values, and deserialize the content of those values.

PLUGIN System Dashboard

CVE-2023-5713

MEDIUM CVSS 4.3 2023-12-07
Scroll to top