Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,522
Critical1,456
High4,832
Medium12,968
Reset
Showing 15781-15800 of 19522 records
Threat Entry Updated 2024-11-21

CVE-2023-6449 - Contact Form 7 Plugin

The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' function in versions up to, and including, 5.8.3. This makes it possible for authenticated attackers with editor-level capabilities or above to upload arbitrary files on the affected site's server, but due to the htaccess configuration, remote code cannot be executed in most cases. By default, the file will be deleted from the server immediately. However, in some cases, other plugins may…

PLUGIN Contact Form 7

CVE-2023-6449

MEDIUM CVSS 6.6 2023-12-01
Threat Entry Updated 2024-11-21

CVE-2023-6360 - My Calendar Plugin

The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.

PLUGIN My Calendar

CVE-2023-6360

HIGH CVSS 8.6 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-46086 - Affiliate Toolkit Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin allows Reflected XSS.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.4.3.

PLUGIN Affiliate Toolkit

CVE-2023-46086

HIGH CVSS 7.1 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-48754 - Delete Post Revisions Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Wap Nepal Delete Post Revisions In WordPress allows Cross Site Request Forgery.This issue affects Delete Post Revisions In WordPress: from n/a through 4.6.

PLUGIN Delete Post Revisions

CVE-2023-48754

MEDIUM CVSS 5.4 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-48328 - Nextgen Gallery Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through 3.37.

PLUGIN Nextgen Gallery

CVE-2023-48328

MEDIUM CVSS 4.3 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-5803 - Business Directory Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Business Directory Team Business Directory Plugin – Easy Listing Directories for WordPress allows Cross-Site Request Forgery.This issue affects Business Directory Plugin – Easy Listing Directories for WordPress: from n/a through 6.3.10.

PLUGIN Business Directory

CVE-2023-5803

MEDIUM CVSS 4.3 2023-11-30
Threat Entry Updated 2025-02-11

CVE-2023-37890 - Kb Support Plugin

Missing Authorization vulnerability in WPOmnia KB Support – WordPress Help Desk and Knowledge Base allows Accessing Functionality Not Properly Constrained by ACLs. Users with a role as low as a subscriber can view other customers.This issue affects KB Support – WordPress Help Desk and Knowledge Base: from n/a through 1.5.88.

PLUGIN Kb Support

CVE-2023-37890

MEDIUM CVSS 4.3 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-37867 - Yet Another Stars Rating Plugin

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: from n/a through 3.3.8.

PLUGIN Yet Another Stars Rating

CVE-2023-37867

LOW CVSS 3.7 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-48323 - Awesome Support Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.

PLUGIN Awesome Support

CVE-2023-48323

MEDIUM CVSS 4.3 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-38474 - Campaign Monitor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Reflected XSS.This issue affects Campaign Monitor for WordPress: from n/a through 2.8.12.

PLUGIN Campaign Monitor

CVE-2023-38474

HIGH CVSS 7.1 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-48322 - Employee Job Application Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eDoc Intelligence eDoc Employee Job Application – Best WordPress Job Manager for Employees allows Reflected XSS.This issue affects eDoc Employee Job Application – Best WordPress Job Manager for Employees: from n/a through 1.13.

PLUGIN Employee Job Application

CVE-2023-48322

HIGH CVSS 7.1 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-5772 - Debug Log Manager Plugin

The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the clear_log() function. This makes it possible for unauthenticated attackers to clear the debug log via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Debug Log Manager

CVE-2023-5772

MEDIUM CVSS 4.3 2023-11-30
Threat Entry Updated 2024-11-21

CVE-2023-6225 - Shortcodes Ultimate Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_meta shortcode combined with post meta data in all versions up to, and including, 5.13.3 due to insufficient input sanitization and output escaping on user supplied meta values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shortcodes Ultimate

CVE-2023-6225

MEDIUM CVSS 6.4 2023-11-28
Threat Entry Updated 2024-11-21

CVE-2023-6226 - Shortcodes Ultimate Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys 'key' and 'post_id'. This makes it possible for authenticated attackers, with contributor-level access and above, to retrieve arbitrary post meta values which may contain sensitive information when combined with another plugin.

PLUGIN Shortcodes Ultimate

CVE-2023-6226

MEDIUM CVSS 4.3 2023-11-28
Threat Entry Updated 2024-11-21

CVE-2023-6219 - Bookingpress Plugin

The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'bookingpress_process_upload' function in versions up to, and including, 1.0.76. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Bookingpress

CVE-2023-6219

HIGH CVSS 7.2 2023-11-28
Threat Entry Updated 2024-11-21

CVE-2023-5604 - Asgaros Forum Plugin

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.

PLUGIN Asgaros Forum

CVE-2023-5604

CRITICAL CVSS 9.8 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5906 - Before 1 Plugin

The Job Manager & Career WordPress plugin before 1.4.4 contains a vulnerability in the Directory Listings system, which allows an unauthorized user to view and download private files of other users. This vulnerability poses a serious security threat because it allows an attacker to gain access to confidential data and files of other users without their permission.

PLUGIN Before 1

CVE-2023-5906

HIGH CVSS 7.5 2023-11-27
Threat Entry Updated 2025-06-04

CVE-2023-5958 - Post Smtp Mailer Plugin

The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.

PLUGIN Post Smtp Mailer

CVE-2023-5958

MEDIUM CVSS 6.1 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5653 - Wassup Real Time Analytics Plugin

The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins

PLUGIN Wassup Real Time Analytics

CVE-2023-5653

MEDIUM CVSS 6.1 2023-11-27
Scroll to top