Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,522
Critical1,456
High4,832
Medium12,968
Reset
Showing 15801-15820 of 19522 records
Threat Entry Updated 2024-11-21

CVE-2023-5641 - Easy Seo Backlink Link Building Network Plugin

The Martins Free & Easy SEO BackLink Link Building Network WordPress plugin before 1.2.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Easy Seo Backlink Link Building Network

CVE-2023-5641

MEDIUM CVSS 6.1 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5942 - Before 1 Plugin

The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2023-5942

MEDIUM CVSS 5.4 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5738 - Before 1 Plugin

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2023-5738

MEDIUM CVSS 5.4 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5620 - Web Push Notifications Plugin

The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.

PLUGIN Web Push Notifications

CVE-2023-5620

MEDIUM CVSS 5.4 2023-11-27
Threat Entry Updated 2025-01-16

CVE-2023-5611 - Seraphinite Accelerator Plugin

The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them

PLUGIN Seraphinite Accelerator

CVE-2023-5611

MEDIUM CVSS 5.3 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5737 - Before 1 Plugin

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.

PLUGIN Before 1

CVE-2023-5737

MEDIUM CVSS 4.3 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5559 - 10web Booster Plugin

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

PLUGIN 10web Booster

CVE-2023-5559

CRITICAL CVSS 9.1 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5239 - Malware Scan By Cleantalk Plugin

The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.

PLUGIN Malware Scan By Cleantalk

CVE-2023-5239

HIGH CVSS 7.5 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5560 - Wp Useronline Plugin

The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputting its content on the page, which allows unauthenticated users to perform Cross-Site Scripting attacks.

PLUGIN Wp Useronline

CVE-2023-5560

MEDIUM CVSS 6.1 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-4642 - Kk Star Ratings Plugin

The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.

PLUGIN Kk Star Ratings

CVE-2023-4642

MEDIUM CVSS 5.9 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-4514 - Mmm Simple File List Plugin

The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Mmm Simple File List

CVE-2023-4514

MEDIUM CVSS 5.4 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-4252 - Eventprime Plugin

The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.

PLUGIN Eventprime

CVE-2023-4252

MEDIUM CVSS 5.3 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5209 - Wordpress Online Booking And Scheduling Plugin

The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wordpress Online Booking And Scheduling

CVE-2023-5209

MEDIUM CVSS 4.8 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5525 - Limit Login Attempts Reloaded Plugin

The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.

PLUGIN Limit Login Attempts Reloaded

CVE-2023-5525

MEDIUM CVSS 4.3 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-4297 - Mmm Simple File List Plugin

The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing any authenticated users, such as subscribers, to list the content of arbitrary directories.

PLUGIN Mmm Simple File List

CVE-2023-4297

MEDIUM CVSS 4.3 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-2707 - Gappointments Plugin

The gAppointments WordPress plugin through 1.9.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Gappointments

CVE-2023-2707

MEDIUM CVSS 4.8 2023-11-27
Scroll to top