Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total19,522
Critical1,456
High4,832
Medium12,968
Reset
Showing 15821-15840 of 19522 records
Threat Entry Updated 2024-11-21

CVE-2023-47835 - Ari Stream Quiz Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder plugin

PLUGIN Ari Stream Quiz

CVE-2023-47835

MEDIUM CVSS 6.5 2023-11-23
Threat Entry Updated 2024-11-21

CVE-2023-6009 - Userpro Plugin

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.

PLUGIN Userpro

CVE-2023-6009

HIGH CVSS 8.8 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5822 - Drag And Drop Multiple File Upload Contact Form 7 Plugin

The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This can be exploited if a user authorized to edit form, which means editor privileges or above, has added a 'multiple file upload' form field with '*' acceptable file types.

PLUGIN Drag And Drop Multiple File Upload Contact Form 7

CVE-2023-5822

HIGH CVSS 8.1 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-6007 - Userpro Plugin

The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.

PLUGIN Userpro

CVE-2023-6007

HIGH CVSS 7.3 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-6008 - Userpro Plugin

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.

PLUGIN Userpro

CVE-2023-6008

MEDIUM CVSS 6.3 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-6160 - Lifterlms Plugin

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 7.4.2 via the maybe_serve_export function. This makes it possible for authenticated attackers, with administrator or LMS manager access and above, to read the contents of arbitrary CSV files on the server, which can contain sensitive information as well as removing those files from the server.

PLUGIN Lifterlms

CVE-2023-6160

LOW CVSS 3.3 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-6164 - Mainwp Plugin

The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficient input sanitization. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary CSS values into the site tags.

PLUGIN Mainwp

CVE-2023-6164

LOW CVSS 2.2 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5815 - News Blog Designer Pack Plugin

The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local File Inclusion in all versions up to, and including, 3.4.1 via the bdp_get_more_post function hooked via a nopriv AJAX. This is due to function utilizing an unsafe extract() method to extract values from the POST variable and passing that input to the include() function. This makes it possible for unauthenticated attackers to include…

PLUGIN News Blog Designer Pack

CVE-2023-5815

HIGH CVSS 8.1 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5742 - Easyrotator For Wordpress Plugin

The EasyRotator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyrotator' shortcode in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Easyrotator For Wordpress

CVE-2023-5742

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5708 - Wp Post Columns Plugin

The WP Post Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'column' shortcode in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Post Columns

CVE-2023-5708

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5706 - Vk Blocks Plugin

The VK Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk-blocks/ancestor-page-list' block in all versions up to, and including, 1.63.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Vk Blocks

CVE-2023-5706

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5704 - Cpo Shortcodes Plugin

The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cpo Shortcodes

CVE-2023-5704

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5715 - Heatmap Plugin

The Website Optimization – Plerdy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tracking code settings in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Heatmap

CVE-2023-5715

MEDIUM CVSS 4.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5667 - Tab Ultimate Plugin

The Tab Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Tab Ultimate

CVE-2023-5667

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5664 - Garden Gnome Package Plugin

The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ggpkg' shortcode in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This was partially patched in version 2.2.7 and fully patched in version 2.2.9.

PLUGIN Garden Gnome Package

CVE-2023-5664

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5662 - Sponsors Plugin

The Sponsors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sponsors' shortcode in all versions up to, and including, 3.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sponsors

CVE-2023-5662

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5469 - Drop Shadow Boxes Plugin

The Drop Shadow Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dropshadowbox' shortcode in versions up to, and including, 1.7.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Drop Shadow Boxes

CVE-2023-5469

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5537 - Delete Usermeta Plugin

The Delete Usermeta plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing nonce validation on the delumet_options_page() function. This makes it possible for unauthenticated attackers to remove user meta for arbitrary users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Delete Usermeta

CVE-2023-5537

MEDIUM CVSS 4.3 2023-11-22
Threat Entry Updated 2024-11-21

CVE-2023-5466 - Wp Anything Slider Plugin

The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wp Anything Slider

CVE-2023-5466

HIGH CVSS 8.8 2023-11-22
Scroll to top