Search Results (20818 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-6278 1 Biteship 1 Biteship 2025-06-20 6.1 Medium
The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2023-7082 1 Soflyy 1 Export Any Wordpress Data To Xml\/csv 2025-06-20 7.2 High
The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly accessible directory without sufficiently validating the extracted file type. This may allows high privilege users such as administrator to upload an executable file type leading to remote code execution.
CVE-2023-6625 1 Gravitymaster 1 Product Enquiry For Woocommerce 2025-06-20 4.3 Medium
The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack
CVE-2024-0236 1 Myeventon 1 Eventon 2025-06-20 5.3 Medium
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
CVE-2024-0235 1 Myeventon 1 Eventon 2025-06-20 5.3 Medium
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
CVE-2024-0233 1 Myeventon 1 Eventon 2025-06-20 6.1 Medium
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2023-7084 1 Davidjmiller 1 Voting Record 2025-06-20 5.4 Medium
The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authenticated users, such as subscriber to perform Stored XSS attacks
CVE-2023-6741 1 Marvinlabs 1 Wp Customer Area 2025-06-20 4.3 Medium
The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.
CVE-2023-6592 1 Ninjateam 1 Fastdup 2025-06-20 5.3 Medium
The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.
CVE-2023-6005 1 Myeventon 1 Eventon 2025-06-20 4.8 Medium
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-6941 1 Keap 1 Official Opt-in Forms 2025-06-20 4.8 Medium
The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
CVE-2023-6620 1 Wpexperts 1 Post Smtp 2025-06-20 7.2 High
The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.
CVE-2023-5905 1 Demomentsomtres 1 Export Posts With Images 2025-06-20 8.1 High
The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected posts.
CVE-2023-4757 1 Miniorange 1 Staff \/ Employee Business Directory For Active Directory 2025-06-20 5.4 Medium
The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.
CVE-2023-4703 1 All In One B2b For Woocommerce Project 1 All In One B2b For Woocommerce 2025-06-20 7.5 High
The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.
CVE-2023-4536 1 Koalaapps 1 My Account Page Editor 2025-06-20 8.8 High
The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE
CVE-2023-3771 1 T1 Project 1 T1 2025-06-20 6.1 Medium
The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.
CVE-2023-3647 1 Indigitall 1 Iurny 2025-06-20 4.8 Medium
The IURNY by INDIGITALL WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2023-3372 1 Lana 1 Lana Shortcodes 2025-06-20 5.4 Medium
The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2023-0824 1 Wpuserplus 1 Userplus 2025-06-20 7.4 High
The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.