Search Results (20777 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-0603 1 Sloth Logo Customizer Project 1 Sloth Logo Customizer 2025-04-23 8.8 High
The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
CVE-2023-0329 1 Elementor 1 Website Builder 2025-04-23 7.2 High
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
CVE-2022-4827 1 Keetrax 1 Wp Tiles 2025-04-23 5.4 Medium
The WP Tiles WordPress plugin through 1.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2022-2311 1 Find And Replace All Project 1 Find And Replace All 2025-04-23 6.1 Medium
The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page before outputting them back to the user, leading to a Reflected Cross-Site Scripting issue.
CVE-2020-36656 1 Brainstormforce 1 Spectra 2025-04-23 5.4 Medium
The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.
CVE-2017-18591 1 Dev4press 1 Gd Rating System 2025-04-23 N/A
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
CVE-2024-10680 1 10web 1 Form Maker 2025-04-23 4.8 Medium
The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2022-3926 1 Wp-oauth 1 Wp Oauth Server 2025-04-23 6.5 Medium
The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID
CVE-2022-3249 1 Wp Csv Exporter Project 1 Wp Csv Exporter 2025-04-23 7.2 High
The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks
CVE-2022-3858 1 Premio 1 Chaty 2025-04-23 7.2 High
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin before 3.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin.
CVE-2022-3846 1 Amentotech 1 Workreap 2025-04-23 7.5 High
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable.
CVE-2022-3838 1 Wpupper Share Buttons Project 1 Wpupper Share Buttons 2025-04-23 4.8 Medium
The WPUpper Share Buttons WordPress plugin through 3.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2022-1540 1 Postmagthemes 1 Postmagthemes Demo Import 2025-04-23 7.2 High
The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE.
CVE-2023-4725 1 Sayandatta 1 Simple Posts Ticker 2025-04-23 4.8 Medium
The Simple Posts Ticker WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-3906 1 Whitestudio 1 Easy Form Builder 2025-04-22 4.8 Medium
The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-5307 1 Contest-gallery 1 Contest Gallery 2025-04-22 6.1 Medium
The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks via certain headers.
CVE-2023-5238 1 Metagauss 1 Eventprime 2025-04-22 6.1 Medium
The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the search area of the website.
CVE-2023-5237 1 Strangerstudios 1 Memberlite Shortcodes 2025-04-22 5.4 Medium
The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.
CVE-2023-5211 1 Fattura24 1 Fattura24 2025-04-22 6.1 Medium
The Fattura24 WordPress plugin before 6.2.8 does not sanitize or escape the 'id' parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting vulnerability.
CVE-2023-4251 1 Metagauss 1 Eventprime 2025-04-22 4.3 Medium
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.