Search Results (20792 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-2605 1 Wp Brutal Ai Project 1 Wp Brutal Ai 2025-02-13 6.1 Medium
The wpbrutalai WordPress plugin before 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.
CVE-2023-2601 1 Wp Brutal Ai Project 1 Wp Brutal Ai 2025-02-13 9.8 Critical
The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin via CSRF.
CVE-2023-2224 1 10web 1 Seo 2025-02-13 4.8 Medium
The SEO by 10Web WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-2223 1 12net 1 Login Rebuilder 2025-02-13 4.8 Medium
The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-2068 1 Advancedfilemanager 1 File Manager Advanced Shortcode 2025-02-13 9.8 Critical
The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.
CVE-2023-2029 1 Enzipe 1 Prepost Seo 2025-02-13 4.8 Medium
The PrePost SEO WordPress plugin through 3.0 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2023-1893 1 Login Configurator Project 1 Login Configurator 2025-02-13 6.1 Medium
The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.
CVE-2023-1890 1 Pauple 1 Tablesome 2025-02-13 6.1 Medium
The Tablesome WordPress plugin before 1.0.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting
CVE-2023-0099 1 Getlasso 1 Simple Urls 2025-02-13 6.1 Medium
The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2011-4595 1 Caseproof 1 Prettylinks 2025-02-13 6.1 Medium
Pretty-Link WordPress plugin 1.5.2 has XSS
CVE-2015-9457 1 Caseproof 1 Prettylinks 2025-02-13 7.2 High
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.
CVE-2023-1426 1 Keetrax 1 Wp Tiles 2025-02-11 6.5 Medium
The WP Tiles WordPress plugin through 1.1.2 does not ensure that posts to be displayed are not draft/private, allowing any authenticated users, such as subscriber to retrieve the titles of draft and privates posts for example. AN attacker could also retrieve the title of any other type of post.
CVE-2023-1425 1 Groundhogg 1 Groundhogg 2025-02-11 7.2 High
The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins
CVE-2023-1406 1 Crocoblock 1 Jetengine For Elementor 2025-02-11 8.8 High
The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.
CVE-2023-1121 1 Ibenic 1 Simple Giveaways 2025-02-11 4.8 Medium
The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2023-1120 1 Ibenic 1 Simple Giveaways 2025-02-11 4.8 Medium
The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2023-0983 1 Stylishcostcalculator 1 Stylish Cost Calculator 2025-02-11 6.1 Medium
The stylish-cost-calculator-premium WordPress plugin before 7.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Stored Cross-Site Scripting which could be used against admins when viewing submissions submitted through the Email Quote Form.
CVE-2023-0874 1 Klaviyo 1 Klavio 2025-02-11 4.8 Medium
The Klaviyo WordPress plugin before 3.0.10 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-0605 1 Auto Rename Media On Upload Project 1 Auto Rename Media On Upload 2025-02-11 4.8 Medium
The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-0423 1 Wordpress Amazon S3 Project 1 Wordpress Amazon S3 2025-02-11 4.8 Medium
The WordPress Amazon S3 Plugin WordPress plugin before 1.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin