Search Results (20818 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-1938 1 Wpfastestcache 1 Wp Fastest Cache 2025-01-10 8.8 High
The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate user input before using it in the wp_remote_get() function, leading to a Blind SSRF issue
CVE-2023-0766 1 Newsletter Popup Project 1 Newsletter Popup 2025-01-10 8.8 High
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks as the wp_newsletter_show_localrecord page is not protected with a nonce.
CVE-2023-0733 1 Newsletter Popup Project 1 Newsletter Popup 2025-01-10 6.1 Medium
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks
CVE-2023-0443 1 Wpvibes 1 Anywhere Elementor 2025-01-10 5.3 Medium
The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.
CVE-2022-30705 1 Wordpress Ping Optimizer Project 1 Wordpress Ping Optimizer 2025-01-10 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Pankaj Jha WordPress Ping Optimizer plugin <= 2.35.1.2.3 versions.
CVE-2022-47146 1 Contempothemes 1 Real Estate 7 2025-01-10 7.1 High
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions.
CVE-2023-2470 1 Add To Feedly Project 1 Add To Feedly 2025-01-10 4.8 Medium
The Add to Feedly WordPress plugin through 1.2.11 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2023-2296 1 Loginizer 1 Loginizer 2025-01-10 6.1 Medium
The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2023-2256 1 Themeisle 1 Product Addons \& Fields For Woocommerce 2025-01-10 6.1 Medium
The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.
CVE-2023-2111 1 Groundhogg 1 Hollerbox 2025-01-10 4.9 Medium
The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL query without escaping it first in the plugin's report API endpoint, which could allow administrators in multi-site configuration to leak sensitive information from the site's database.
CVE-2022-4676 1 Openstreetmap 1 Openstreetmap 2025-01-09 5.4 Medium
The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
CVE-2023-2023 1 Kunalnagar 1 Custom 404 Pro 2025-01-09 6.1 Medium
The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
CVE-2022-45846 1 Wpmart 1 Interactive Svg Image Map Builder 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro for WordPress - Interactive SVG Image Map Builder plugin < 5.6.9 versions.
CVE-2022-47615 1 Thimpress 1 Learnpress 2025-01-08 9.3 Critical
Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CVE-2022-45808 1 Thimpress 1 Learnpress 2025-01-08 9.9 Critical
SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CVE-2023-23706 1 Miniorange 1 Wordpress Social Login And Register \(discord\, Google\, Twitter\, Linkedin\) 2025-01-08 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
CVE-2023-23705 1 Hmplugin 1 Wordpress Books Gallery 2025-01-08 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin WordPress Books Gallery plugin <= 4.4.8 versions.
CVE-2022-47446 1 Viadat 1 Store Locator For Wordpress With Google Maps 2025-01-08 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions.
CVE-2022-47447 1 Internet-formation 1 Wp-advanced-search 2025-01-08 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8 versions.
CVE-2022-47161 1 Wordpress 1 Health Check \& Troubleshooting 2025-01-08 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.