CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2022-2658

    Last Modified: 4 Apr 2025

    The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 16 Jan 2023
    4.8
    Medium

    CVE-2022-4299

    Last Modified: 4 Apr 2025

    The Metricool WordPress plugin before 1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4431

    Last Modified: 4 Apr 2025

    The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    3.1
    Low

    CVE-2022-4309

    Last Modified: 7 Apr 2025

    The Subscribe2 WordPress plugin before 10.38 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete arbitrary users by knowing their email via a CSRF attack.

    Published: 16 Jan 2023
    6.1
    Medium

    CVE-2022-4295

    Last Modified: 8 Apr 2025

    The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4578

    Last Modified: 8 Apr 2025

    The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4484

    Last Modified: 8 Apr 2025

    The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    9.8
    Critical

    CVE-2022-4447

    Last Modified: 8 Apr 2025

    The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4451

    Last Modified: 4 Apr 2025

    The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    9.8
    Critical

    CVE-2022-4060

    Last Modified: 4 Apr 2025

    The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4544

    Last Modified: 4 Apr 2025

    The MashShare WordPress plugin before 3.8.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4483

    Last Modified: 4 Apr 2025

    The Insert Pages WordPress plugin before 3.7.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4460

    Last Modified: 4 Apr 2025

    The Sidebar Widgets by CodeLights WordPress plugin through 1.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4476

    Last Modified: 4 Apr 2025

    The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4477

    Last Modified: 4 Apr 2025

    The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4508

    Last Modified: 4 Apr 2025

    The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.

    Published: 16 Jan 2023
    4.3
    Medium

    CVE-2022-4549

    Last Modified: 4 Apr 2025

    The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4482

    Last Modified: 4 Apr 2025

    The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4478

    Last Modified: 7 Apr 2025

    The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4481

    Last Modified: 7 Apr 2025

    The Mesmerize Companion WordPress plugin before 1.6.135 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4655

    Last Modified: 4 Apr 2025

    The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4507

    Last Modified: 4 Apr 2025

    The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

    Published: 16 Jan 2023
    4.8
    Medium

    CVE-2022-4442

    Last Modified: 4 Apr 2025

    The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

    Published: 16 Jan 2023
    6.1
    Medium

    CVE-2022-4320

    Last Modified: 4 Apr 2025

    The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high-privilege ones like admin).

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4658

    Last Modified: 4 Apr 2025

    The RSSImport WordPress plugin through 4.6.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4571

    Last Modified: 4 Apr 2025

    The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    4.8
    Medium

    CVE-2022-4199

    Last Modified: 4 Apr 2025

    The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 16 Jan 2023
    7.2
    High

    CVE-2022-4547

    Last Modified: 4 Apr 2025

    The Conditional Payment Methods for WooCommerce WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by [high privilege users such as admin|users with a role as low as admin.

    Published: 16 Jan 2023
    9.1
    Critical

    CVE-2022-4101

    Last Modified: 4 Apr 2025

    The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4480

    Last Modified: 4 Apr 2025

    The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4464

    Last Modified: 8 Apr 2025

    Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privileged users such as admin.

    Published: 16 Jan 2023
    —
    Unknown

    CVE-2022-4327

    Last Modified: 7 Nov 2023

    This issue does not bear any security risk as it's only exploitable by users with administrator or super-administrator roles, who can already do what they want on their site.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4487

    Last Modified: 8 Apr 2025

    The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4653

    Last Modified: 10 Jun 2025

    The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4453

    Last Modified: 21 Nov 2024

    The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against high privilege users like administrators.

    Published: 16 Jan 2023
    6.1
    Medium

    CVE-2022-3904

    Last Modified: 8 Apr 2025

    The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4469

    Last Modified: 8 Apr 2025

    The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4486

    Last Modified: 7 Apr 2025

    The Meteor Slides WordPress plugin before 1.5.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    4.8
    Medium

    CVE-2022-4330

    Last Modified: 21 Nov 2024

    The WP Attachments WordPress plugin before 5.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4449

    Last Modified: 7 Apr 2025

    The Page scroll to id WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4465

    Last Modified: 7 Apr 2025

    The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

    Published: 16 Jan 2023
    5.4
    Medium

    CVE-2022-4648

    Last Modified: 7 Apr 2025

    The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

    Published: 16 Jan 2023
    7.3
    High

    CVE-2023-0324

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-218426 is the identifier assigned to this vulnerability.

    Published: 16 Jan 2023
    6.3
    Medium

    CVE-2022-4890

    Last Modified: 7 Apr 2025

    A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The patch is named b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387.

    Published: 16 Jan 2023
    5.5
    Medium

    CVE-2021-4313

    Last Modified: 21 Nov 2024

    A vulnerability was found in NethServer phonenehome. It has been rated as critical. This issue affects the function get_info/get_country_coor of the file server/index.php. The manipulation leads to sql injection. The identifier of the patch is 759c30b0ddd7d493836bbdf695cf71624b377391. It is recommended to apply a patch to fix this issue. The identifier VDB-218393 was assigned to this vulnerability.

    Published: 16 Jan 2023
    5.5
    Medium

    CVE-2018-25076

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Events Extension on BigTree. Affected by this vulnerability is the function getRandomFeaturedEventByDate/getUpcomingFeaturedEventsInCategoriesWithSubcategories/recacheEvent/searchResults of the file classes/events.php. The manipulation leads to sql injection. The patch is named 11169e48ab1249109485fdb1e0c9fca3d25ba01d. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218395.

    Published: 16 Jan 2023
    5.5
    Medium

    CVE-2015-10053

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in prodigasistemas curupira up to 0.1.3. Affected is an unknown function of the file app/controllers/curupira/passwords_controller.rb. The manipulation leads to sql injection. Upgrading to version 0.1.4 is able to address this issue. The patch is identified as 93a9a77896bb66c949acb8e64bceafc74bc8c271. It is recommended to upgrade the affected component. VDB-218394 is the identifier assigned to this vulnerability.

    Published: 16 Jan 2023
    —
    Unknown

    CVE-2010-10005

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: It is a duplicate of CVE-2010-2799.

    Published: 16 Jan 2023
    5.5
    Medium

    CVE-2016-15020

    Last Modified: 21 Nov 2024

    A vulnerability was found in liftkit database up to 2.13.1. It has been classified as critical. This affects the function processOrderBy of the file src/Query/Query.php. The manipulation leads to sql injection. Upgrading to version 2.13.2 is able to address this issue. The patch is named 42ec8f2b22e0b0b98fb5b4444ed451c1b21d125a. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-218391.

    Published: 16 Jan 2023
    5.5
    Medium

    CVE-2013-10012

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in antonbolling clan7ups. Affected is an unknown function of the component Login/Session. The manipulation leads to sql injection. The name of the patch is 25afad571c488291033958d845830ba0a1710764. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218388.

    Published: 16 Jan 2023