CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-30310

    Last Modified: 21 Nov 2024

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

    Published: 13 Jun 2022
    9.8
    Critical

    CVE-2022-30309

    Last Modified: 21 Nov 2024

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

    Published: 13 Jun 2022
    9.8
    Critical

    CVE-2022-30308

    Last Modified: 21 Nov 2024

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

    Published: 13 Jun 2022
    7.8
    High

    CVE-2022-24077

    Last Modified: 21 Nov 2024

    Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.

    Published: 13 Jun 2022
    5.5
    Medium

    CVE-2022-1750

    Last Modified: 8 Apr 2026

    The Sticky Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ popup_title' parameter in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin level capabilities and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This issue mostly affects sites where unfiltered_html has been disabled for administrators and on multi-site installations where unfiltered_html is disabled for administrators.

    Published: 13 Jun 2022
    5.4
    Medium

    CVE-2022-1659

    Last Modified: 31 Jan 2025

    Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which can be used to call any function in the includes/condition/class-condition-manager.php file by sending the desired function to call in the sub_action parameter. This can be used to view site configuration and logged-in users, modify post conditions, or perform a denial of service attack.

    Published: 13 Jun 2022
    8.8
    High

    CVE-2022-1654

    Last Modified: 31 Jan 2025

    Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or customer-level attacker, to gain administrative privileges via the "abb_uninstall_template" (both) and "jupiterx_core_cp_uninstall_template" (JupiterX Core Only) AJAX actions

    Published: 13 Jun 2022
    8.8
    High

    CVE-2022-1969

    Last Modified: 8 Apr 2026

    The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the admin_update_data() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 13 Jun 2022
    5.4
    Medium

    CVE-2022-1658

    Last Modified: 31 Jan 2025

    Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using this functionality, any logged-in user can delete any installed plugin on the site.

    Published: 13 Jun 2022
    8.8
    High

    CVE-2022-1749

    Last Modified: 8 Apr 2026

    The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting_page() function found in the ~/inc/config/create-plugin-config.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.

    Published: 13 Jun 2022
    5.5
    Medium

    CVE-2022-1961

    Last Modified: 8 Apr 2026

    The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~/public/frontend.php` file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

    Published: 13 Jun 2022
    4.8
    Medium

    CVE-2022-0209

    Last Modified: 31 Jan 2025

    The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 13 Jun 2022
    6.1
    Medium

    CVE-2022-1820

    Last Modified: 8 Apr 2026

    The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 13 Jun 2022
    9.8
    Critical

    CVE-2022-1768

    Last Modified: 8 Apr 2026

    The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

    Published: 13 Jun 2022
    8.8
    High

    CVE-2022-1657

    Last Modified: 13 Feb 2025

    Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscriber-level users, to perform Path Traversal and Local File inclusion. In the JupiterX theme, the jupiterx_cp_load_pane_action AJAX action present in the lib/admin/control-panel/control-panel.php file calls the load_control_panel_pane function. It is possible to use this action to include any local PHP file via the slug parameter. The Jupiter theme has a nearly identical vulnerability which can be exploited via the mka_cp_load_pane_action AJAX action present in the framework/admin/control-panel/logic/functions.php file, which calls the mka_cp_load_pane_action function.

    Published: 13 Jun 2022
    4.8
    Medium

    CVE-2022-31400

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.

    Published: 13 Jun 2022
    4.8
    Medium

    CVE-2022-31398

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.

    Published: 13 Jun 2022
    8.8
    High

    CVE-2022-1900

    Last Modified: 8 Apr 2026

    The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. This is due to missing nonce validation on the CopifySettings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 13 Jun 2022
    8.8
    High

    CVE-2022-1918

    Last Modified: 8 Apr 2026

    The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0. This is due to missing nonce validation on the plugin_toolbar_comparte page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 13 Jun 2022
    6.1
    Medium

    CVE-2022-1707

    Last Modified: 8 Apr 2026

    The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to an including 1.15. The affected file is ~/public/frontend.php and this could be exploited by unauthenticated attackers.

    Published: 13 Jun 2022
    6.1
    Medium

    CVE-2022-1985

    Last Modified: 8 Apr 2026

    The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.

    Published: 13 Jun 2022
    6.4
    Medium

    CVE-2022-1208

    Last Modified: 8 Apr 2026

    The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allows users to encode malicious web scripts with HTML encoding that is reflected back on the page. This affects versions up to, and including, 2.3.2. Please note this issue was only partially fixed in version 2.3.2.

    Published: 13 Jun 2022
    4.8
    Medium

    CVE-2022-1814

    Last Modified: 21 Nov 2024

    The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

    Published: 13 Jun 2022
    7.2
    High

    CVE-2022-1800

    Last Modified: 21 Nov 2024

    The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.

    Published: 13 Jun 2022
    4.3
    Medium

    CVE-2022-1793

    Last Modified: 21 Nov 2024

    The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow attackers to make a logged in admin perform such action via a CSRF attack and make the blog public

    Published: 13 Jun 2022
    5.4
    Medium

    CVE-2022-1792

    Last Modified: 21 Nov 2024

    The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them

    Published: 13 Jun 2022
    8.1
    High

    CVE-2022-1791

    Last Modified: 21 Nov 2024

    The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check.

    Published: 13 Jun 2022
    6.5
    Medium

    CVE-2022-1790

    Last Modified: 21 Nov 2024

    The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 13 Jun 2022
    6.5
    Medium

    CVE-2022-1788

    Last Modified: 21 Nov 2024

    Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.

    Published: 13 Jun 2022
    5.4
    Medium

    CVE-2022-1787

    Last Modified: 21 Nov 2024

    The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

    Published: 13 Jun 2022
    5.4
    Medium

    CVE-2022-1781

    Last Modified: 21 Nov 2024

    The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

    Published: 13 Jun 2022
    5.4
    Medium

    CVE-2022-1780

    Last Modified: 21 Nov 2024

    The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack which could also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

    Published: 13 Jun 2022
    8.1
    High

    CVE-2022-1779

    Last Modified: 21 Nov 2024

    The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific posts, categories and attachments at once.

    Published: 13 Jun 2022
    8.8
    High

    CVE-2022-1777

    Last Modified: 21 Nov 2024

    The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticated users, such as subscriber. They are are protected with a nonce, however the nonce is leaked on the dashboard. This could allow them to upload arbitrary HTML files as well as delete all files or arbitrary ones.

    Published: 13 Jun 2022
    6.1
    Medium

    CVE-2022-1773

    Last Modified: 21 Nov 2024

    The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 13 Jun 2022
    4.8
    Medium

    CVE-2022-1772

    Last Modified: 21 Nov 2024

    The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.

    Published: 13 Jun 2022
    8.8
    High

    CVE-2022-1765

    Last Modified: 21 Nov 2024

    The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations or licensing rules).

    Published: 13 Jun 2022
    5.4
    Medium

    CVE-2022-1764

    Last Modified: 21 Nov 2024

    The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

    Published: 13 Jun 2022
    5.4
    Medium

    CVE-2022-1763

    Last Modified: 21 Nov 2024

    Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-1762

    Last Modified: 21 Nov 2024

    The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.

    Published: 13 Jun 2022
    6.5
    Medium

    CVE-2022-1761

    Last Modified: 21 Nov 2024

    The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more.

    Published: 13 Jun 2022
    5.4
    Medium

    CVE-2022-1759

    Last Modified: 21 Nov 2024

    The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform Stored Cross-Site Scripting attacks due to the lack of sanitisation and escaping

    Published: 13 Jun 2022
    8.8
    High

    CVE-2022-1758

    Last Modified: 21 Nov 2024

    The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS as well as RCE when custom code is added via the plugin settings.

    Published: 13 Jun 2022
    6.1
    Medium

    CVE-2022-1756

    Last Modified: 21 Nov 2024

    The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.

    Published: 13 Jun 2022
    6.1
    Medium

    CVE-2022-1724

    Last Modified: 21 Nov 2024

    The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting

    Published: 13 Jun 2022
    4.8
    Medium

    CVE-2022-1710

    Last Modified: 21 Nov 2024

    The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

    Published: 13 Jun 2022
    6.5
    Medium

    CVE-2022-1694

    Last Modified: 21 Nov 2024

    The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin by submitting a form.

    Published: 13 Jun 2022
    6.5
    Medium

    CVE-2022-1624

    Last Modified: 21 Nov 2024

    The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 13 Jun 2022
    6.5
    Medium

    CVE-2022-1612

    Last Modified: 21 Nov 2024

    The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 13 Jun 2022
    6.5
    Medium

    CVE-2022-1608

    Last Modified: 21 Nov 2024

    The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 13 Jun 2022