| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-2711 | WP All Import < 3.6.9 - Admin+ Directory traversal via file upload | Unknown | Import any XML or CSV File to WordPress | 高危 | - | 2022-11-07 00:00:00 | Deep Dive |
| CVE-2022-3418 | WP All Import < 3.6.9 - Admin+ Arbitrary File Upload to RCE | Unknown | Import any XML or CSV File to WordPress | 高危 | - | 2022-11-07 00:00:00 | Deep Dive |
| CVE-2022-3463 | FluentForm < 4.3.13 - CSV Injection | Unknown | Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms | 超危 | - | 2022-11-07 00:00:00 | Deep Dive |
| CVE-2022-25952 | WordPress Content Egg plugin <= 5.4.0 - Cross-Site Request Forgery (CSRF) vulnerability | Keywordrush | Content Egg (WordPress plugin) | Medium | 4.3 | 2022-11-03 19:35:05 | Deep Dive |
| CVE-2021-36906 | WordPress Quiz And Survey Master plugin <= 7.3.6 - Multiple Insecure direct object references (IDOR) vulnerabilities | ExpressTech | Quiz And Survey Master (WordPress plugin) | Low | 2.7 | 2022-11-03 19:33:46 | Deep Dive |
| CVE-2022-44628 | WordPress 4ECPS Web Forms plugin <= 0.2.17 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | JumpDEMAND Inc. | 4ECPS Web Forms (WordPress plugin) | Medium | 5.9 | 2022-11-03 19:32:26 | Deep Dive |
| CVE-2022-44627 | WordPress Simple SEO plugin <= 1.8.12 - Cross-Site Request Forgery (CSRF) vulnerability | David Cole | Simple SEO (WordPress plugin) | Medium | 5.4 | 2022-11-03 19:30:58 | Deep Dive |
| CVE-2022-36404 | WordPress Simple SEO plugin <= 1.8.12 - Broken Access Control vulnerability | David Cole | Simple SEO (WordPress plugin) | Medium | 5.4 | 2022-11-03 19:27:39 | Deep Dive |
| CVE-2022-40131 | WordPress Page View Count plugin <= 2.5.5 - Cross-Site Request Forgery (CSRF) vulnerability | a3rev Software | Page View Count (WordPress plugin) | Medium | 5.4 | 2022-11-03 19:26:22 | Deep Dive |
| CVE-2022-36428 | WordPress Rock Convert plugin <= 2.11.0 - Auth. Cross-Site Scripting (XSS) vulnerability | Stage | Rock Convert (WordPress plugin) | Medium | 4.8 | 2022-11-03 19:22:18 | Deep Dive |
| CVE-2022-44586 | WordPress AM-HiLi plugin <= 1.0 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | Ayoub Media | AM-HiLi (WordPress plugin) | Medium | 4.8 | 2022-11-02 21:13:33 | Deep Dive |
| CVE-2022-44576 | WordPress AgentEasy Properties plugin <= 1.0.4 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | AgentEasy | AgentEasy Properties (WordPress plugin) | Medium | 4.8 | 2022-11-02 21:05:56 | Deep Dive |
| CVE-2022-2190 | Envira Gallery Lite < 1.8.4.7 - Reflected Cross-Site Scripting | Unknown | Gallery Plugin for WordPress – Envira Photo Gallery | 中危 | - | 2022-10-31 00:00:00 | Deep Dive |
| CVE-2022-3254 | AWP Classifieds Plugin < 4.3 - Unauthenticated SQLi | Unknown | WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds | 超危 | - | 2022-10-31 00:00:00 | Deep Dive |
| CVE-2022-3360 | LearnPress < 4.1.7.2 - Unauthenticated PHP Object Injection via REST API | Unknown | LearnPress – WordPress LMS Plugin | 高危 | - | 2022-10-31 00:00:00 | Deep Dive |
| CVE-2021-36898 | WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. SQL Injection (SQLi) vulnerability | ExpressTech | Quiz And Survey Master (WordPress plugin) | High | 7.5 | 2022-10-28 17:07:26 | Deep Dive |
| CVE-2021-36864 | WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. Reflected Cross-Site Scripting (XSS) vulnerability | ExpressTech | Quiz And Survey Master (WordPress plugin) | Low | 3.4 | 2022-10-28 17:05:30 | Deep Dive |
| CVE-2021-36863 | WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | ExpressTech | Quiz And Survey Master (WordPress plugin) | Medium | 5.4 | 2022-10-28 15:11:16 | Deep Dive |
| CVE-2021-36858 | WordPress Testimonials plugin <= 2.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | Themepoints | Testimonials (WordPress plugin) | Medium | 4.8 | 2022-10-28 15:09:34 | Deep Dive |
| CVE-2022-41996 | WordPress Avada premium theme <= 7.8.1 - Cross-Site Request Forgery (CSRF) vulnerability | ThemeFusion | Avada (premium WordPress theme) | High | 8.8 | 2022-10-27 16:51:43 | Deep Dive |