| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-46201 | WordPress Auto Login New User After Registration Plugin <= 1.9.6 is vulnerable to Cross Site Request Forgery (CSRF) | Jeff Sherk | Auto Login New User After Registration | High | 7.1 | 2023-11-13 04:09:16 | Deep Dive |
| CVE-2023-34025 | WordPress LWS Hide Login plugin <= 2.1.6 - Cross Site Request Forgery (CSRF) vulnerability | Aurélien LWS | LWS Hide Login | Medium | 5.4 | 2023-11-09 20:29:08 | Deep Dive |
| CVE-2023-46777 | WordPress Feather Login Page plugin <= 1.1.3 - Cross Site Request Forgery (CSRF) vulnerability | PluginOps | Feather Login Page | Medium | 5.4 | 2023-11-06 11:06:58 | Deep Dive |
| CVE-2023-47182 | WordPress Login Screen Manager Plugin <= 3.5.2 is vulnerable to Cross Site Scripting (XSS) | Nazmul Hossain Nihal | Login Screen Manager | 中危 | - | 2023-11-06 09:52:49 | Deep Dive |
| CVE-2023-5243 | Login screen manager <= 3.5.2 - Admin+ Stored XSS | Unknown | Login Screen Manager | 中危 | - | 2023-10-31 13:54:43 | Deep Dive |
| CVE-2023-46202 | WordPress Auto Login New User After Registration Plugin <= 1.9.6 is vulnerable to Cross Site Request Forgery (CSRF) | Jeff Sherk | Auto Login New User After Registration | Medium | 4.3 | 2023-10-24 10:51:02 | Deep Dive |
| CVE-2022-4943 | miniOrange's Google Authenticator <= 5.6.5 - Missing Authorization to Plugin Settings Change | cyberlord92 | miniOrange 2FA – Two-Factor Authentication for WordPress (SMS, Email & Google Authenticator) | High | 7.5 | 2023-10-20 07:29:21 | Deep Dive |
| CVE-2023-44995 | WordPress WooCommerce Login Redirect Plugin <= 2.2.4 is vulnerable to Cross Site Request Forgery (CSRF) | WP Doctor | WooCommerce Login Redirect | Medium | 5.4 | 2023-10-10 15:46:49 | Deep Dive |
| CVE-2023-4916 | Login with phone number <= 1.5.6 - Cross-Site Request Forgery to User Password Change | glboy | OTP Login With Phone Number, OTP Verification | High | 8.8 | 2023-09-13 02:54:12 | Deep Dive |
| CVE-2023-41936 | Jenkins Plugin Google Login 安全漏洞 | Jenkins Project | Jenkins Google Login Plugin | 高危 | - | 2023-09-06 12:08:56 | Deep Dive |
| CVE-2023-40329 | WordPress Custom Admin Login Page | WPZest Plugin <= 1.2.0 is vulnerable to Cross Site Scripting (XSS) | WPZest | Custom Admin Login Page | WPZest | Medium | 5.9 | 2023-09-06 08:24:14 | Deep Dive |
| CVE-2023-4773 | WordPress Social Login <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | miled | WordPress Social Login | Medium | 6.4 | 2023-09-06 03:28:20 | Deep Dive |
| CVE-2023-38476 | WordPress Client Portal : SuiteDash Direct Login Plugin <= 1.7.6 is vulnerable to Cross Site Scripting (XSS) | SuiteDash :: ONE Dashboard® | Client Portal : SuiteDash Direct Login | Medium | 5.9 | 2023-09-03 11:43:04 | Deep Dive |
| CVE-2023-37986 | WordPress YourMembership Single Sign On Plugin <= 1.1.3 is vulnerable to Cross Site Scripting (XSS) | miniOrange | YourMembership Single Sign On – YM SSO Login | Medium | 5.9 | 2023-09-01 11:09:08 | Deep Dive |
| CVE-2023-34023 | WordPress WordPress Social Login Plugin <= 3.0.4 is vulnerable to Cross Site Scripting (XSS) | Miled | WordPress Social Login | High | 7.1 | 2023-08-30 14:25:03 | Deep Dive |
| CVE-2023-34172 | WordPress WordPress Social Login Plugin <= 3.0.4 is vulnerable to Cross Site Scripting (XSS) | Miled | WordPress Social Login | Medium | 5.9 | 2023-08-30 14:12:47 | Deep Dive |
| CVE-2023-34175 | WordPress Login Configurator Plugin <= 2.1 is vulnerable to Cross Site Scripting (XSS) | GrandSlambert | Login Configurator | High | 7.1 | 2023-08-30 13:39:26 | Deep Dive |
| CVE-2023-32505 | WordPress Easy Hide Login Plugin <= 1.0.7 is vulnerable to Cross Site Scripting (XSS) | Arshid | Easy Hide Login | Medium | 5.9 | 2023-08-23 14:22:41 | Deep Dive |
| CVE-2023-3604 | Change WP Admin < 1.1.4 - Secret Login Page Disclosure | Unknown | Change WP Admin Login | 高危 | - | 2023-08-21 12:29:51 | Deep Dive |
| CVE-2023-34369 | WordPress Login Configurator Plugin <= 2.1 is vulnerable to Cross Site Scripting (XSS) | GrandSlambert | Login Configurator | Medium | 5.9 | 2023-07-25 13:02:01 | Deep Dive |