| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-32588 | WordPress Post State Tags Plugin <= 2.0.6 is vulnerable to Cross Site Request Forgery (CSRF) | BRANDbrilliance | Post State Tags | Medium | 4.3 | 2023-11-13 01:14:37 | Deep Dive |
| CVE-2023-34378 | WordPress WP Hide Post Plugin <= 2.0.10 is vulnerable to Cross Site Request Forgery (CSRF) | scriptburn.com | WP Hide Post | Medium | 4.3 | 2023-11-13 01:02:32 | Deep Dive |
| CVE-2023-34171 | WordPress WP Report Post Plugin <= 2.1.2 is vulnerable to Cross Site Request Forgery (CSRF) | Alex Raven | WP Report Post | 中危 | - | 2023-11-09 19:22:26 | Deep Dive |
| CVE-2023-47226 | WordPress Post Sliders & Post Grids Plugin <= 1.0.20 is vulnerable to Cross Site Scripting (XSS) | I Thirteen Web Solution | Post Sliders & Post Grids | 中危 | - | 2023-11-08 18:33:43 | Deep Dive |
| CVE-2023-36527 | WordPress Post to CSV by BestWebSoft Plugin <= 1.4.0 is vulnerable to CSV Injection | BestWebSoft | Post to CSV by BestWebSoft | 高危 | - | 2023-11-07 16:04:27 | Deep Dive |
| CVE-2023-46781 | WordPress Current Menu Item for Custom Post Types Plugin <= 1.5 is vulnerable to Cross Site Request Forgery (CSRF) | Roland Murg | Current Menu Item for Custom Post Types | 中危 | - | 2023-11-06 11:19:15 | Deep Dive |
| CVE-2023-5362 | Carousel, Recent Post Slider and Banner Slider <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | spicethemes | Carousel, Recent Post Slider and Banner Slider | Medium | 6.4 | 2023-10-30 13:49:02 | Deep Dive |
| CVE-2023-5425 | Post Meta Data Manager <=1.2.0 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation | gandhihitesh9 | Post Meta Data Manager | High | 8.8 | 2023-10-28 11:06:04 | Deep Dive |
| CVE-2023-5426 | Post Meta Data Manager <=1.2.0 - Missing Authorization to User, Term, and Post Meta Deletion | gandhihitesh9 | Post Meta Data Manager | High | 7.5 | 2023-10-28 11:06:04 | Deep Dive |
| CVE-2023-32116 | WordPress Custom post types Plugin <= 4.0.12 is vulnerable to Cross Site Scripting (XSS) | TotalPress.org | Custom post types, Custom Fields & more | Medium | 5.9 | 2023-10-26 12:15:28 | Deep Dive |
| CVE-2023-45769 | WordPress WP Report Post Plugin <= 2.1.2 is vulnerable to Cross Site Scripting (XSS) | Alex Raven | WP Report Post | High | 7.1 | 2023-10-24 12:08:06 | Deep Dive |
| CVE-2023-45764 | WordPress Scroll post excerpt Plugin <= 8.0 is vulnerable to Cross Site Scripting (XSS) | Gopi Ramasamy | Scroll post excerpt | Medium | 5.9 | 2023-10-24 11:58:06 | Deep Dive |
| CVE-2022-3622 | Blog2Social <= 6.9.11 - Missing Authorization to Authenticated (Subscriber+) Settings Update | pr-gateway | Blog2Social: Social Media Auto Post & Scheduler | Medium | 4.1 | 2023-10-20 07:29:40 | Deep Dive |
| CVE-2020-36758 | RSS Aggregator by Feedzy <= 3.4.2 - Cross-Site Request Forgery Bypass | themeisle | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | Medium | 4.3 | 2023-10-20 07:29:37 | Deep Dive |
| CVE-2023-45752 | WordPress Post Gallery Plugin <= 2.3.12 is vulnerable to Cross Site Request Forgery (CSRF) | 10 Quality | Post Gallery | Medium | 4.3 | 2023-10-16 10:06:58 | Deep Dive |
| CVE-2023-44996 | WordPress Post View Count Plugin <= 1.8.2 is vulnerable to Cross Site Request Forgery (CSRF) | Naresh Parmar | Post View Count | Medium | 5.4 | 2023-10-10 15:50:18 | Deep Dive |
| CVE-2023-41851 | WordPress WP Custom Post Template Plugin <= 1.0 is vulnerable to Cross Site Request Forgery (CSRF) | Dotsquares | WP Custom Post Template | Medium | 4.3 | 2023-10-10 08:29:52 | Deep Dive |
| CVE-2023-44238 | WordPress Remove slug from custom post type Plugin <= 1.0.3 is vulnerable to Cross Site Request Forgery (CSRF) | Joakim Ling | Remove slug from custom post type | Medium | 4.3 | 2023-10-09 09:57:11 | Deep Dive |
| CVE-2023-25480 | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.24.1 is vulnerable to Cross Site Request Forgery (CSRF) | BoldGrid | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor | Medium | 4.3 | 2023-10-06 12:41:33 | Deep Dive |
| CVE-2023-5291 | Blog Filter <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | awordpresslife | Blog Filter Post Filtering | Medium | 6.4 | 2023-10-04 01:52:40 | Deep Dive |