| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-47808 | WordPress Add Widgets to Page Plugin <= 1.3.2 is vulnerable to Cross Site Scripting (XSS) | Christina Uechi | Add Widgets to Page | Medium | 6.5 | 2023-11-22 22:12:23 | Deep Dive |
| CVE-2023-47651 | WordPress WP Links Page Plugin <= 4.9.4 is vulnerable to Cross Site Request Forgery (CSRF) | Robert Macchi | WP Links Page | Medium | 4.3 | 2023-11-18 21:17:10 | Deep Dive |
| CVE-2023-47757 | WordPress AWeber Plugin <= 7.3.9 is vulnerable to Broken Access Control | AWeber | AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth | Medium | 4.3 | 2023-11-17 08:52:19 | Deep Dive |
| CVE-2023-27623 | WordPress WP Page Numbers Plugin <= 0.5 is vulnerable to Cross Site Request Forgery (CSRF) | Jens Törnell | WP Page Numbers | Medium | 5.4 | 2023-11-12 22:43:48 | Deep Dive |
| CVE-2023-31077 | WordPress Export WP Page to Static HTML/CSS Plugin <= 2.1.9 is vulnerable to Cross Site Request Forgery (CSRF) | ReCorp | Export WP Page to Static HTML/CSS | 高危 | - | 2023-11-10 13:36:15 | Deep Dive |
| CVE-2023-4888 | Simple Like Page Plugin <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | topdevs | Simple Like Page Plugin – Fast & Privacy-Friendly Page Embeds | Medium | 6.4 | 2023-11-07 11:31:10 | Deep Dive |
| CVE-2023-46777 | WordPress Feather Login Page Plugin <= 1.1.3 is vulnerable to Cross Site Request Forgery (CSRF) | - | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | Medium | 5.4 | 2023-11-06 11:06:58 | Deep Dive |
| CVE-2023-45074 | WordPress Advanced Page Visit Counter Plugin <= 7.1.1 is vulnerable to SQL Injection | Page Visit Counter | Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress | 超危 | - | 2023-11-06 08:35:03 | Deep Dive |
| CVE-2022-46849 | WordPress Coming Soon Plugin <= 1.5.9 is vulnerable to SQL Injection | Weblizar | Coming Soon Page – Responsive Coming Soon & Maintenance Mode | 超危 | - | 2023-11-06 07:56:31 | Deep Dive |
| CVE-2023-33927 | WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.19 is vulnerable to SQL Injection | Themeisle | Multiple Page Generator Plugin – MPG | High | 7.6 | 2023-10-31 14:12:52 | Deep Dive |
| CVE-2023-5199 | PHP to Page <= 0.3 - Authenticated (Subscriber+) Local File Inclusion to Remote Code Execution via Shortcode | bloafer | PHP to Page | Critical | 9.9 | 2023-10-30 13:48:59 | Deep Dive |
| CVE-2023-46211 | WordPress Ultimate Addons for WPBakery Page Builder Plugin <= 3.19.14 is vulnerable to Cross Site Scripting (XSS) | Brainstorm Force | Ultimate Addons for WPBakery Page Builder | Medium | 6.5 | 2023-10-27 20:22:57 | Deep Dive |
| CVE-2023-45768 | WordPress Next Page Plugin <= 1.5.2 is vulnerable to Cross Site Scripting (XSS) | Stephanie Leary | Next Page | Medium | 5.9 | 2023-10-24 12:04:53 | Deep Dive |
| CVE-2023-4386 | Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via queries | wpdevteam | Essential Blocks Pro | High | 8.1 | 2023-10-20 07:29:28 | Deep Dive |
| CVE-2020-36714 | Brizy < 1.0.126 - Authorization Bypass to Settings Updates | themefusecom | Brizy – Page Builder | High | 7.4 | 2023-10-20 07:29:24 | Deep Dive |
| CVE-2023-4975 | Website Builder by SeedProd <= 6.15.13.1 - Cross-Site Request Forgery to Settings Update | seedprod | Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode | Medium | 4.3 | 2023-10-20 06:35:13 | Deep Dive |
| CVE-2023-4402 | Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via products | wpdevteam | Essential Blocks Pro | High | 8.1 | 2023-10-20 06:35:11 | Deep Dive |
| CVE-2023-4687 | PageLayer < 1.7.7 - Unauthenticated Stored XSS | Unknown | Page Builder: Pagelayer | 中危 | - | 2023-10-16 19:39:03 | Deep Dive |
| CVE-2023-5087 | PageLayer < 1.7.8 - Author+ Stored XSS | Unknown | Page Builder: Pagelayer | 中危 | - | 2023-10-16 19:38:57 | Deep Dive |
| CVE-2023-46087 | WordPress Who Hit The Page – Hit Counter Plugin <= 1.4.14.3 is vulnerable to Cross Site Request Forgery (CSRF) | Mahlamusa | Who Hit The Page – Hit Counter | Medium | 4.3 | 2023-10-16 14:28:09 | Deep Dive |