| CVE-2022-45073 | WordPress REST API Authentication plugin <= 2.4.0 - Cross-Site Request Forgery (CSRF) vulnerability | miniOrange | WordPress REST API Authentication (WordPress plugin) | Medium | 5.4 | 2022-11-18 21:42:34 | Deep Dive |
| CVE-2022-42461 | WordPress miniOrange's Google Authenticator plugin <= 5.6.1 - Broken Access Control vulnerability | miniOrange | miniOrange's Google Authenticator (WordPress plugin) | Medium | 5.4 | 2022-11-18 19:06:13 | Deep Dive |
| CVE-2022-43482 | WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerability | CodePeople | Appointment Booking Calendar (WordPress plugin) | Medium | 4.3 | 2022-11-18 19:03:50 | Deep Dive |
| CVE-2022-38075 | WordPress Mantenimiento web plugin <= 0.13 - Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) | Carlos Doral | Mantenimiento web (WordPress plugin) | Medium | 6.1 | 2022-11-18 18:57:07 | Deep Dive |
| CVE-2022-41692 | WordPress Appointment Hour Booking plugin <= 1.3.71 - Missing Authorization vulnerability | CodePeople | Appointment Hour Booking (WordPress plugin) | Medium | 4.3 | 2022-11-18 18:54:30 | Deep Dive |
| CVE-2022-43463 | WordPress Custom Product Tabs for WooCommerce plugin <= 1.7.9 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | YIKES, Inc. | Custom Product Tabs for WooCommerce (WordPress plugin) | Medium | 4.8 | 2022-11-18 18:51:40 | Deep Dive |
| CVE-2022-40687 | WordPress Creative Mail plugin <= 1.5.4 - Cross-Site Request Forgery (CSRF) vulnerability | Constant Contact | Creative Mail (WordPress plugin) | Medium | 5.4 | 2022-11-18 18:47:20 | Deep Dive |
| CVE-2022-41805 | WordPress Booster for WooCommerce plugin <= 5.6.6 - Cross-Site Request Forgery (CSRF) vulnerability | Pluggabl LLC | Booster for WooCommerce (WordPress plugin) | Medium | 5.4 | 2022-11-18 18:44:15 | Deep Dive |
| CVE-2022-40686 | WordPress Creative Mail plugin <= 1.5.4 - Cross-Site Request Forgery (CSRF) vulnerability | Constant Contact | Creative Mail (WordPress plugin) | Medium | 5.4 | 2022-11-18 18:38:46 | Deep Dive |
| CVE-2022-41652 | WordPress Quiz And Survey Master plugin <= 7.3.10 - Bypass vulnerability | ExpressTech | Quiz And Survey Master (WordPress plugin) | Medium | 6.5 | 2022-11-18 18:32:09 | Deep Dive |
| CVE-2022-41840 | WordPress Welcart eCommerce plugin <= 2.7.7 - Unauth. Directory Traversal vulnerability | Collne Inc. | Welcart e-Commerce (WordPress plugin) | High | 7.5 | 2022-11-18 18:27:06 | Deep Dive |
| CVE-2022-38974 | WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability | OnTheGoSystems Ltd. | WPML Multilingual CMS (WordPress plugin) | Medium | 4.3 | 2022-11-18 18:13:33 | Deep Dive |
| CVE-2022-45069 | WordPress Crowdsignal Dashboard plugin <= 3.0.9 - Privilege Escalation vulnerability | Automattic, Inc. | Crowdsignal Dashboard – Polls, Surveys & more (WordPress plugin) | Medium | 6.3 | 2022-11-17 22:18:39 | Deep Dive |
| CVE-2022-40694 | WordPress News Announcement Scroll plugin <= 8.8.8 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | StoreApps | News Announcement Scroll (WordPress plugin) | Medium | 4.8 | 2022-11-17 22:17:27 | Deep Dive |
| CVE-2022-44736 | WordPress Chameleon plugin <= 1.4.3 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | Fahad Mahmood | Chameleon (WordPress plugin) | Medium | 4.8 | 2022-11-17 22:16:07 | Deep Dive |
| CVE-2022-40192 | WordPress wpForo Forum plugin <= 2.0.9 - Cross-Site Request Forgery (CSRF) vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | High | 7.1 | 2022-11-17 22:14:27 | Deep Dive |
| CVE-2022-41315 | WordPress Ezoic plugin <= 2.8.8 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | Ezoic Inc. | Ezoic (WordPress plugin) | Medium | 4.8 | 2022-11-17 22:12:15 | Deep Dive |
| CVE-2022-41132 | WordPress Ezoic plugin <= 2.8.8 - Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability | Ezoic Inc. | Ezoic (WordPress plugin) | Medium | 6.1 | 2022-11-17 22:11:09 | Deep Dive |
| CVE-2022-44591 | WordPress Anthologize plugin <= 0.8.0 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | One Week | One Tool | Anthologize (WordPress plugin) | Medium | 4.8 | 2022-11-17 22:09:59 | Deep Dive |
| CVE-2022-41791 | WordPress ProfileGrid plugin <= 5.1.6 - Auth. CSV Injection vulnerability | Profilegrid | ProfileGrid (WordPress plugin) | Medium | 6.8 | 2022-11-17 22:08:40 | Deep Dive |