| CVE-2022-45066 | WordPress WooSwipe WooCommerce Gallery plugin <= 2.0.1 - Auth. Broken Access Control vulnerability | Thrive Website Design | WooSwipe WooCommerce Gallery (WordPress plugin) | Medium | 5.4 | 2022-11-17 22:05:04 | Deep Dive |
| CVE-2022-45375 | WordPress iFeature Slider plugin <= 1.2 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | CyberChimps inc. | iFeature Slider (WordPress plugin) | Medium | 5.4 | 2022-11-17 22:03:41 | Deep Dive |
| CVE-2021-36905 | WordPress Quiz And Survey Master plugin <= 7.3.4 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilities | ExpressTech | Quiz And Survey Master (WordPress plugin) | Medium | 5.4 | 2022-11-17 22:02:19 | Deep Dive |
| CVE-2022-40200 | WordPress wpForo Forum plugin <= 2.0.9 - Auth. Arbitrary File Upload vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | Critical | 9.9 | 2022-11-17 22:01:00 | Deep Dive |
| CVE-2022-38461 | WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability | OnTheGoSystems Ltd. | WPML Multilingual CMS (WordPress plugin) | Medium | 5.4 | 2022-11-17 21:59:47 | Deep Dive |
| CVE-2022-45071 | WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerability | OnTheGoSystems Ltd. | WPML Multilingual CMS (WordPress plugin) | Medium | 5.4 | 2022-11-17 21:58:31 | Deep Dive |
| CVE-2022-45072 | WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerability | OnTheGoSystems Ltd. | WPML Multilingual CMS (WordPress plugin) | Medium | 4.3 | 2022-11-17 21:57:12 | Deep Dive |
| CVE-2022-42460 | WordPress Traffic Manager plugin <= 1.4.5 - Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) | SedLex | Traffic Manager (WordPress plugin) | Medium | 6.5 | 2022-11-10 21:36:56 | Deep Dive |
| CVE-2022-44590 | WordPress Simple Video Embedder plugin <= 2.2 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | James Lao | Simple Video Embedder (WordPress plugin) | Medium | 5.4 | 2022-11-09 21:14:28 | Deep Dive |
| CVE-2022-41978 | WordPress Zoho CRM Lead Magnet plugin <= 1.7.5.8 - Auth. Arbitrary Options Update vulnerability | Zoho CRM | Zoho CRM Lead Magnet (WordPress plugin) | High | 8.8 | 2022-11-09 15:46:23 | Deep Dive |
| CVE-2022-43488 | WordPress Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 - Cross-Site Request Forgery (CSRF) vulnerability | AlgolPlus | Advanced Dynamic Pricing for WooCommerce (WordPress plugin) | Medium | 5.4 | 2022-11-09 15:44:58 | Deep Dive |
| CVE-2022-32587 | WordPress WP Page Widget plugin <= 3.9 - Cross-Site Request Forgery (CSRF) vulnerability | CodeAndMore | WP Page Widget (WordPress plugin) | Medium | 5.4 | 2022-11-08 18:37:29 | Deep Dive |
| CVE-2022-44741 | WordPress Testimonial Slider plugin <= 1.3.1 - Cross-Site Request Forgery (CSRF) vulnerability | David Anderson | Testimonial Slider (WordPress plugin) | Medium | 6.1 | 2022-11-08 18:36:34 | Deep Dive |
| CVE-2022-41980 | WordPress Mantenimiento web plugin <= 0.13 - Auth. Cross-Site Scripting (XSS) vulnerability | Carlos Doral | Mantenimiento web (WordPress plugin) | Medium | 4.8 | 2022-11-08 18:34:39 | Deep Dive |
| CVE-2022-42494 | WordPress All in One SEO Pro plugin <= 4.2.5.1 - Server Side Request Forgery (SSRF) vulnerability | Semper Plugins, LLC | All in One SEO Pro (WordPress plugin) | Low | 3.0 | 2022-11-08 18:33:32 | Deep Dive |
| CVE-2022-38137 | WordPress Analytify plugin <= 4.2.2 - Cross-Site Request Forgery (CSRF) vulnerability | Analytify | Analytify (WordPress plugin) | Medium | 4.3 | 2022-11-08 18:32:21 | Deep Dive |
| CVE-2022-40206 | WordPress wpForo Forum plugin <= 2.0.5 - Insecure direct object references (IDOR) vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | Medium | 6.3 | 2022-11-08 18:31:21 | Deep Dive |
| CVE-2022-27855 | WordPress Analytics Cat plugin <= 1.0.9 - Plugin Settings change via Cross-Site Request Forgery (CSRF) vulnerability | Fatcat Apps | Analytics Cat (WordPress plugin) | Medium | 5.4 | 2022-11-08 18:30:20 | Deep Dive |
| CVE-2022-27858 | WordPress Activity Log plugin <= 2.8.3 - CSV Injection vulnerability | Activity Log Team | Activity Log (WordPress plugin) | High | 7.4 | 2022-11-08 18:29:27 | Deep Dive |
| CVE-2022-41136 | WordPress Shortcodes Ultimate plugin <= 5.12.0 - CSRF vulnerability leading to Stored XSS | Vladimir Anokhin | Shortcodes Ultimate (WordPress plugin) | Medium | 6.1 | 2022-11-08 18:28:05 | Deep Dive |