| CVE-2022-40205 | WordPress wpForo Forum plugin <= 2.0.5 - Insecure direct object references (IDOR) vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | Medium | 5.4 | 2022-11-08 18:26:59 | Deep Dive |
| CVE-2022-40632 | WordPress wpForo Forum plugin <= 2.0.5 - Cross-Site Request Forgery (CSRF) vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | Medium | 5.4 | 2022-11-08 18:23:19 | Deep Dive |
| CVE-2022-30545 | WordPress 5 Anker Connect plugin <= 1.2.6 - Reflected Cross-Site Scripting (XSS) vulnerability | 5 Anker GmbH | 5 Anker Connect (WordPress plugin) | Medium | 4.8 | 2022-11-08 18:16:22 | Deep Dive |
| CVE-2022-40128 | WordPress Advanced Order Export For WooCommerce plugin <= 3.3.2 - Cross-Site Request Forgery (CSRF) vulnerability | AlgolPlus | Advanced Order Export For WooCommerce (WordPress plugin) | Medium | 4.3 | 2022-11-08 18:15:18 | Deep Dive |
| CVE-2022-43481 | WordPress Advanced Coupons for WooCommerce Coupons plugin <= 4.5 - Cross-Site Request Forgery (CSRF) vulnerability | Rymera Web Co | Advanced Coupons (WordPress plugin) | Medium | 5.4 | 2022-11-08 18:14:12 | Deep Dive |
| CVE-2022-43491 | WordPress Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 - Cross-Site Request Forgery (CSRF) vulnerability | AlgolPlus | Advanced Dynamic Pricing for WooCommerce (WordPress plugin) | Medium | 5.4 | 2022-11-08 18:12:19 | Deep Dive |
| CVE-2022-3463 | FluentForm < 4.3.13 - CSV Injection | Unknown | Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms | 超危 | - | 2022-11-07 00:00:00 | Deep Dive |
| CVE-2022-25952 | WordPress Content Egg plugin <= 5.4.0 - Cross-Site Request Forgery (CSRF) vulnerability | Keywordrush | Content Egg (WordPress plugin) | Medium | 4.3 | 2022-11-03 19:35:05 | Deep Dive |
| CVE-2021-36906 | WordPress Quiz And Survey Master plugin <= 7.3.6 - Multiple Insecure direct object references (IDOR) vulnerabilities | ExpressTech | Quiz And Survey Master (WordPress plugin) | Low | 2.7 | 2022-11-03 19:33:46 | Deep Dive |
| CVE-2022-44628 | WordPress 4ECPS Web Forms plugin <= 0.2.17 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | JumpDEMAND Inc. | 4ECPS Web Forms (WordPress plugin) | Medium | 4.8 | 2022-11-03 19:32:26 | Deep Dive |
| CVE-2022-44627 | WordPress Simple SEO plugin <= 1.8.12 - Cross-Site Request Forgery (CSRF) vulnerability | David Cole | Simple SEO (WordPress plugin) | Medium | 5.4 | 2022-11-03 19:30:58 | Deep Dive |
| CVE-2022-36404 | WordPress Simple SEO plugin <= 1.8.12 - Broken Access Control vulnerability | David Cole | Simple SEO (WordPress plugin) | Medium | 5.4 | 2022-11-03 19:27:39 | Deep Dive |
| CVE-2022-40131 | WordPress Page View Count plugin <= 2.5.5 - Cross-Site Request Forgery (CSRF) vulnerability | a3rev Software | Page View Count (WordPress plugin) | Medium | 5.4 | 2022-11-03 19:26:22 | Deep Dive |
| CVE-2022-36428 | WordPress Rock Convert plugin <= 2.11.0 - Auth. Cross-Site Scripting (XSS) vulnerability | Stage | Rock Convert (WordPress plugin) | Medium | 4.8 | 2022-11-03 19:22:18 | Deep Dive |
| CVE-2022-44586 | WordPress AM-HiLi plugin <= 1.0 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | Ayoub Media | AM-HiLi (WordPress plugin) | Medium | 4.8 | 2022-11-02 21:13:33 | Deep Dive |
| CVE-2022-44576 | WordPress AgentEasy Properties plugin <= 1.0.4 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | AgentEasy | AgentEasy Properties (WordPress plugin) | Medium | 4.8 | 2022-11-02 21:05:56 | Deep Dive |
| CVE-2022-2190 | Envira Gallery Lite < 1.8.4.7 - Reflected Cross-Site Scripting | Unknown | Gallery Plugin for WordPress – Envira Photo Gallery | 中危 | - | 2022-10-31 00:00:00 | Deep Dive |
| CVE-2022-3254 | AWP Classifieds Plugin < 4.3 - Unauthenticated SQLi | Unknown | WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds | 超危 | - | 2022-10-31 00:00:00 | Deep Dive |
| CVE-2022-3360 | LearnPress < 4.1.7.2 - Unauthenticated PHP Object Injection via REST API | Unknown | LearnPress – WordPress LMS Plugin | 高危 | - | 2022-10-31 00:00:00 | Deep Dive |
| CVE-2021-36898 | WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. SQL Injection (SQLi) vulnerability | ExpressTech | Quiz And Survey Master (WordPress plugin) | Critical | 9.1 | 2022-10-28 17:07:26 | Deep Dive |