| CVE-2021-36854 | WordPress Booking Ultra Pro plugin <= 1.1.4 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities | Booking Ultra Pro | Booking Ultra Pro (WordPress plugin) | Medium | 5.4 | 2022-09-30 16:52:21 | Deep Dive |
| CVE-2021-36830 | WordPress Comment Guestbook plugin <= 0.8.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | mibuthu | Comment Guestbook (WordPress plugin) | Medium | 4.8 | 2022-09-30 16:14:59 | Deep Dive |
| CVE-2021-36839 | WordPress Social Media Follow Buttons Bar plugin <= 4.73 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Space X-Chimp | Social Media Follow Buttons Bar (WordPress plugin) | Medium | 4.8 | 2022-09-30 16:14:55 | Deep Dive |
| CVE-2022-38454 | WordPress Kraken.io Image Optimizer plugin <= 2.6.5 - Cross-Site Request Forgery (CSRF) vulnerability | Karim Salman | Kraken.io Image Optimizer (WordPress plugin) | Medium | 5.4 | 2022-09-23 18:36:52 | Deep Dive |
| CVE-2022-38079 | WordPress Backup Scheduler plugin <= 1.5.13 - Cross-Site Request Forgery (CSRF) vulnerability | SedLex | Backup Scheduler (WordPress plugin) | Medium | 5.4 | 2022-09-23 18:35:40 | Deep Dive |
| CVE-2022-40132 | WordPress Seriously Simple Podcasting plugin <= 2.16.0 - Cross-Site Request Forgery (CSRF) vulnerability | Castos | Seriously Simple Podcasting (WordPress plugin) | Medium | 5.4 | 2022-09-23 18:34:05 | Deep Dive |
| CVE-2022-38704 | WordPress SEO Redirection plugin <= 8.9 - Cross-Site Request Forgery (CSRF) vulnerability | WP-buy | SEO Redirection Plugin – 301 Redirect Manager (WordPress plugin) | Medium | 5.4 | 2022-09-23 18:32:55 | Deep Dive |
| CVE-2022-36340 | WordPress MailOptin plugin <= 1.2.49.0 - Unauthenticated Optin Campaign Cache Deletion vulnerability | MailOptin Popup Builder Team | MailOptin (WordPress plugin) | Medium | 6.5 | 2022-09-23 18:31:51 | Deep Dive |
| CVE-2022-40215 | WordPress Tabs plugin <= 3.7.1 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities | Biplob Adhikari | Tabs (WordPress plugin) | Low | 3.4 | 2022-09-23 15:22:06 | Deep Dive |
| CVE-2022-36417 | WordPress 3D Tag Cloud plugin <= 3.8 - Multiple Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability | Vinoj Cardoza | 3D Tag Cloud (WordPress plugin) | Medium | 6.1 | 2022-09-23 15:20:50 | Deep Dive |
| CVE-2022-38134 | WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Authenticated Broken Access Control vulnerability | CusRev | Customer Reviews for WooCommerce (WordPress plugin) | Medium | 4.3 | 2022-09-23 15:14:40 | Deep Dive |
| CVE-2022-38470 | WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Cross-Site Request Forgery (CSRF) vulnerability | CusRev | Customer Reviews for WooCommerce (WordPress plugin) | Medium | 4.3 | 2022-09-23 15:08:23 | Deep Dive |
| CVE-2022-40194 | WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Sensitive Information Disclosure vulnerability | CusRev | Customer Reviews for WooCommerce (WordPress plugin) | Medium | 5.3 | 2022-09-23 15:05:35 | Deep Dive |
| CVE-2022-38061 | WordPress Export Post Info plugin <= 1.2.0 - Authenticated CSV Injection vulnerability | Apasionados | Export Post Info (WordPress plugin) | Medium | 6.2 | 2022-09-23 14:40:08 | Deep Dive |
| CVE-2022-40672 | WordPress CPO Shortcodes plugin <= 1.5.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | WPChill | CPO Shortcodes (WordPress plugin) | Medium | 4.8 | 2022-09-23 14:38:37 | Deep Dive |
| CVE-2022-40195 | WordPress PCA Predict plugin <= 1.0.3 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | PCA Predict | PCA Predict (WordPress plugin) | Medium | 4.8 | 2022-09-23 14:36:58 | Deep Dive |
| CVE-2022-38085 | WordPress Read more By Adam plugin <= 1.1.8 - Cross-Site Request Forgery (CSRF) vulnerability | Adam Skaat | Read more By Adam (WordPress plugin) | Medium | 5.4 | 2022-09-23 14:35:43 | Deep Dive |
| CVE-2022-37342 | WordPress Add Shortcodes Actions And Filters plugin <= 2.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Michael Simpson | Add Shortcodes Actions And Filters (WordPress plugin) | Medium | 4.8 | 2022-09-23 14:32:52 | Deep Dive |
| CVE-2022-36388 | WordPress YDS Support Ticket System plugin <= 1.0 - Cross-Site Request Forgery (CSRF) vulnerability | Ydesignservices | YDS Support Ticket System (WordPress plugin) | Medium | 5.4 | 2022-09-23 14:31:32 | Deep Dive |
| CVE-2022-40193 | WordPress Awesome Filterable Portfolio plugin <= 1.9.7 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability | BriniA | Awesome Filterable Portfolio (WordPress plugin) | Medium | 6.1 | 2022-09-23 14:30:01 | Deep Dive |