| CVE-2022-38135 | WordPress Photospace Gallery plugin <= 2.3.5 - Broken Access Control vulnerability | Dean Oakley | Photospace Gallery (WordPress plugin) | Medium | 5.4 | 2022-09-12 19:24:03 | Deep Dive |
| CVE-2022-37335 | WordPress Word Search Puzzles game plugin <= 2.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | WHA | Word Search Puzzles game (WordPress plugin) | Medium | 4.8 | 2022-09-09 14:40:07 | Deep Dive |
| CVE-2022-37407 | WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities | WPChill | Gallery PhotoBlocks (WordPress plugin) | Medium | 4.1 | 2022-09-09 14:40:07 | Deep Dive |
| CVE-2022-35275 | WordPress Advanced Order Export For WooCommerce plugin <= 3.3.1 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability | AlgolPlus | Advanced Order Export For WooCommerce (WordPress plugin) | Medium | 4.8 | 2022-09-09 14:39:56 | Deep Dive |
| CVE-2022-35277 | WordPress GetResponse plugin <= 5.5.20 - Cross-Site Request Forgery (CSRF) vulnerability | GetResponse | GetResponse for WordPress (WordPress plugin) | Medium | 5.4 | 2022-09-09 14:39:56 | Deep Dive |
| CVE-2022-37411 | WordPress Captcha Code plugin <= 2.7 - Cross-Site Request Forgery (CSRF) vulnerability | Vinoj Cardoza | Captcha Code (WordPress plugin) | Medium | 5.4 | 2022-09-09 14:39:56 | Deep Dive |
| CVE-2022-36793 | WordPress WP Shop plugin <= 3.9.6 - Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities | wp-shop.ru | WP Shop (WordPress plugin) | Medium | 6.5 | 2022-09-09 14:39:55 | Deep Dive |
| CVE-2022-37404 | WordPress add2fav plugin <= 1.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Christian Salazar | add2fav (WordPress plugin) | Medium | 4.8 | 2022-09-09 14:39:55 | Deep Dive |
| CVE-2022-37412 | WordPress Better Delete Revision plugin <= 1.6.1 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability | Galerio & Urda | Better Delete Revision (WordPress plugin) | Medium | 4.8 | 2022-09-09 14:39:55 | Deep Dive |
| CVE-2022-38067 | WordPress Event Calendar – Calendar plugin <= 1.4.6 - Unauthenticated Event Deletion vulnerability | Totalsoft | Event Calendar – Calendar (WordPress plugin) | Medium | 6.5 | 2022-09-09 14:39:55 | Deep Dive |
| CVE-2022-37403 | WordPress Add User Role plugin <= 0.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Nikhil Vaghela | Add User Role (WordPress plugin) | Medium | 4.8 | 2022-09-09 14:39:54 | Deep Dive |
| CVE-2022-37405 | WordPress Better Font Awesome plugin <= 2.0.1 - Cross-Site Request Forgery (CSRF) vulnerability | Mickey Kay | Better Font Awesome (WordPress plugin) | Medium | 4.3 | 2022-09-09 14:39:54 | Deep Dive |
| CVE-2022-38058 | WordPress WP Shamsi plugin <= 4.1.1 - Authenticated Plugin Setting change vulnerability | wpvar.com | WP Shamsi (WordPress plugin) | Medium | 4.3 | 2022-09-09 14:39:54 | Deep Dive |
| CVE-2022-38093 | WordPress All in One SEO plugin <= 4.2.3.1 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities | All in One SEO Team | All in One SEO (WordPress plugin) | Medium | 5.4 | 2022-09-09 14:39:54 | Deep Dive |
| CVE-2022-38144 | WordPress wpForo Forum plugin <= 2.0.5 - Cross-Site Request Forgery (CSRF) vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | 高危 | - | 2022-09-09 14:39:54 | Deep Dive |
| CVE-2022-36356 | WordPress Culture Object plugin <= 4.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Liam Gladdy / Thirty8 Digital | Culture Object (WordPress plugin) | Medium | 4.8 | 2022-09-09 14:39:53 | Deep Dive |
| CVE-2022-36376 | WordPress Rank Math SEO plugin <= 1.0.95 - Server-Side Request Forgery (SSRF) vulnerability | Rank Math | Rank Math SEO (WordPress plugin) | Medium | 6.8 | 2022-09-09 14:39:53 | Deep Dive |
| CVE-2022-36422 | WP-PostRatings plugin <= 1.89 - Rating increase/decrease via race condition | Lester 'GaMerZ' Chan | WP-PostRatings (WordPress plugin) | Medium | 4.3 | 2022-09-09 14:39:53 | Deep Dive |
| CVE-2022-40191 | WordPress Contact Form By Mega Forms plugin <= 1.2.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Ali Khallad | Contact Form By Mega Forms (WordPress plugin) | Medium | 5.4 | 2022-09-09 14:39:53 | Deep Dive |
| CVE-2022-35725 | WordPress wp-forecast plugin <= 7.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Hans Matzen | wp-forecast (WordPress plugin) | Medium | 4.8 | 2022-09-09 14:39:52 | Deep Dive |