| CVE-2022-38068 | WordPress Export Post Info plugin <= 1.1.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Apasionados | Export Post Info (WordPress plugin) | Medium | 4.8 | 2022-09-09 14:39:52 | Deep Dive |
| CVE-2022-38070 | WordPress Pop-up plugin <= 1.1.5 - Privilege Escalation vulnerability | Pop-ups | Pop-up (WordPress plugin) | Medium | 5.4 | 2022-09-09 14:39:52 | Deep Dive |
| CVE-2022-38059 | WordPress Access Code Feeder plugin <= 1.0.3 - Cross-Site Request Forgery (CSRF) vulnerability | Alexey Trofimov | Access Code Feeder (WordPress plugin) | Medium | 5.5 | 2022-09-09 14:39:51 | Deep Dive |
| CVE-2022-36427 | WordPress About Rentals plugin <= 1.5 - Missing Access Control vulnerability | About Rentals. Inc. | About Rentals (WordPress plugin) | High | 7.3 | 2022-09-06 22:19:14 | Deep Dive |
| CVE-2022-37344 | WordPress Accommodation System plugin <= 1.0.1 - Missing Access Control vulnerability | PHP Crafts | Accommodation System (WordPress plugin) | High | 7.6 | 2022-09-06 22:19:14 | Deep Dive |
| CVE-2022-36387 | WordPress About Me plugin <= 1.0.12 - Broken Access Control vulnerability | Alessio Caiazza | About Me (WordPress plugin) | High | 7.6 | 2022-09-06 22:19:13 | Deep Dive |
| CVE-2022-34656 | WordPress Poll, Survey, Questionnaire and Voting system plugin <= 1.7.4 - Authenticated Cross-Site Scripting (XSS) vulnerability | wpdevart | Poll, Survey, Questionnaire and Voting system (WordPress plugin) | Medium | 4.8 | 2022-09-06 17:18:55 | Deep Dive |
| CVE-2022-36425 | WordPress Beaver Builder plugin <= 2.5.4.3 - Broken Access Control vulnerability | The Beaver Builder Team | Beaver Builder – WordPress Page Builder (WordPress plugin) | Medium | 5.4 | 2022-09-06 17:18:55 | Deep Dive |
| CVE-2022-33177 | WordPress Booking Calendar plugin <= 9.2.1 - Cross-Site Request Forgery (CSRF) vulnerabiulity | WPdevelop/Oplugins | Booking Calendar (WordPress plugin) | Medium | 5.4 | 2022-09-06 17:18:54 | Deep Dive |
| CVE-2022-34867 | WordPress WP Libre Form 2 plugin <= 2.0.8 - Unauthenticated Sensitive Information Disclosure vulnerability | Libreform | WP Libre Form 2 (WordPress plugin) | High | 7.3 | 2022-09-06 17:18:52 | Deep Dive |
| CVE-2021-36829 | WordPress Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | MyThemeShop | Launcher: Coming Soon & Maintenance Mode (WordPress plugin) | Medium | 4.8 | 2022-09-06 17:18:51 | Deep Dive |
| CVE-2022-2376 | Directorist < 7.3.1 - Unauthenticated Email Address Disclosure | Unknown | Directorist – WordPress Business Directory Plugin with Classified Ads Listings | 中危 | - | 2022-09-05 12:35:19 | Deep Dive |
| CVE-2022-36355 | WordPress Easy Org Chart plugin <= 3.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | PluginlySpeaking | Easy Org Chart (WordPress plugin) | Medium | 5.4 | 2022-09-01 16:49:39 | Deep Dive |
| CVE-2022-36373 | WordPress MP3 jPlayer plugin <= 2.7.3 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities | Simon Ward | MP3-jPlayer (WordPress plugin) | Medium | 5.4 | 2022-09-01 16:49:39 | Deep Dive |
| CVE-2022-36796 | WordPress CallRail Phone Call Tracking plugin <= 0.4.9 - Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) | CallRail, Inc. | CallRail Phone Call Tracking (WordPress plugin) | Medium | 6.1 | 2022-09-01 16:49:39 | Deep Dive |
| CVE-2022-2374 | Simply Schedule Appointments < 1.5.7.7 - Admin+ Stored Cross-Site Scripting | Unknown | Simply Schedule Appointments – WordPress Booking Plugin | 中危 | - | 2022-08-29 17:15:36 | Deep Dive |
| CVE-2022-2559 | Fluent Support < 1.5.8 - Admin+ SQLi | Unknown | Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin | 高危 | - | 2022-08-29 17:15:36 | Deep Dive |
| CVE-2022-2373 | Simply Schedule Appointments < 1.5.7.7 - Unauthenticated Email Address Disclosure | Unknown | Simply Schedule Appointments – WordPress Booking Plugin | 中危 | - | 2022-08-29 17:15:35 | Deep Dive |
| CVE-2022-36389 | WordPress Better Messages plugin <= 1.9.9.148 - Cross-Site Request Forgery (CSRF) vulnerability | WordPlus | Better Messages (WordPress plugin) | Medium | 4.3 | 2022-08-23 15:48:48 | Deep Dive |
| CVE-2022-36405 | WordPress amCharts: Charts and Maps plugin <= 1.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | amCharts | amCharts: Charts and Maps (WordPress plugin) | Medium | 5.4 | 2022-08-23 15:48:38 | Deep Dive |