| CVE-2022-36389 | WordPress Better Messages plugin <= 1.9.9.148 - Cross-Site Request Forgery (CSRF) vulnerability | WordPlus | Better Messages (WordPress plugin) | Medium | 4.3 | 2022-08-23 15:48:48 | Deep Dive |
| CVE-2022-36405 | WordPress amCharts: Charts and Maps plugin <= 1.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | amCharts | amCharts: Charts and Maps (WordPress plugin) | Medium | 5.4 | 2022-08-23 15:48:38 | Deep Dive |
| CVE-2022-36347 | WordPress Alpine PhotoTile for Pinterest plugin <= 1.3.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Alpine Press | Alpine PhotoTile for Pinterest (WordPress plugin) | Medium | 4.8 | 2022-08-23 15:48:28 | Deep Dive |
| CVE-2022-36292 | WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Cross-Site Request Forgery (CSRF) vulnerabilities | WPChill | Gallery PhotoBlocks (WordPress plugin) | Medium | 5.4 | 2022-08-23 15:48:17 | Deep Dive |
| CVE-2022-36285 | WordPress Uploading SVG, WEBP and ICO files plugin <= 1.0.1 - Authenticated Arbitrary File Upload vulnerability | dmitrylitvinov | Uploading SVG, WEBP and ICO files (WordPress plugin) | High | 7.2 | 2022-08-23 15:48:09 | Deep Dive |
| CVE-2022-35726 | WordPress Video Gallery plugin <= 1.3.4.5 - Broken Authentication vulnerability | yotuwp | Video Gallery (WordPress plugin) | Medium | 4.3 | 2022-08-23 15:47:56 | Deep Dive |
| CVE-2022-36379 | WordPress ЮKassa для WooCommerce plugin <= 2.3.0 - Cross-Site Request Forgery (CSRF) leading to plugin settings update | YooMoney | ЮKassa для WooCommerce (WordPress plugin) | High | 8.8 | 2022-08-23 15:47:42 | Deep Dive |
| CVE-2022-36394 | WordPress Contest Gallery plugin <= 17.0.4 - Authenticated SQL Injection (SQLi) vulnerability | Contest Gallery | Contest Gallery (WordPress plugin) | High | 7.6 | 2022-08-23 15:47:28 | Deep Dive |
| CVE-2022-36341 | WordPress AS – Create Pinterest Pinboard Pages plugin <= 1.0 - Authenticated plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability | Akash soni | AS – Create Pinterest Pinboard Pages (WordPress plugin) | Medium | 5.4 | 2022-08-23 15:47:18 | Deep Dive |
| CVE-2022-36288 | WordPress Download Manager plugin <= 3.2.48 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities | W3 Eden, Inc. | Download Manager (WordPress plugin) | Medium | 5.4 | 2022-08-23 15:47:10 | Deep Dive |
| CVE-2022-35235 | WordPress WPide plugin <= 2.6 - Authenticated Arbitrary File Read vulnerability | XplodedThemes | WPIDE – File Manager & Code Editor (WordPress plugin) | Medium | 4.9 | 2022-08-23 15:46:59 | Deep Dive |
| CVE-2022-36282 | WordPress Search Exclude plugin <= 1.2.6 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Roman Pronskiy | Search Exclude (WordPress plugin) | Medium | 4.8 | 2022-08-23 15:46:49 | Deep Dive |
| CVE-2022-34658 | WordPress Download Manager plugin <= 3.2.48 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities | W3 Eden, Inc. | Download Manager (WordPress plugin) | Medium | 5.4 | 2022-08-23 15:46:34 | Deep Dive |
| CVE-2022-33142 | WordPress Better Messages plugin <= 1.9.10.57 - Denial Of Service (DoS) vulnerability | WordPlus | Better Messages (WordPress plugin) | High | 7.7 | 2022-08-23 15:46:19 | Deep Dive |
| CVE-2022-34868 | WordPress ЮKassa для WooCommerce plugin <= 2.3.0 - Authenticated Arbitrary Settings Update vulnerability | YooMoney | ЮKassa для WooCommerce (WordPress plugin) | High | 8.8 | 2022-08-23 15:46:08 | Deep Dive |
| CVE-2022-35242 | WordPress THE Leads Management System: 59sec LITE plugin <= 3.4.1 - Unauthenticated plugin settings change vulnerability | 59sec | THE Leads Management System: 59sec LITE (WordPress plugin) | Medium | 6.5 | 2022-08-23 15:45:55 | Deep Dive |
| CVE-2022-34648 | WordPress Uploading SVG, WEBP and ICO files plugin <= 1.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | dmitrylitvinov | Uploading SVG, WEBP and ICO files (WordPress plugin) | Medium | 4.8 | 2022-08-23 15:45:25 | Deep Dive |
| CVE-2022-2557 | WordPress Team Members Showcase < 4.1.2 - Subscriber+ Arbitrary File Read and Deletion | Unknown | Team – WordPress Team Members Showcase Plugin | 高危 | - | 2022-08-22 15:04:22 | Deep Dive |
| CVE-2022-2551 | Duplicator < 1.4.7 - Unauthenticated Backup Download | Unknown | Duplicator – WordPress Migration Plugin | 高危 | - | 2022-08-22 15:03:52 | Deep Dive |
| CVE-2022-2544 | Ninja Job Board < 1.3.3 - Resume Disclosure via Directory Listing | Unknown | Ninja Job Board – Ultimate WordPress Job Board Plugin | 高危 | - | 2022-08-22 15:03:39 | Deep Dive |