| CVE-2022-36346 | WordPress MaxButtons plugin <= 9.2 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities | Max Foundry | MaxButtons (WordPress plugin) | Medium | 4.3 | 2022-08-22 14:50:25 | Deep Dive |
| CVE-2022-34149 | WordPress WP OAuth Server plugin <= 3.0.4 - Authentication Bypass vulnerability | miniOrange | WP OAuth Server (WordPress plugin) | Critical | 9.8 | 2022-08-22 14:50:02 | Deep Dive |
| CVE-2022-34858 | WordPress OAuth 2.0 client for SSO plugin <= 1.11.3 - Authentication Bypass vulnerability | miniOrange | OAuth 2.0 client for SSO (WordPress plugin) | Critical | 9.8 | 2022-08-22 14:49:22 | Deep Dive |
| CVE-2022-34347 | WordPress Download Manager plugin <= 3.2.48 - Cross-Site Request Forgery (CSRF) vulnerability | W3 Eden, Inc. | Download Manager (WordPress plugin) | Medium | 4.2 | 2022-08-22 14:47:17 | Deep Dive |
| CVE-2021-36857 | WordPress Testimonial Builder plugin <= 1.6.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | wpshopmart | Testimonial (WordPress plugin) | Medium | 4.8 | 2022-08-22 14:46:13 | Deep Dive |
| CVE-2021-36847 | WordPress Webba Booking plugin <= 4.2.21 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | WebbaPlugins | Webba Booking (WordPress plugin) | Medium | 4.8 | 2022-08-22 14:44:48 | Deep Dive |
| CVE-2022-2046 | Directorist - Business Directory Plugin < 7.2.3 - Admin+ Arbitrary File Upload | Unknown | Directorist – WordPress Business Directory Plugin with Classified Ads Listings | 中危 | - | 2022-08-08 13:46:03 | Deep Dive |
| CVE-2022-36284 | WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Authenticated IDOR vulnerability leading to PayPal email change | StoreApps | Affiliate For WooCommerce (WordPress plugin) | Medium | 6.4 | 2022-08-05 15:08:52 | Deep Dive |
| CVE-2021-36861 | WordPress Rich Reviews by Starfish plugin <= 1.9.14 - Cross-Site Request Forgery (CSRF) vulnerability | Starfish Reviews | Rich Reviews by Starfish (WordPress plugin) | Medium | 5.4 | 2022-08-05 15:08:36 | Deep Dive |
| CVE-2022-33201 | WordPress MailerLite – Signup forms (official) plugin <= 1.5.7 - Cross-Site Request Forgery (CSRF) vulnerability | MailerLite | MailerLite (WordPress plugin) | Medium | 6.3 | 2022-08-05 15:08:21 | Deep Dive |
| CVE-2022-25649 | WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Multiple Improper Access Control vulnerabilities | StoreApps | Affiliate For WooCommerce (WordPress plugin) | Medium | 5.0 | 2022-08-05 15:07:53 | Deep Dive |
| CVE-2022-34154 | WordPress Enable SVG, WebP & ICO Upload plugin <= 1.0.1 - Authenticated Arbitrary File Upload vulnerability | ideasToCode | Enable SVG, WebP & ICO Upload (WordPress plugin) | High | 7.2 | 2022-08-01 13:55:12 | Deep Dive |
| CVE-2022-36343 | WordPress Enable SVG, WebP & ICO Upload plugin <= 1.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | ideasToCode | Enable SVG, WebP & ICO Upload (WordPress plugin) | Low | 3.4 | 2022-08-01 13:55:01 | Deep Dive |
| CVE-2022-2245 | Counter Box < 1.2.1 - Arbitrary Counter Activation/Deactivation via CSRF | Unknown | Counter Box – WordPress plugin for countdown, timer, counter | 高危 | - | 2022-08-01 12:50:45 | Deep Dive |
| CVE-2022-1950 | Youzify < 1.2.0 - Unauthenticated SQLi | Unknown | Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress | 超危 | - | 2022-08-01 12:49:04 | Deep Dive |
| CVE-2022-36378 | WordPress Floating Div plugin <= 3.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | PluginlySpeaking | Floating Div (WordPress plugin) | Medium | 4.8 | 2022-07-29 18:57:28 | Deep Dive |
| CVE-2016-0796 | WordPress Plugin mb.miniAudioPlayer 安全漏洞 | - | WordPress Plugin mb.miniAudioPlayer-an | 高危 | - | 2022-07-28 16:35:10 | Deep Dive |
| CVE-2022-35882 | WordPress GS Testimonial Slider plugin <= 1.9.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | GS Plugins | GS Testimonial Slider (WordPress plugin) | Medium | 4.8 | 2022-07-28 14:22:48 | Deep Dive |
| CVE-2022-33943 | WordPress BxSlider WP plugin <= 2.0.0 - Authenticated Cross-Site Scripting (XSS) vulnerability | Nico Amarilla | BxSlider WP (WordPress plugin) | Medium | 5.4 | 2022-07-27 16:22:13 | Deep Dive |
| CVE-2022-33970 | WordPress Shortcode Addons plugin <= 3.1.2 - Authenticated WordPress Options Change vulnerability | Biplob018 | Shortcode Addons (WordPress plugin) | High | 7.2 | 2022-07-27 13:28:14 | Deep Dive |