| CVE-2022-36375 | WordPress Tabs plugin <= 3.6.0 - Authenticated WordPress Options Change vulnerability | Biplob Adhikari | Tabs (WordPress plugin) | High | 7.2 | 2022-07-25 19:50:51 | Deep Dive |
| CVE-2022-33969 | WordPress Flipbox plugin <= 2.6.0 - Authenticated WordPress Options Change vulnerability | Biplob Adhikari | Flipbox (WordPress plugin) | High | 7.2 | 2022-07-25 17:45:56 | Deep Dive |
| CVE-2022-33965 | WordPress WP Visitor Statistics plugin <= 5.7 - Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities | Osamaesh | WP Visitor Statistics (WordPress plugin) | Critical | 9.3 | 2022-07-25 14:01:28 | Deep Dive |
| CVE-2022-33901 | WordPress MultiSafepay plugin for WooCommerce plugin <= 4.13.1 - Unauthenticated Arbitrary File Read vulnerability | MultiSafepay | MultiSafepay plugin for WooCommerce (WordPress plugin) | Medium | 5.3 | 2022-07-22 16:52:53 | Deep Dive |
| CVE-2022-34650 | WordPress Team plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities | wpWax | Team (WordPress plugin) | Medium | 4.1 | 2022-07-22 16:51:41 | Deep Dive |
| CVE-2022-34853 | WordPress Team plugin <= 1.2.6 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities | wpWax | Team (WordPress plugin) | Medium | 4.1 | 2022-07-22 16:49:35 | Deep Dive |
| CVE-2022-30998 | WordPress Homepage Product Organizer for WooCommerce plugin <= 1.1 - Multiple Authenticated SQL Injection (SQLi) vulnerabilities | WooPlugins.co | Homepage Product Organizer for WooCommerce (WordPress plugin) | Critical | 9.1 | 2022-07-22 16:48:27 | Deep Dive |
| CVE-2022-33191 | WordPress Testimonials plugin <= 3.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Chinmoy Paul (chinmoy29) | Testimonials (WordPress plugin) | Medium | 4.1 | 2022-07-22 16:46:52 | Deep Dive |
| CVE-2022-34839 | WordPress WP OAuth2 Server plugin <= 1.0.1 - Authentication Bypass vulnerability | CodexShaper | WP OAuth2 Server (WordPress plugin) | Medium | 5.9 | 2022-07-22 16:44:40 | Deep Dive |
| CVE-2022-27235 | WordPress Social Share Buttons by Supsystic plugin <= 2.2.3 - Multiple Broken Access Control vulnerabilities | Supsystic | Social Share Buttons by Supsystic (WordPress plugin) | Medium | 6.3 | 2022-07-22 16:43:11 | Deep Dive |
| CVE-2022-33960 | WordPress Social Share Buttons by Supsystic plugin <= 2.2.3 - Multiple Authenticated SQL Injection (SQLi) vulnerabilities | Supsystic | Social Share Buttons by Supsystic (WordPress plugin) | High | 8.5 | 2022-07-22 16:40:38 | Deep Dive |
| CVE-2022-29495 | WordPress Popup Builder plugin <= 4.1.11 - Cross-Site Request Forgery (CSRF) leading to plugin settings update | Sygnoos | Popup Builder (WordPress plugin) | Medium | 5.4 | 2022-07-22 16:39:04 | Deep Dive |
| CVE-2022-34487 | WordPress Shortcode Addons plugin <= 3.0.2 - Unauthenticated Arbitrary Option Update vulnerability | biplob018 | Shortcode Addons (WordPress plugin) | Critical | 9.8 | 2022-07-21 17:27:59 | Deep Dive |
| CVE-2022-33198 | WordPress Accordions plugin <= 2.0.2 - Unauthenticated WordPress Options Change vulnerability | Biplob Adhikari | Accordions (WordPress plugin) | Critical | 9.8 | 2022-07-21 17:26:31 | Deep Dive |
| CVE-2022-31475 | WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Read via Export function vulnerability | GiveWP | GiveWP (WordPress plugin) | Medium | 5.5 | 2022-07-21 17:24:57 | Deep Dive |
| CVE-2022-28700 | WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Creation via Export function vulnerability | GiveWP | GiveWP (WordPress plugin) | Critical | 9.1 | 2022-07-21 17:23:24 | Deep Dive |
| CVE-2022-30536 | WordPress WP Maintenance plugin <= 6.0.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Florent Maillefaud | WP Maintenance (WordPress plugin) | Low | 3.4 | 2022-07-21 17:22:01 | Deep Dive |
| CVE-2022-28666 | WordPress Custom Product Tabs for WooCommerce plugin <= 1.7.7 - Broken Access Control vulnerability | YIKES Inc. | Custom Product Tabs for WooCommerce (WordPress plugin) | Medium | 5.3 | 2022-07-21 16:59:23 | Deep Dive |
| CVE-2022-30337 | WordPress WP Meta SEO plugin <= 4.4.8 - Social Settings Update vis Cross-Site Request Forgery (CSRF) vulnerability | JoomUnited | WP Meta SEO (WordPress plugin) | Medium | 5.4 | 2022-07-21 16:02:24 | Deep Dive |
| CVE-2022-32289 | WordPress Popup Builder plugin <= 4.1.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Popup Status Change | Sygnoos | Popup Builder (WordPress plugin) | Medium | 5.4 | 2022-07-21 15:29:30 | Deep Dive |