| CVE-2022-27849 | WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerability | Jeff Starr | Simple Ajax Chat (WordPress plugin) | Medium | 5.3 | 2022-04-15 16:24:45 | Deep Dive |
| CVE-2022-27848 | WordPress Modern Events Calendar Lite plugin <= 6.5.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Webnus | Modern Events Calendar Lite (WordPress plugin) | Low | 3.4 | 2022-04-14 20:05:48 | Deep Dive |
| CVE-2022-27846 | WordPress Yoo Slider plugin <= 2.0.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Slider Creation / Modification | Yooslider | Yoo Slider – Image Slider & Video Slider (WordPress plugin) | Medium | 4.3 | 2022-04-13 17:05:53 | Deep Dive |
| CVE-2022-27847 | WordPress Yoo Slider plugin <= 2.0.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Template Import | Yooslider | Yoo Slider – Image Slider & Video Slider (WordPress plugin) | Medium | 4.3 | 2022-04-13 17:05:53 | Deep Dive |
| CVE-2021-36914 | WordPress CalderaWP License Manager plugin <= 1.2.11 - Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) | Desertsnowman, Shelob9 | CalderaWP License Manager (WordPress plugin) | Medium | 6.1 | 2022-04-12 16:11:19 | Deep Dive |
| CVE-2022-25614 | WordPress eRoom plugin <= 1.3.7 - Cross-Site Request Forgery (CSRF) leading to Sync with Zoom Meetings vulnerability | StylemixThemes | eRoom – Zoom Meetings & Webinar (WordPress plugin) | Medium | 4.3 | 2022-04-11 19:38:35 | Deep Dive |
| CVE-2022-25615 | WordPress eRoom plugin <= 1.3.8 - Cross-Site Request Forgery (CSRF) vulnerability leading to Cache Deletion | StylemixThemes | eRoom – Zoom Meetings & Webinar (WordPress plugin) | Medium | 4.3 | 2022-04-11 19:38:34 | Deep Dive |
| CVE-2022-27845 | WordPress Plausible Analytics plugin <= 1.2.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | PlausibleHQ | Plausible Analytics (WordPress plugin) | Medium | 4.8 | 2022-04-11 19:38:17 | Deep Dive |
| CVE-2022-27844 | WordPress WPvivid plugin <= 0.9.70 - Arbitrary File Read vulnerability | WPvivid Team | Migration, Backup, Staging – WPvivid (WordPress plugin) | Low | 2.7 | 2022-04-11 19:38:16 | Deep Dive |
| CVE-2021-36893 | WordPress Responsive Tabs plugin <= 4.0.5 - Cross-Site Scripting (XSS) vulnerability | WP Darko | Responsive Tabs (WordPress plugin) | Medium | 4.8 | 2022-04-11 19:37:49 | Deep Dive |
| CVE-2021-36846 | WordPress Chaty plugin <= 2.8.3 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Premio | Chaty (WordPress plugin) | Medium | 4.8 | 2022-04-11 19:37:42 | Deep Dive |
| CVE-2021-36896 | WordPress Pricing Table plugin <= 1.5.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | W3 Eden, Inc. | Pricing Table (WordPress plugin) | Medium | 4.8 | 2022-04-11 19:36:57 | Deep Dive |
| CVE-2021-36848 | WordPress Social Media Feather plugin <= 2.0.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Socialmediafeather | Social Media Feather (WordPress plugin) | Low | 3.4 | 2022-04-11 19:36:56 | Deep Dive |
| CVE-2021-36910 | WordPress WP-Appbox plugin <= 4.3.20 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Marcel Schmilgeit | WP-Appbox (WordPress plugin) | Low | 3.4 | 2022-04-11 19:36:55 | Deep Dive |
| CVE-2022-0271 | LearnPress < 4.1.6 - Reflected Cross-Site Scripting | Unknown | LearnPress – WordPress LMS Plugin | 中危 | - | 2022-04-11 14:40:41 | Deep Dive |
| CVE-2021-36826 | WordPress WP Project Manager plugin <= 2.4.13 - Stored Cross-Site Scripting (XSS) vulnerability | weDevs | WP Project Manager (WordPress plugin) | Medium | 5.4 | 2022-04-04 19:46:20 | Deep Dive |
| CVE-2021-36851 | WordPress Testimonial Slider plugin <= 3.5.8.3 - Cross-Site Scripting (XSS) vulnerability | Web-Settler | Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) | Medium | 4.1 | 2022-04-04 19:46:19 | Deep Dive |
| CVE-2022-25618 | WordPress wpDataTables plugin <= 2.1.27 - Stored Cross-Site Scripting (XSS) vulnerability | TMS-Plugins | wpDataTables – Tables & Table Charts (WordPress plugin) | Low | 3.4 | 2022-04-04 19:46:18 | Deep Dive |
| CVE-2022-25613 | WordPress FV Flowplayer Video Player plugin <= 7.5.18.727 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability | FolioVision | FV Flowplayer Video Player (WordPress plugin) | Medium | 4.1 | 2022-04-04 19:46:17 | Deep Dive |
| CVE-2022-0864 | UpdraftPlus < 1.22.9 - Reflected Cross-Site Scripting | Unknown | UpdraftPlus WordPress Backup Plugin | 中危 | - | 2022-04-04 15:35:53 | Deep Dive |