| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-23911 | AP Custom Testimonial < 1.4.8 - Admin+ SQL Injection | Unknown | Testimonial WordPress Plugin – AP Custom Testimonial | 高危 | - | 2022-02-28 09:06:57 | Deep Dive |
| CVE-2021-25081 | WP Google Map < 1.8.4 - Arbitrary Post Deletion and Plugin's Settings Update via CSRF | Unknown | Maps Plugin using Google Maps for WordPress – WP Google Map | 中危 | - | 2022-02-28 09:06:35 | Deep Dive |
| CVE-2021-25011 | WP Google Map < 1.8.1 - Subscriber+ Arbitrary Post Deletion and Plugin's Settings Update | Unknown | Maps Plugin using Google Maps for WordPress – WP Google Map | 中危 | - | 2022-02-28 09:06:30 | Deep Dive |
| CVE-2021-26256 | WordPress Survey Maker plugin <= 2.0.6 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability | Survey Maker team | Survey Maker (WordPress plugin) | Medium | 4.7 | 2022-02-21 17:49:34 | Deep Dive |
| CVE-2022-25599 | WordPress Spiffy Calendar plugin <= 4.9.0 - Event deletion via Cross-Site Request Forgery (CSRF) vulnerability | Spiffy Plugins | Spiffy Calendar (WordPress plugin) | Medium | 5.4 | 2022-02-21 17:49:33 | Deep Dive |
| CVE-2022-23983 | WordPress WP Content Copy Protection & No Right Click plugin <= 3.4.4 - Cross-Site Request Forgery (CSRF) leads to Settings Update vulnerability | WP-buy | WP Content Copy Protection & No Right Click (WordPress plugin) | Medium | 4.3 | 2022-02-21 17:49:31 | Deep Dive |
| CVE-2022-23984 | WordPress wpDiscuz plugin <= 7.3.11 - Sensitive Information Disclosure | gVectors Team | Comments – wpDiscuz (WordPress plugin) | Low | 3.7 | 2022-02-21 17:49:31 | Deep Dive |
| CVE-2021-24867 | Backdoored Plugins & Themes from AccessPress Themes | AccessPress Themes | Frontend Post WordPress Plugin – AccessPress Anonymous Post | 超危 | - | 2022-02-21 10:45:39 | Deep Dive |
| CVE-2022-23982 | WordPress Perfect Brands for WooCommerce plugin <= 2.0.4 - Server Information Exposure vulnerability | QuadLayers | Perfect Brands for WooCommerce (WordPress plugin) | Medium | 4.3 | 2022-02-18 17:50:15 | Deep Dive |
| CVE-2022-23981 | WordPress Perfect Brands for WooCommerce plugin <= 2.0.4 - Set Featured Brand vulnerability | QuadLayers | Perfect Brands for WooCommerce (WordPress plugin) | Medium | 4.3 | 2022-02-18 17:50:14 | Deep Dive |
| CVE-2022-0633 | UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Download | UpdraftPlus | UpdraftPlus WordPress Backup Plugin (Free) | 中危 | - | 2022-02-17 18:45:11 | Deep Dive |
| CVE-2021-25033 | Noptin < 1.6.5 - Open Redirect | Unknown | WordPress Newsletter Plugin – Noptin | 中危 | - | 2022-02-14 09:20:45 | Deep Dive |
| CVE-2021-25106 | WPLegalPages < 2.7.1 - Subscriber+ Arbitrary Settings Update to Stored XSS | Unknown | Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages | 中危 | - | 2022-02-07 15:47:23 | Deep Dive |
| CVE-2021-25105 | Ivory Search < 5.4.1 - Multiple Admin+ Stored Cross-Site Scripting | Unknown | Ivory Search – WordPress Search Plugin | 中危 | - | 2022-02-07 15:47:22 | Deep Dive |
| CVE-2021-24993 | Ultimate Product Catalog < 5.0.26 - Subscriber+ Arbitrary Product Creation & Settings Update | Unknown | Ultimate Product Catalog – WordPress Catalog Plugin | 中危 | - | 2022-02-07 15:47:14 | Deep Dive |
| CVE-2022-23980 | WordPress Yasr – Yet Another Stars Rating plugin <= 2.9.9 - Cross-Site Scripting (XSS) vulnerability | Dario Curvino | Yasr – Yet Another Stars Rating (WordPress plugin) | Medium | 4.7 | 2022-02-04 22:29:26 | Deep Dive |
| CVE-2021-44779 | WordPress [GWA] AutoResponder plugin <= 2.3 - Unauthenticated SQL Injection (SQLi) vulnerability | G.J.P. | [GWA] AutoResponder (WordPress plugin) | High | 7.3 | 2022-02-04 22:29:17 | Deep Dive |
| CVE-2021-25089 | UpdraftPlus < 1.16.69 - Reflected Cross-Site Scripting | Unknown | UpdraftPlus WordPress Backup Plugin | 中危 | - | 2022-02-01 12:21:37 | Deep Dive |
| CVE-2021-24900 | Ninja Tables < 4.1.8 - Admin+ Stored Cross-Site Cross-Site Scripting | Unknown | Ninja Tables – Best WP DataTables Plugin for WordPress | 中危 | - | 2022-02-01 12:21:28 | Deep Dive |
| CVE-2021-45729 | WordPress WP Google Map plugin <= 1.8.0 - Privilege Escalation vulnerability | WP Google Map | WP Google Map (WordPress plugin) | Medium | 5.4 | 2022-01-25 19:11:16 | Deep Dive |