| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-2020 | Calculated Fields Form Professional <= 5.1.56 - Unauthenticated Stored Cross-Site Scripting | codepeople | Calculated Fields Form | High | 7.2 | 2024-03-13 15:26:46 | Deep Dive |
| CVE-2023-6701 | Advanced Custom Fields <= 6.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field | wpengine | Advanced Custom Fields (ACF®) | Medium | 6.4 | 2024-02-05 21:22:04 | Deep Dive |
| CVE-2023-6996 | Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Authenticated (Contributor+) Code Injection | josevega | Display custom fields in the frontend – Post and User Profile Fields | High | 8.8 | 2024-02-05 21:22:03 | Deep Dive |
| CVE-2023-6982 | Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via vg_display_data | josevega | Display custom fields in the frontend – Post and User Profile Fields | Medium | 6.4 | 2024-02-05 21:21:39 | Deep Dive |
| CVE-2023-6526 | Meta Box – WordPress Custom Fields Framework <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | metabox | Meta Box | Medium | 6.4 | 2024-02-05 21:21:38 | Deep Dive |
| CVE-2023-6983 | Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Meta Disclosure | josevega | Display custom fields in the frontend – Post and User Profile Fields | Medium | 4.3 | 2024-02-05 21:21:32 | Deep Dive |
| CVE-2024-0963 | Calculated Fields Form <= 1.2.52 - Authenticated (Contributor+) Stored Cross-Site Scripting | codepeople | Calculated Fields Form | Medium | 6.4 | 2024-02-02 11:34:15 | Deep Dive |
| CVE-2023-0389 | Calculated Fields Form < 1.1.151 - Admin+ Stored Cross-Site Scripting via Dropdown Fields | Unknown | Calculated Fields Form | - | - | 2024-01-16 15:56:08 | Deep Dive |
| CVE-2023-6446 | Calculated Fields Form <= 1.2.40 - Authenticated (Admin+) Stored Cross-Site Scripting | codepeople | Calculated Fields Form | Medium | 4.4 | 2024-01-11 06:49:33 | Deep Dive |
| CVE-2022-40696 | WordPress Advanced Custom Fields Plugin 3.1.1-6.0.2 is vulnerable to Sensitive Data Exposure | WP Engine | Advanced Custom Fields (ACF) | Low | 3.7 | 2024-01-08 22:02:53 | Deep Dive |
| CVE-2023-51517 | WordPress Calculated Fields Form Plugin <= 1.2.28 is vulnerable to Open Redirection | CodePeople | Calculated Fields Form | Medium | 4.1 | 2023-12-29 14:48:26 | Deep Dive |
| CVE-2023-32116 | WordPress Custom post types Plugin <= 4.0.12 is vulnerable to Cross Site Scripting (XSS) | TotalPress.org | Custom post types, Custom Fields & more | Medium | 5.9 | 2023-10-26 12:15:28 | Deep Dive |
| CVE-2023-5292 | Advanced Custom Fields: Extended <= 0.8.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | hwk-fr | Advanced Custom Fields: Extended | Medium | 6.4 | 2023-10-20 07:29:36 | Deep Dive |
| CVE-2023-4469 | Profile Extra Fields by BestWebSoft <= 1.2.7 - Missing Authorization to Sensitive Information Exposure | bestwebsoft | Profile Extra Fields by BestWebSoft | Medium | 5.3 | 2023-10-06 09:31:01 | Deep Dive |
| CVE-2023-40068 | WordPress plugin Advanced Custom Fields 跨站脚本漏洞 | WP Engine | Advanced Custom Fields | 中危 | - | 2023-08-21 08:13:50 | Deep Dive |
| CVE-2022-4888 | Multiple Plugins from Addify - Multiple CSRF | Unknown | Checkout Fields Manager | 中危 | - | 2023-07-31 09:37:33 | Deep Dive |
| CVE-2023-33213 | WordPress wpView Plugin <= 1.3.0 is vulnerable to Cross Site Scripting (XSS) | gVectors | Display Custom Fields – wpView | Medium | 5.9 | 2023-06-19 12:42:25 | Deep Dive |
| CVE-2020-36731 | Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update | wpdesk | Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager | High | 7.2 | 2023-06-07 01:51:54 | Deep Dive |
| CVE-2020-36696 | Product Input Fields for WooCommerce <= 1.2.6 - Missing Authorization | tychesoftwares | Product Input Fields for WooCommerce | High | 7.5 | 2023-06-07 01:51:10 | Deep Dive |
| CVE-2023-2256 | Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting | Unknown | Product Addons & Fields for WooCommerce | 中危 | - | 2023-05-30 07:49:09 | Deep Dive |