| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-24410 | WordPress FluentForm Plugin <= 4.3.25 is vulnerable to SQL Injection | Contact Form - WPManageNinja LLC | Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms | Medium | 5.5 | 2023-10-31 14:25:56 | Deep Dive |
| CVE-2023-36508 | WordPress Contact Form to DB by BestWebSoft Plugin <= 1.7.1 is vulnerable to SQL Injection | BestWebSoft | Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress | High | 7.6 | 2023-10-31 14:23:21 | Deep Dive |
| CVE-2023-4836 | WordPress File Sharing Plugin < 2.0.5 - Subscriber+ Sensitive Data and Files Exposure via IDOR | Unknown | WordPress File Sharing Plugin | 中危 | - | 2023-10-31 13:54:46 | Deep Dive |
| CVE-2023-5252 | FareHarbor for WordPress <= 3.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | fareharbor | FareHarbor for WordPress | Medium | 6.4 | 2023-10-30 13:48:57 | Deep Dive |
| CVE-2023-46074 | WordPress FreshMail For WordPress Plugin <= 2.3.2 is vulnerable to Cross Site Scripting (XSS) | Borbis Media | FreshMail For WordPress | Medium | 5.8 | 2023-10-26 11:54:40 | Deep Dive |
| CVE-2023-5802 | WordPress WP Knowledgebase Plugin <= 1.3.4 is vulnerable to Cross Site Request Forgery (CSRF) | Mihai Iova | WordPress Knowledge base & Documentation Plugin – WP Knowledgebase | Medium | 4.3 | 2023-10-26 11:47:50 | Deep Dive |
| CVE-2023-46068 | WordPress Maileon Plugin <= 2.16.0 is vulnerable to Cross Site Scripting (XSS) | XQueue GmbH | Maileon for WordPress | Medium | 5.9 | 2023-10-24 12:54:11 | Deep Dive |
| CVE-2023-45829 | WordPress Newsletter & Bulk Email Sender Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS) | HappyBox | Newsletter & Bulk Email Sender – Email Newsletter Plugin for WordPress | Medium | 6.5 | 2023-10-24 12:24:08 | Deep Dive |
| CVE-2023-45640 | WordPress WP ULike Plugin <= 4.6.8 is vulnerable to Cross Site Scripting (XSS) | TechnoWich | WP ULike – Most Advanced WordPress Marketing Toolkit | Medium | 6.5 | 2023-10-24 11:06:17 | Deep Dive |
| CVE-2023-46152 | WordPress WOLF Plugin <= 1.0.7.1 is vulnerable to Cross Site Request Forgery (CSRF) | realmag777 | WOLF – WordPress Posts Bulk Editor and Manager Professional | Medium | 4.3 | 2023-10-24 10:13:03 | Deep Dive |
| CVE-2023-3962 | Winters <= 1.4.3 - Prototype Pollution to Reflected Cross-Site Scripting | myshopkit | Winters - WordPress Blog Theme | Medium | 6.1 | 2023-10-20 15:06:22 | Deep Dive |
| CVE-2023-3965 | nsc <= 1.0 - Prototype Pollution to Reflected Cross-Site Scripting | National Show Centre | NSC WordPress Theme | Medium | 6.1 | 2023-10-20 15:06:12 | Deep Dive |
| CVE-2023-4961 | Poptin <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | poptin | Poptin – Exit Pop Ups & Email Popups | Medium | 6.4 | 2023-10-20 07:29:22 | Deep Dive |
| CVE-2022-4943 | miniOrange's Google Authenticator <= 5.6.5 - Missing Authorization to Plugin Settings Change | cyberlord92 | miniOrange 2FA – Two-Factor Authentication for WordPress (SMS, Email & Google Authenticator) | High | 7.5 | 2023-10-20 07:29:21 | Deep Dive |
| CVE-2023-4968 | WPLegalPages <= 2.9.2 - Authenticated (Author+) Stored Cross-Site Scripting via Shortcode | wplegalpages | Privacy Policy Generator – WPLP Legal Pages | Medium | 5.5 | 2023-10-20 06:35:31 | Deep Dive |
| CVE-2023-5414 | Icegram Express <= 5.6.23 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read | icegram | Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress | Critical | 9.1 | 2023-10-20 06:35:20 | Deep Dive |
| CVE-2023-5336 | iPanorama 360 – WordPress Virtual Tour Builder <= 1.8.0 - Authenticated (Contributor+) SQL Injection via Shortcode | avirtum | iPanorama 360 – Advanced Virtual Tour Builder | High | 8.8 | 2023-10-19 01:53:49 | Deep Dive |
| CVE-2023-45607 | WordPress WordPress Popular Posts Plugin <= 6.3.2 is vulnerable to Cross Site Scripting (XSS) | Hector Cabrera | WordPress Popular Posts | Medium | 6.5 | 2023-10-18 13:13:18 | Deep Dive |
| CVE-2023-45067 | WordPress WP Simple HTML Sitemap Plugin <= 2.1 is vulnerable to Cross Site Scripting (XSS) | Ashish Ajani | WordPress Simple HTML Sitemap | Medium | 6.5 | 2023-10-18 12:30:30 | Deep Dive |
| CVE-2023-44990 | WordPress WOLF Plugin <= 1.0.7.1 is vulnerable to Cross Site Scripting (XSS) | realmag777 | WOLF – WordPress Posts Bulk Editor and Manager Professional | Medium | 5.9 | 2023-10-17 09:01:37 | Deep Dive |