| CVE-2023-2714 | Groundhogg <= 2.7.9.8 - Missing Authorization to Update License | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | Medium | 4.3 | 2023-05-20 02:03:20 | Deep Dive |
| CVE-2023-2715 | Groundhogg <= 2.7.9.8 - Missing Authorization to Admin Account and Ticket Creation | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | Medium | 4.3 | 2023-05-20 02:03:19 | Deep Dive |
| CVE-2023-2745 | WordPress Core < 6.2.1 - Directory Traversal | WordPress Foundation | WordPress | Medium | 5.4 | 2023-05-17 08:36:44 | Deep Dive |
| CVE-2023-0644 | PushAssist <= 3.0.8 - Reflected Cross-Site Scripting | Unknown | Push Notifications for WordPress by PushAssist | 中危 | - | 2023-05-15 12:15:41 | Deep Dive |
| CVE-2022-45846 | WordPress Image Map Pro Plugin < 5.6.9 is vulnerable to Cross Site Request Forgery (CSRF) | Nickys | Image Map Pro for WordPress - Interactive SVG Image Map Builder | Medium | 5.4 | 2023-05-10 11:08:51 | Deep Dive |
| CVE-2022-46861 | WordPress Login Page Styler Plugin <= 6.2 is vulnerable to Cross Site Scripting (XSS) | Zia Imtiaz | Custom Login Page Styler for WordPress | Medium | 5.9 | 2023-05-10 09:30:24 | Deep Dive |
| CVE-2023-27918 | WordPress plugin Appointment and Event Booking Calendar for WordPress 跨站脚本漏洞 | TMS | Appointment and Event Booking Calendar for WordPress - Amelia | 中危 | - | 2023-05-10 00:00:00 | Deep Dive |
| CVE-2023-23734 | WordPress Userlike – WordPress Live Chat plugin Plugin <= 2.2 is vulnerable to Cross Site Scripting (XSS) | David Voswinkel | Userlike – WordPress Live Chat plugin | Medium | 5.9 | 2023-05-09 10:40:15 | Deep Dive |
| CVE-2023-23884 | WordPress Kanban Boards for WordPress Plugin <= 2.5.20 is vulnerable to Cross Site Scripting (XSS) | Kanban for WordPress | Kanban Boards for WordPress | Medium | 5.9 | 2023-05-09 10:07:16 | Deep Dive |
| CVE-2023-23664 | WordPress ConvertBox Auto Embed WordPress plugin Plugin <= 1.0.19 is vulnerable to Cross Site Scripting (XSS) | ConvertBox | ConvertBox Auto Embed WordPress plugin | Medium | 6.5 | 2023-05-09 09:58:02 | Deep Dive |
| CVE-2023-1979 | Auth bypass in Web Stories for WordPress plugin | Google | Web Stories for WordPress | Medium | 4.9 | 2023-05-08 16:28:54 | Deep Dive |
| CVE-2023-25021 | WordPress FareHarbor for WordPress Plugin <= 3.6.6 is vulnerable to Cross Site Scripting (XSS) | FareHarbor | FareHarbor for WordPress | Medium | 5.9 | 2023-05-08 11:48:22 | Deep Dive |
| CVE-2023-26017 | WordPress Jobs for WordPress Plugin <= 2.5.10.2 is vulnerable to Cross Site Scripting (XSS) | BlueGlass | Jobs for WordPress | Medium | 5.9 | 2023-05-03 15:24:38 | Deep Dive |
| CVE-2023-23708 | WordPress Visualizer Plugin <= 3.9.4 is vulnerable to Cross Site Scripting (XSS) | Themeisle | Visualizer: Tables and Charts Manager for WordPress | Medium | 6.5 | 2023-05-03 12:27:25 | Deep Dive |
| CVE-2023-22713 | WordPress Gutenberg Blocks by WordPress Download Manager Plugin <= 2.1.8 is vulnerable to Cross Site Scripting (XSS) | WordPress Download Manager | Gutenberg Blocks by WordPress Download Manager | Medium | 6.5 | 2023-05-03 11:14:44 | Deep Dive |
| CVE-2023-25797 | WordPress vSlider Multi Image Slider for WordPress Plugin <= 4.1.2 is vulnerable to Cross Site Scripting (XSS) | Mr.Vibe | vSlider Multi Image Slider for WordPress | Medium | 5.9 | 2023-05-03 10:25:11 | Deep Dive |
| CVE-2023-23710 | WordPress WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 is vulnerable to Cross Site Scripting (XSS) | miniOrange | WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) | Medium | 5.9 | 2023-04-25 19:41:40 | Deep Dive |
| CVE-2023-0418 | Video Central for WordPress <= 1.3.0 - Contributor+ Stored XSS | Unknown | Video Central for WordPress | 中危 | - | 2023-04-24 18:31:00 | Deep Dive |
| CVE-2022-44743 | WordPress Jobs for WordPress Plugin <= 2.5.11.2 is vulnerable to Cross Site Scripting (XSS) | BlueGlass | Jobs for WordPress | Medium | 6.5 | 2023-04-23 09:59:49 | Deep Dive |
| CVE-2023-2170 | TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting | stevejburge | Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI | Medium | 5.5 | 2023-04-19 09:38:20 | Deep Dive |