| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-2168 | TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting | stevejburge | Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI | Medium | 5.5 | 2023-04-19 09:38:19 | Deep Dive |
| CVE-2023-2169 | TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting | stevejburge | Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI | Medium | 5.5 | 2023-04-19 09:38:19 | Deep Dive |
| CVE-2023-28121 | WordPress plugin WooCommerce Payments 授权问题漏洞 | - | WooCommerce Payments WordPress Plugin | 超危 | - | 2023-04-12 00:00:00 | Deep Dive |
| CVE-2023-0423 | WordPress Amazon S3 Plugin < 1.6 - Reflected XSS | Unknown | WordPress Amazon S3 Plugin | 中危 | - | 2023-04-10 13:18:03 | Deep Dive |
| CVE-2023-1425 | Groundhogg Contacts < 2.7.9.4 - Admin+ SQLi | Unknown | WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg | 高危 | - | 2023-04-10 13:17:57 | Deep Dive |
| CVE-2023-28789 | WordPress Contact Forms by Cimatti Plugin <= 1.5.4 is vulnerable to Cross Site Scripting (XSS) | Cimatti Consulting | WordPress Contact Forms by Cimatti | High | 7.1 | 2023-04-07 14:12:32 | Deep Dive |
| CVE-2023-28781 | WordPress Contact Forms by Cimatti Plugin <= 1.5.4 is vulnerable to Cross Site Scripting (XSS) | Cimatti Consulting | WordPress Contact Forms by Cimatti | High | 7.1 | 2023-04-07 14:08:40 | Deep Dive |
| CVE-2023-25049 | WordPress eCommerce Product Catalog Plugin <= 3.3.4 is vulnerable to Cross Site Scripting (XSS) | impleCode | eCommerce Product Catalog Plugin for WordPress | Medium | 5.9 | 2023-04-07 11:12:17 | Deep Dive |
| CVE-2023-24003 | WordPress WP Popups Plugin <= 2.1.4.8 is vulnerable to Cross Site Scripting (XSS) | Timersys | WP Popups – WordPress Popup builder | Medium | 6.5 | 2023-04-06 08:09:15 | Deep Dive |
| CVE-2023-26536 | WordPress Sp*tify Play Button for WordPress Plugin <= 2.05 is vulnerable to Cross Site Scripting (XSS) | Jonk @ Follow me Darling | Sp*tify Play Button for WordPress | Medium | 6.5 | 2023-04-05 07:35:11 | Deep Dive |
| CVE-2023-1840 | Sp*tify Play Button for WordPress <= 2.07 - Authenticated (Administrator+) Stored Cross-Site Scripting | jonkastonka | Sp*tify Play Button for WordPress | Medium | 4.4 | 2023-04-04 19:00:13 | Deep Dive |
| CVE-2023-23977 | WordPress Heateor Social Comments Plugin <= 1.6.1 is vulnerable to Cross Site Scripting (XSS) | Team Heateor | WordPress Social Comments Plugin for Vkontakte Comments and Disqus Comments | Medium | 6.5 | 2023-04-04 12:56:36 | Deep Dive |
| CVE-2023-23878 | WordPress WP Google Map Plugin Plugin <= 4.3.9 is vulnerable to Cross Site Scripting (XSS) | flippercode | WordPress Plugin for Google Maps – WP MAPS | Medium | 5.9 | 2023-04-04 11:38:54 | Deep Dive |
| CVE-2023-23685 | WordPress Portfolio – WordPress Portfolio Plugin Plugin <= 2.8.10 is vulnerable to Cross Site Scripting (XSS) | RadiusTheme | Portfolio – WordPress Portfolio Plugin | Medium | 6.5 | 2023-04-04 11:05:20 | Deep Dive |
| CVE-2023-25040 | WordPress Shortcodes Ultimate Plugin <= 5.12.6 is vulnerable to Cross Site Scripting (XSS) | Vova Anokhin | WordPress Shortcodes Plugin — Shortcodes Ultimate | Medium | 6.5 | 2023-03-30 11:10:27 | Deep Dive |
| CVE-2023-23677 | WordPress GTmetrix for WordPress Plugin <= 0.4.5 is vulnerable to Cross Site Scripting (XSS) | GTmetrix | GTmetrix for WordPress | Low | 3.8 | 2023-03-30 10:58:01 | Deep Dive |
| CVE-2023-23670 | WordPress Fancy Comments WordPress Plugin <= 1.2.10 is vulnerable to Cross Site Scripting (XSS) | Team Heateor | Fancy Comments WordPress | Medium | 6.5 | 2023-03-30 10:44:53 | Deep Dive |
| CVE-2022-46848 | WordPress Visualizer Plugin <= 3.9.1 is vulnerable to Cross Site Scripting (XSS) | Themeisle | Visualizer: Tables and Charts Manager for WordPress | Medium | 6.5 | 2023-03-28 07:50:29 | Deep Dive |
| CVE-2022-47146 | WordPress Real Estate 7 Theme <= 3.3.1 is vulnerable to Cross Site Scripting (XSS) | Contempoinc | Real Estate 7 WordPress | High | 7.1 | 2023-03-27 14:00:50 | Deep Dive |
| CVE-2022-30705 | WordPress WordPress Ping Optimizer Plugin <= 2.35.1.2.3 is vulnerable to Cross Site Request Forgery (CSRF) | Pankaj Jha | WordPress Ping Optimizer | Medium | 5.4 | 2023-03-27 13:50:33 | Deep Dive |