| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-28070 | WordPress WP eMember plugin <= v10.2.2 - Broken Access Control vulnerability | Tips and Tricks HQ | WP eMember | Medium | 5.3 | 2026-03-19 05:20:04 | Deep Dive |
| CVE-2026-28073 | WordPress WP eMember theme <= v10.2.2 - Reflected Cross Site Scripting (XSS) vulnerability | Tips and Tricks HQ | WP eMember | High | 7.1 | 2026-03-19 05:18:57 | Deep Dive |
| CVE-2025-11767 | Tips Shortcode <= 0.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | fpcorso | Tips Shortcode | Medium | 6.4 | 2025-11-21 07:31:50 | Deep Dive |
| CVE-2025-11627 | Site Checkup AI Troubleshooting with Wizard and Tips for Each Issue <= 1.47 - Unauthenticated Log File Poisoning | sminozzi | Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue | Medium | 6.5 | 2025-10-30 05:28:27 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-3112 | Quotes and Tips < 1.45 - Admin+ Arbitrary File Upload | Unknown | Quotes and Tips by BestWebSoft | 中危 | - | 2024-07-12 06:00:06 | Deep Dive |
| CVE-2024-34599 | SAMSUNG Mobile devices 安全漏洞 | Samsung Mobile | Tips | Medium | 4.0 | 2024-07-02 09:23:40 | Deep Dive |
| CVE-2023-48285 | WordPress Accept Stripe Payments plugin <= 2.0.79 - Content Injection vulnerability | Tips and Tricks HQ | Stripe Payments | Medium | 5.3 | 2024-06-04 10:23:00 | Deep Dive |
| CVE-2024-30527 | WordPress WP Express Checkout plugin <= 2.3.7 - Price Manipulation vulnerability | Tips and Tricks HQ | WP Express Checkout (Accept PayPal Payments) | High | 7.5 | 2024-05-17 08:21:00 | Deep Dive |
| CVE-2024-33591 | WordPress Easy Accept Payments for PayPal plugin <= 4.9.10 - Broken Access Control vulnerability | Tips and Tricks HQ | Easy Accept Payments | High | 7.5 | 2024-04-29 10:10:53 | Deep Dive |
| CVE-2022-47588 | WordPress Simple Photo Gallery Plugin <= v1.8.1 is vulnerable to SQL Injection | Tips and Tricks HQ, Peter Petreski | Simple Photo Gallery | 超危 | - | 2023-11-03 11:14:44 | Deep Dive |
| CVE-2023-22685 | WordPress Category Specific RSS feed Subscription Plugin <= v2.2 is vulnerable to Cross Site Scripting (XSS) | Tips and Tricks HQ, Ruhul Amin | Category Specific RSS feed Subscription | Medium | 5.9 | 2023-05-12 15:24:46 | Deep Dive |
| CVE-2023-22691 | WordPress Category Specific RSS feed Subscription Plugin <= v2.1 is vulnerable to Cross Site Request Forgery (CSRF) | Tips and Tricks HQ, Ruhul Amin | Category Specific RSS feed Subscription | Medium | 4.3 | 2023-05-03 07:33:42 | Deep Dive |
| CVE-2022-47163 | WordPress WP CSV to Database Plugin <= 2.6 is vulnerable to Cross Site Request Forgery (CSRF) | Tips and Tricks HQ, josh401 | WP CSV to Database – Insert CSV file content into WordPress database | Low | 3.1 | 2023-03-14 06:48:02 | Deep Dive |
| CVE-2021-20782 | Software License Manager 跨站请求伪造漏洞 | Tips and Tricks HQ | Software License Manager | 高危 | - | 2021-07-14 01:20:28 | Deep Dive |
| CVE-2020-5651 | WordPress Simple Download Monitor SQL注入漏洞 | Tips and Tricks HQ | Simple Download Monitor | 高危 | - | 2020-10-21 15:15:18 | Deep Dive |
| CVE-2020-5650 | WordPress Simple Download Monitor 跨站脚本漏洞 | Tips and Tricks HQ | Simple Download Monitor | 中危 | - | 2020-10-21 15:15:17 | Deep Dive |
| CVE-2017-2171 | 多款WordPress插件跨站脚本漏洞 | BestWebSoft | Captcha | 中危 | - | 2017-05-22 16:00:00 | Deep Dive |