The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloade
The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers
The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which
The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow hig
In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you
The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high
The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could all
The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow hig
The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow hi
The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high
The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before o
The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow h
The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as
The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting
The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high priv
The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirectio
The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access control
The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outpu
The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, wh
The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, whic
The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow
The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could a
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its short
The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could all
The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing use
The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blo
The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, wh
The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could
The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin
The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, w
The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the p
The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the
The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it ba
The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which cou
The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which co
The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in th
The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which cou
The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the p
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its setting
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some
The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high priv
The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could
The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high priv
The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high pr
The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h
The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could
The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started