The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before
The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privile
The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high pr
The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which co
The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high pr
The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allo
The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sani
The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it bac
The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it bac
The ClipArt WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page,
The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting
The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in th
The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of
The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which
The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high
The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high
The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers
The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as
The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high p
The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation
The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, whi
The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attr
The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which co
The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which cou
The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its
The jwp-a11y WordPress plugin through 4.1.7 does not sanitise and escape some of its settings, which could allow high pr
The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, whi
The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing C
The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could
The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes befor
The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow
The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow
The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which
The Nokaut Offers Box WordPress plugin through 1.4.0 does not sanitize and escape some of its settings, which could allo
The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its b
The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some par
The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of
The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allo
The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow hig
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some
The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its sett
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its sett
The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelera
The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible t
The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high
The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a S
This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrust
The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started