VYPR

Vendor CVEs

Tipsandtricks Hq

All CVEs

78 total · sorted by risk
  • CVE-2016-10888CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.

  • CVE-2016-10887CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.

  • CVE-2015-9310CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.

  • CVE-2021-24693CriNov 8, 2021
    risk 0.59cvss 9.0epss 0.01

    The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered…

  • CVE-2024-6075HigJul 15, 2024
    risk 0.57cvss 8.8epss 0.00

    The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2024-5080HigJul 13, 2024
    risk 0.57cvss 8.8epss 0.01

    The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server

  • CVE-2024-5076HigJul 13, 2024
    risk 0.57cvss 8.8epss 0.00

    The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2022-3898HigNov 29, 2022
    risk 0.57cvss 8.8epss 0.00

    The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce validation on various functions including the affiliates_menu method. This makes it possible for…

  • CVE-2021-24696HigJan 24, 2022
    risk 0.57cvss 8.8epss 0.01

    The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3)…

  • CVE-2021-24711HigOct 11, 2021
    risk 0.57cvss 8.8epss 0.01

    The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack

  • CVE-2021-20782HigJul 14, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2020-5651HigOct 21, 2020
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.

  • CVE-2019-5993HigSep 12, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2024-4749HigJun 4, 2024
    risk 0.54cvss 8.3epss 0.00

    The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

  • CVE-2021-24695HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.02

    The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and…

  • CVE-2024-5715HigJul 13, 2024
    risk 0.46cvss 7.1epss 0.00

    The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2024-5287HigJul 13, 2024
    risk 0.46cvss 7.1epss 0.00

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change them via a CSRF attack

  • CVE-2024-5744MedJul 13, 2024
    risk 0.44cvss 6.8epss 0.00

    The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

  • CVE-2024-5284MedJul 13, 2024
    risk 0.44cvss 6.8epss 0.00

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

  • CVE-2024-5077MedJul 13, 2024
    risk 0.44cvss 6.8epss 0.00

    The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

  • CVE-2022-47588MedNov 3, 2023
    risk 0.44cvss 6.7epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Peter Petreski Simple Photo Gallery simple-photo-gallery allows SQL Injection.This issue affects Simple Photo Gallery: from n/a through v1.8.1.

  • CVE-2025-3890MedMay 1, 2025
    risk 0.42cvss 6.4epss 0.00

    The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping on user supplied attributes.…

  • CVE-2025-3874MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.00

    The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to lack of randomization of a user controlled key. This makes it possible for unauthenticated attackers to access customer…

  • CVE-2024-6133MedAug 12, 2024
    risk 0.42cvss 6.5epss 0.00

    The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2022-44737MedNov 22, 2022
    risk 0.42cvss 6.5epss 0.00

    Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.

  • CVE-2021-24692MedMar 14, 2022
    risk 0.42cvss 6.5epss 0.01

    The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

  • CVE-2021-24735MedOct 18, 2021
    risk 0.42cvss 6.5epss 0.01

    The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack.

  • CVE-2024-5081MedAug 5, 2024
    risk 0.40cvss 6.1epss 0.00

    The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

  • CVE-2024-6076MedJul 15, 2024
    risk 0.40cvss 6.1epss 0.00

    The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2024-6074MedJul 15, 2024
    risk 0.40cvss 6.1epss 0.00

    The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2024-6073MedJul 15, 2024
    risk 0.40cvss 6.1epss 0.00

    The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2024-6072MedJul 15, 2024
    risk 0.40cvss 6.1epss 0.00

    The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

  • CVE-2024-5283MedJul 13, 2024
    risk 0.40cvss 6.1epss 0.00

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2024-5282MedJul 13, 2024
    risk 0.40cvss 6.1epss 0.00

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2024-5281MedJul 13, 2024
    risk 0.40cvss 6.1epss 0.00

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2024-5079MedJul 13, 2024
    risk 0.40cvss 6.1epss 0.00

    The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks

  • CVE-2022-3896MedNov 29, 2022
    risk 0.40cvss 6.1epss 0.01

    The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2022-2189MedJul 25, 2022
    risk 0.40cvss 6.1epss 0.01

    The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

  • CVE-2021-24697MedNov 8, 2021
    risk 0.40cvss 6.1epss 0.01

    The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

  • CVE-2021-24560MedSep 13, 2021
    risk 0.40cvss 6.1epss 0.01

    The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

  • CVE-2020-5650MedOct 21, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

  • CVE-2016-10867MedAug 13, 2019
    risk 0.40cvss 6.1epss 0.01

    The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.

  • CVE-2016-10866MedAug 13, 2019
    risk 0.40cvss 6.1epss 0.01

    The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.

  • CVE-2016-10868MedAug 13, 2019
    risk 0.40cvss 6.1epss 0.01

    The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.

  • CVE-2015-9294MedAug 13, 2019
    risk 0.40cvss 6.1epss 0.01

    The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.

  • CVE-2015-9293MedAug 13, 2019
    risk 0.40cvss 6.1epss 0.01

    The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.

  • CVE-2024-5075MedJul 13, 2024
    risk 0.38cvss 5.9epss 0.00

    The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2023-22685MedMay 12, 2023
    risk 0.38cvss 5.9epss 0.00

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.2 versions.

  • CVE-2024-5285MedJul 29, 2024
    risk 0.36cvss 5.5epss 0.00

    The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack

  • CVE-2022-3897MedNov 29, 2022
    risk 0.36cvss 5.5epss 0.01

    The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Page 1 of 2