VYPR

Vendor CVEs

WordPress

All CVEs

33,189 total · sorted by risk
  • CVE-2021-28121CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.02

    Virtual Robots.txt before 1.10 does not block HTML tags in the robots.txt field.

  • CVE-2021-24385CriJul 12, 2021
    risk 0.64cvss 9.8epss 0.03

    The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL…

  • CVE-2020-24142CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open…

  • CVE-2021-34624CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.07

    A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 -…

  • CVE-2021-34623CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 -…

  • CVE-2021-34622CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects…

  • CVE-2021-24384CriJul 6, 2021
    risk 0.64cvss 9.8epss 0.02

    The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have…

  • CVE-2021-24375CriJul 6, 2021
    risk 0.64cvss 9.8epss 0.03

    Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unauthenticated attacker access to arbitrary files in the server file system, and to…

  • CVE-2021-24376CriJun 21, 2021
    risk 0.64cvss 9.8epss 0.04

    The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a…

  • CVE-2021-24361CriJun 21, 2021
    risk 0.64cvss 9.8epss 0.02

    In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.

  • CVE-2013-20002CriJun 17, 2021
    risk 0.64cvss 9.8epss 0.04

    Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.

  • CVE-2021-24347HigJun 14, 2021
    risk 0.64cvss 8.8epss 0.54

    The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php…

  • CVE-2021-24314CriMay 17, 2021
    risk 0.64cvss 9.8epss 0.02

    The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue

  • CVE-2021-24236CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.07

    The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along…

  • CVE-2021-24240CriApr 22, 2021
    risk 0.64cvss 9.8epss 0.03

    The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.

  • CVE-2021-24223CriApr 12, 2021
    risk 0.64cvss 9.8epss 0.02

    The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case…

  • CVE-2021-24222CriApr 12, 2021
    risk 0.64cvss 9.8epss 0.02

    The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file…

  • CVE-2021-24215CriApr 12, 2021
    risk 0.64cvss 9.8epss 0.10

    An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a…

  • CVE-2021-24212CriApr 5, 2021
    risk 0.64cvss 9.8epss 0.08

    The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

  • CVE-2021-24171CriApr 5, 2021
    risk 0.64cvss 9.8epss 0.02

    The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the…

  • CVE-2021-24148CriMar 18, 2021
    risk 0.64cvss 9.8epss 0.03

    A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

  • CVE-2021-24139CriMar 18, 2021
    risk 0.64cvss 9.8epss 0.05

    Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

  • CVE-2021-26754CriFeb 8, 2021
    risk 0.64cvss 9.8epss 0.05

    wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.

  • CVE-2012-10001CriJan 6, 2021
    risk 0.64cvss 9.8epss 0.03

    The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.

  • CVE-2020-35590CriDec 21, 2020
    risk 0.64cvss 9.8epss 0.04

    LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP…

  • CVE-2020-5664CriNov 16, 2020
    risk 0.64cvss 9.8epss 0.03

    Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2020-22276CriNov 4, 2020
    risk 0.64cvss 9.8epss 0.03

    WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.

  • CVE-2020-28035CriNov 2, 2020
    risk 0.64cvss 9.8epss 0.04

    WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

  • CVE-2020-5624CriAug 28, 2020
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2020-12832CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.07

    WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

  • CVE-2020-6010HigApr 30, 2020
    risk 0.64cvss 8.8epss 0.49

    LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

  • CVE-2020-11928CriApr 20, 2020
    risk 0.64cvss 9.8epss 0.04

    In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.

  • CVE-2020-11673CriApr 13, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php…

  • CVE-2020-11514CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.09

    The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

  • CVE-2020-11548CriApr 5, 2020
    risk 0.64cvss 9.8epss 0.05

    The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.

  • CVE-2020-6009CriApr 1, 2020
    risk 0.64cvss 9.8epss 0.02

    LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.

  • CVE-2020-7947CriApr 1, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting…

  • CVE-2020-6008CriMar 31, 2020
    risk 0.64cvss 9.8epss 0.04

    LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution

  • CVE-2019-12498CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.02

    The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.

  • CVE-2020-10564CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.09

    An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.

  • CVE-2018-14502CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.03

    controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.

  • CVE-2020-10257CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.09

    The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe…

  • CVE-2020-9006CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.09

    The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary…

  • CVE-2013-1401CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll.

  • CVE-2013-1400CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.

  • CVE-2012-4919CriJan 22, 2020
    risk 0.64cvss 9.8epss 0.03

    Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability

  • CVE-2020-7109CriJan 22, 2020
    risk 0.64cvss 9.8epss 0.02

    The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.

  • CVE-2016-11018CriJan 21, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().

  • CVE-2019-19589CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.02

    The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the…

  • CVE-2014-9013HigNov 6, 2019
    risk 0.64cvss 8.8epss 0.48

    The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.

Page 28 of 664