Vendor CVEs
WordPress
All CVEs
33,189 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-28121 | Cri | 0.64 | 9.8 | 0.02 | Aug 12, 2021 | Virtual Robots.txt before 1.10 does not block HTML tags in the robots.txt field. | ||
| CVE-2021-24385 | Cri | 0.64 | 9.8 | 0.03 | Jul 12, 2021 | The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL… | ||
| CVE-2020-24142 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2021 | Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open… | ||
| CVE-2021-34624 | Cri | 0.64 | 9.8 | 0.07 | Jul 7, 2021 | A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 -… | ||
| CVE-2021-34623 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2021 | A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 -… | ||
| CVE-2021-34622 | Cri | 0.64 | 9.8 | 0.04 | Jul 7, 2021 | A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects… | ||
| CVE-2021-24384 | Cri | 0.64 | 9.8 | 0.02 | Jul 6, 2021 | The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have… | ||
| CVE-2021-24375 | Cri | 0.64 | 9.8 | 0.03 | Jul 6, 2021 | Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unauthenticated attacker access to arbitrary files in the server file system, and to… | ||
| CVE-2021-24376 | Cri | 0.64 | 9.8 | 0.04 | Jun 21, 2021 | The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a… | ||
| CVE-2021-24361 | Cri | 0.64 | 9.8 | 0.02 | Jun 21, 2021 | In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues. | ||
| CVE-2013-20002 | Cri | 0.64 | 9.8 | 0.04 | Jun 17, 2021 | Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file. | ||
| CVE-2021-24347 | Hig | 0.64 | 8.8 | 0.54 | Jun 14, 2021 | The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php… | ||
| CVE-2021-24314 | Cri | 0.64 | 9.8 | 0.02 | May 17, 2021 | The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue | ||
| CVE-2021-24236 | Cri | 0.64 | 9.8 | 0.07 | May 6, 2021 | The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along… | ||
| CVE-2021-24240 | Cri | 0.64 | 9.8 | 0.03 | Apr 22, 2021 | The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability. | ||
| CVE-2021-24223 | Cri | 0.64 | 9.8 | 0.02 | Apr 12, 2021 | The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case… | ||
| CVE-2021-24222 | Cri | 0.64 | 9.8 | 0.02 | Apr 12, 2021 | The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file… | ||
| CVE-2021-24215 | Cri | 0.64 | 9.8 | 0.10 | Apr 12, 2021 | An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a… | ||
| CVE-2021-24212 | Cri | 0.64 | 9.8 | 0.08 | Apr 5, 2021 | The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp. | ||
| CVE-2021-24171 | Cri | 0.64 | 9.8 | 0.02 | Apr 5, 2021 | The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the… | ||
| CVE-2021-24148 | Cri | 0.64 | 9.8 | 0.03 | Mar 18, 2021 | A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address. | ||
| CVE-2021-24139 | Cri | 0.64 | 9.8 | 0.05 | Mar 18, 2021 | Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter. | ||
| CVE-2021-26754 | Cri | 0.64 | 9.8 | 0.05 | Feb 8, 2021 | wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection. | ||
| CVE-2012-10001 | Cri | 0.64 | 9.8 | 0.03 | Jan 6, 2021 | The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts. | ||
| CVE-2020-35590 | Cri | 0.64 | 9.8 | 0.04 | Dec 21, 2020 | LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP… | ||
| CVE-2020-5664 | Cri | 0.64 | 9.8 | 0.03 | Nov 16, 2020 | Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors. | ||
| CVE-2020-22276 | Cri | 0.64 | 9.8 | 0.03 | Nov 4, 2020 | WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry. | ||
| CVE-2020-28035 | Cri | 0.64 | 9.8 | 0.04 | Nov 2, 2020 | WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. | ||
| CVE-2020-5624 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2020 | SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | ||
| CVE-2020-12832 | Cri | 0.64 | 9.8 | 0.07 | May 13, 2020 | WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. | ||
| CVE-2020-6010 | Hig | 0.64 | 8.8 | 0.49 | Apr 30, 2020 | LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection | ||
| CVE-2020-11928 | Cri | 0.64 | 9.8 | 0.04 | Apr 20, 2020 | In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin. | ||
| CVE-2020-11673 | Cri | 0.64 | 9.8 | 0.04 | Apr 13, 2020 | An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php… | ||
| CVE-2020-11514 | Cri | 0.64 | 9.8 | 0.09 | Apr 7, 2020 | The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint. | ||
| CVE-2020-11548 | Cri | 0.64 | 9.8 | 0.05 | Apr 5, 2020 | The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed. | ||
| CVE-2020-6009 | Cri | 0.64 | 9.8 | 0.02 | Apr 1, 2020 | LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection. | ||
| CVE-2020-7947 | Cri | 0.64 | 9.8 | 0.03 | Apr 1, 2020 | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting… | ||
| CVE-2020-6008 | Cri | 0.64 | 9.8 | 0.04 | Mar 31, 2020 | LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution | ||
| CVE-2019-12498 | Cri | 0.64 | 9.8 | 0.02 | Mar 20, 2020 | The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism. | ||
| CVE-2020-10564 | Cri | 0.64 | 9.8 | 0.09 | Mar 13, 2020 | An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call. | ||
| CVE-2018-14502 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2020 | controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters. | ||
| CVE-2020-10257 | Cri | 0.64 | 9.8 | 0.09 | Mar 10, 2020 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe… | ||
| CVE-2020-9006 | Cri | 0.64 | 9.8 | 0.09 | Feb 17, 2020 | The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary… | ||
| CVE-2013-1401 | Cri | 0.64 | 9.8 | 0.05 | Feb 13, 2020 | Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll. | ||
| CVE-2013-1400 | Cri | 0.64 | 9.8 | 0.03 | Feb 13, 2020 | Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action. | ||
| CVE-2012-4919 | Cri | 0.64 | 9.8 | 0.03 | Jan 22, 2020 | Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability | ||
| CVE-2020-7109 | Cri | 0.64 | 9.8 | 0.02 | Jan 22, 2020 | The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. | ||
| CVE-2016-11018 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2020 | An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback(). | ||
| CVE-2019-19589 | Cri | 0.64 | 9.8 | 0.02 | Dec 5, 2019 | The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the… | ||
| CVE-2014-9013 | Hig | 0.64 | 8.8 | 0.48 | Nov 6, 2019 | The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user. |
- risk 0.64cvss 9.8epss 0.02
Virtual Robots.txt before 1.10 does not block HTML tags in the robots.txt field.
- risk 0.64cvss 9.8epss 0.03
The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL…
- risk 0.64cvss 9.8epss 0.02
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open…
- risk 0.64cvss 9.8epss 0.07
A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 -…
- risk 0.64cvss 9.8epss 0.02
A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 -…
- risk 0.64cvss 9.8epss 0.04
A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects…
- risk 0.64cvss 9.8epss 0.02
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have…
- risk 0.64cvss 9.8epss 0.03
Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unauthenticated attacker access to arbitrary files in the server file system, and to…
- risk 0.64cvss 9.8epss 0.04
The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a…
- risk 0.64cvss 9.8epss 0.02
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.
- risk 0.64cvss 9.8epss 0.04
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.
- risk 0.64cvss 8.8epss 0.54
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php…
- risk 0.64cvss 9.8epss 0.02
The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue
- risk 0.64cvss 9.8epss 0.07
The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along…
- risk 0.64cvss 9.8epss 0.03
The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.
- risk 0.64cvss 9.8epss 0.02
The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case…
- risk 0.64cvss 9.8epss 0.02
The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file…
- risk 0.64cvss 9.8epss 0.10
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a…
- risk 0.64cvss 9.8epss 0.08
The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.
- risk 0.64cvss 9.8epss 0.02
The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the…
- risk 0.64cvss 9.8epss 0.03
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.
- risk 0.64cvss 9.8epss 0.05
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
- risk 0.64cvss 9.8epss 0.05
wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.
- risk 0.64cvss 9.8epss 0.03
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.
- risk 0.64cvss 9.8epss 0.04
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP…
- risk 0.64cvss 9.8epss 0.03
Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors.
- risk 0.64cvss 9.8epss 0.03
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
- risk 0.64cvss 9.8epss 0.04
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- risk 0.64cvss 9.8epss 0.07
WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.
- risk 0.64cvss 8.8epss 0.49
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
- risk 0.64cvss 9.8epss 0.04
In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
- risk 0.64cvss 9.8epss 0.04
An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php…
- risk 0.64cvss 9.8epss 0.09
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
- risk 0.64cvss 9.8epss 0.05
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
- risk 0.64cvss 9.8epss 0.02
LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting…
- risk 0.64cvss 9.8epss 0.04
LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution
- risk 0.64cvss 9.8epss 0.02
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
- risk 0.64cvss 9.8epss 0.09
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
- risk 0.64cvss 9.8epss 0.03
controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.
- risk 0.64cvss 9.8epss 0.09
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe…
- risk 0.64cvss 9.8epss 0.09
The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary…
- risk 0.64cvss 9.8epss 0.05
Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll.
- risk 0.64cvss 9.8epss 0.03
Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.
- risk 0.64cvss 9.8epss 0.03
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
- risk 0.64cvss 9.8epss 0.02
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().
- risk 0.64cvss 9.8epss 0.02
The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the…
- risk 0.64cvss 8.8epss 0.48
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.
Page 28 of 664