Vendor CVEs
WordPress
All CVEs
33,189 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-9479 | Cri | 0.64 | 9.8 | 0.03 | Oct 10, 2019 | The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php. | ||
| CVE-2015-9471 | Cri | 0.64 | 9.8 | 0.04 | Oct 10, 2019 | The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload. | ||
| CVE-2015-9467 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2019 | The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter. | ||
| CVE-2015-9466 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2019 | The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable. | ||
| CVE-2019-17072 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2019 | The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php. | ||
| CVE-2015-9452 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2019 | The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter. | ||
| CVE-2015-9451 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2019 | The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter. | ||
| CVE-2015-9450 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2019 | The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_cc pmfb_tid parameter. | ||
| CVE-2015-9435 | Cri | 0.64 | 9.8 | 0.02 | Sep 26, 2019 | The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers. | ||
| CVE-2016-11000 | Cri | 0.64 | 9.8 | 0.02 | Sep 20, 2019 | The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter. | ||
| CVE-2016-10995 | Cri | 0.64 | 9.8 | 0.02 | Sep 18, 2019 | The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php. | ||
| CVE-2016-10972 | Cri | 0.64 | 9.8 | 0.09 | Sep 16, 2019 | The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. | ||
| CVE-2016-10971 | Cri | 0.64 | 9.8 | 0.02 | Sep 16, 2019 | The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an e-mail address is required. | ||
| CVE-2017-18634 | Cri | 0.64 | 9.8 | 0.02 | Sep 16, 2019 | The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. | ||
| CVE-2016-10955 | Cri | 0.64 | 9.8 | 0.02 | Sep 13, 2019 | The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking. | ||
| CVE-2016-10954 | Cri | 0.64 | 9.8 | 0.02 | Sep 13, 2019 | The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload. | ||
| CVE-2019-15896 | Cri | 0.64 | 9.8 | 0.07 | Sep 10, 2019 | An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account… | ||
| CVE-2017-18605 | Cri | 0.64 | 9.8 | 0.02 | Sep 10, 2019 | The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection. | ||
| CVE-2018-21013 | Cri | 0.64 | 9.8 | 0.02 | Sep 9, 2019 | The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php. | ||
| CVE-2019-15872 | Cri | 0.64 | 9.8 | 0.02 | Sep 3, 2019 | The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings. | ||
| CVE-2019-15826 | Cri | 0.64 | 9.8 | 0.03 | Aug 30, 2019 | The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field. | ||
| CVE-2019-15825 | Cri | 0.64 | 9.8 | 0.03 | Aug 30, 2019 | The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass. | ||
| CVE-2019-15824 | Cri | 0.64 | 9.8 | 0.03 | Aug 30, 2019 | The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass. | ||
| CVE-2019-15823 | Cri | 0.64 | 9.8 | 0.09 | Aug 30, 2019 | The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass. | ||
| CVE-2019-15822 | Cri | 0.64 | 9.8 | 0.03 | Aug 30, 2019 | The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal. | ||
| CVE-2019-15819 | Cri | 0.64 | 9.8 | 0.03 | Aug 30, 2019 | The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication. | ||
| CVE-2019-15780 | Cri | 0.64 | 9.8 | 0.02 | Aug 29, 2019 | The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. | ||
| CVE-2018-21007 | Cri | 0.64 | 9.8 | 0.02 | Aug 29, 2019 | The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads. | ||
| CVE-2012-6719 | Cri | 0.64 | 9.8 | 0.02 | Aug 28, 2019 | The sharebar plugin before 1.2.2 for WordPress has SQL injection. | ||
| CVE-2015-9352 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The wp-polls plugin before 2.72 for WordPress has SQL injection. | ||
| CVE-2015-9351 | Cri | 0.64 | 9.8 | 0.03 | Aug 27, 2019 | The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button. | ||
| CVE-2019-15659 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969. | ||
| CVE-2019-15646 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The rsvpmaker plugin before 6.2 for WordPress has SQL injection. | ||
| CVE-2018-21005 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The bbp-move-topics plugin before 1.1.6 for WordPress has code injection. | ||
| CVE-2018-21004 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection. | ||
| CVE-2018-21003 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The buddyforms plugin before 2.2.8 for WordPress has SQL injection. | ||
| CVE-2016-10935 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation. | ||
| CVE-2015-9344 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The link-log plugin before 2.1 for WordPress has SQL injection. | ||
| CVE-2018-20987 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. | ||
| CVE-2015-9334 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The email-newsletter plugin through 20.15 for WordPress has SQL injection. | ||
| CVE-2013-7483 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion. | ||
| CVE-2016-10930 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number. | ||
| CVE-2014-10389 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. | ||
| CVE-2014-10387 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection. | ||
| CVE-2019-15322 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion. | ||
| CVE-2019-15321 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. | ||
| CVE-2019-15320 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. | ||
| CVE-2019-15319 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. | ||
| CVE-2018-20985 | Cri | 0.64 | 9.8 | 0.08 | Aug 22, 2019 | The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec. | ||
| CVE-2018-20984 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The patreon-connect plugin before 1.2.2 for WordPress has Object Injection. |
- risk 0.64cvss 9.8epss 0.03
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
- risk 0.64cvss 9.8epss 0.04
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
- risk 0.64cvss 9.8epss 0.02
The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.
- risk 0.64cvss 9.8epss 0.02
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.
- risk 0.64cvss 9.8epss 0.02
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.
- risk 0.64cvss 9.8epss 0.02
The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.
- risk 0.64cvss 9.8epss 0.02
The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter.
- risk 0.64cvss 9.8epss 0.02
The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_cc pmfb_tid parameter.
- risk 0.64cvss 9.8epss 0.02
The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
- risk 0.64cvss 9.8epss 0.02
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
- risk 0.64cvss 9.8epss 0.02
The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.
- risk 0.64cvss 9.8epss 0.09
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
- risk 0.64cvss 9.8epss 0.02
The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an e-mail address is required.
- risk 0.64cvss 9.8epss 0.02
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
- risk 0.64cvss 9.8epss 0.02
The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.
- risk 0.64cvss 9.8epss 0.02
The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
- risk 0.64cvss 9.8epss 0.07
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account…
- risk 0.64cvss 9.8epss 0.02
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
- risk 0.64cvss 9.8epss 0.02
The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.
- risk 0.64cvss 9.8epss 0.02
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
- risk 0.64cvss 9.8epss 0.03
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
- risk 0.64cvss 9.8epss 0.03
The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.
- risk 0.64cvss 9.8epss 0.03
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.
- risk 0.64cvss 9.8epss 0.09
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
- risk 0.64cvss 9.8epss 0.03
The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.
- risk 0.64cvss 9.8epss 0.03
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
- risk 0.64cvss 9.8epss 0.02
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
- risk 0.64cvss 9.8epss 0.02
The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.
- risk 0.64cvss 9.8epss 0.02
The sharebar plugin before 1.2.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The wp-polls plugin before 2.72 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.03
The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.
- risk 0.64cvss 9.8epss 0.02
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
- risk 0.64cvss 9.8epss 0.02
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.
- risk 0.64cvss 9.8epss 0.02
The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.
- risk 0.64cvss 9.8epss 0.02
The link-log plugin before 2.1 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
- risk 0.64cvss 9.8epss 0.02
The email-newsletter plugin through 20.15 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.
- risk 0.64cvss 9.8epss 0.02
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
- risk 0.64cvss 9.8epss 0.02
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
- risk 0.64cvss 9.8epss 0.02
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion.
- risk 0.64cvss 9.8epss 0.02
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
- risk 0.64cvss 9.8epss 0.02
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
- risk 0.64cvss 9.8epss 0.02
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
- risk 0.64cvss 9.8epss 0.08
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.
- risk 0.64cvss 9.8epss 0.02
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
Page 29 of 664