Vendor CVEs
WordPress
All CVEs
33,189 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18583 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection. | ||
| CVE-2016-10923 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation. | ||
| CVE-2016-10922 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation. | ||
| CVE-2014-10384 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion. | ||
| CVE-2014-10383 | Cri | 0.64 | 9.8 | 0.03 | Aug 22, 2019 | The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion. | ||
| CVE-2019-15318 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field. | ||
| CVE-2018-20979 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type. | ||
| CVE-2017-18573 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The simple-login-log plugin before 1.1.2 for WordPress has SQL injection. | ||
| CVE-2017-18571 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316. | ||
| CVE-2017-18570 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries. | ||
| CVE-2016-10921 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection. | ||
| CVE-2016-10917 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316. | ||
| CVE-2016-10916 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319. | ||
| CVE-2015-9335 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling. | ||
| CVE-2015-9333 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The cforms2 plugin before 14.6.10 for WordPress has SQL injection. | ||
| CVE-2014-10379 | Cri | 0.64 | 9.8 | 0.02 | Aug 21, 2019 | The duplicate-post plugin before 2.6 for WordPress has SQL injection. | ||
| CVE-2019-15111 | Cri | 0.64 | 9.8 | 0.02 | Aug 21, 2019 | The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue. | ||
| CVE-2016-10909 | Cri | 0.64 | 9.8 | 0.02 | Aug 21, 2019 | The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection. | ||
| CVE-2015-9330 | Cri | 0.64 | 9.8 | 0.02 | Aug 20, 2019 | The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection. | ||
| CVE-2018-20973 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion. | ||
| CVE-2017-18543 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations. | ||
| CVE-2015-9324 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection. | ||
| CVE-2014-10376 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection. | ||
| CVE-2017-18548 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The note-press plugin before 0.1.2 for WordPress has SQL injection. | ||
| CVE-2016-10904 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The olimometer plugin before 2.57 for WordPress has SQL injection. | ||
| CVE-2015-9326 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection. | ||
| CVE-2015-9325 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The visitors-online plugin before 0.4 for WordPress has SQL injection. | ||
| CVE-2016-10888 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues. | ||
| CVE-2016-10887 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues. | ||
| CVE-2016-10886 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions. | ||
| CVE-2015-9310 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues. | ||
| CVE-2019-15025 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. | ||
| CVE-2017-18514 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The simple-login-log plugin before 1.1.2 for WordPress has SQL injection. | ||
| CVE-2016-10889 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name. | ||
| CVE-2015-9316 | Cri | 0.64 | 9.8 | 0.03 | Aug 14, 2019 | The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter. | ||
| CVE-2015-9315 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The newstatpress plugin before 1.0.1 for WordPress has SQL injection. | ||
| CVE-2015-9313 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element. | ||
| CVE-2015-9301 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2019 | The liveforms plugin before 3.2.0 for WordPress has SQL injection. | ||
| CVE-2015-9298 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2019 | The events-manager plugin before 5.6 for WordPress has code injection. | ||
| CVE-2019-14801 | Cri | 0.64 | 9.8 | 0.02 | Aug 9, 2019 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. | ||
| CVE-2019-14695 | Cri | 0.64 | 9.8 | 0.03 | Aug 6, 2019 | A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers… | ||
| CVE-2019-13572 | Cri | 0.64 | 9.8 | 0.02 | Aug 1, 2019 | The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection. | ||
| CVE-2019-14313 | Cri | 0.64 | 9.8 | 0.04 | Jul 30, 2019 | A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php. | ||
| CVE-2019-13571 | Cri | 0.64 | 9.8 | 0.04 | Jul 29, 2019 | A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. | ||
| CVE-2019-14231 | Cri | 0.64 | 9.8 | 0.05 | Jul 21, 2019 | An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no sanitization prior to use in a SQL query in getResultByPointsTrivia. This allows… | ||
| CVE-2019-14230 | Cri | 0.64 | 9.8 | 0.05 | Jul 21, 2019 | An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitization prior to use in a SQL query in saveQuestionVote. This allows an… | ||
| CVE-2019-13569 | Cri | 0.64 | 9.8 | 0.04 | Jul 19, 2019 | A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. | ||
| CVE-2019-1010104 | Cri | 0.64 | 9.8 | 0.02 | Jul 18, 2019 | TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request. | ||
| CVE-2019-13573 | Cri | 0.64 | 9.8 | 0.04 | Jul 17, 2019 | A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. | ||
| CVE-2019-13478 | Cri | 0.64 | 9.8 | 0.03 | Jul 9, 2019 | The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions. |
- risk 0.64cvss 9.8epss 0.02
The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.
- risk 0.64cvss 9.8epss 0.02
The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.
- risk 0.64cvss 9.8epss 0.02
The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.
- risk 0.64cvss 9.8epss 0.02
The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
- risk 0.64cvss 9.8epss 0.03
The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
- risk 0.64cvss 9.8epss 0.02
The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.
- risk 0.64cvss 9.8epss 0.02
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.
- risk 0.64cvss 9.8epss 0.02
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316.
- risk 0.64cvss 9.8epss 0.02
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
- risk 0.64cvss 9.8epss 0.02
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.
- risk 0.64cvss 9.8epss 0.02
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
- risk 0.64cvss 9.8epss 0.02
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
- risk 0.64cvss 9.8epss 0.02
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The duplicate-post plugin before 2.6 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue.
- risk 0.64cvss 9.8epss 0.02
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
- risk 0.64cvss 9.8epss 0.02
The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion.
- risk 0.64cvss 9.8epss 0.02
The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
- risk 0.64cvss 9.8epss 0.02
The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The note-press plugin before 0.1.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The olimometer plugin before 2.57 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The visitors-online plugin before 0.4 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
- risk 0.64cvss 9.8epss 0.02
The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
- risk 0.64cvss 9.8epss 0.02
The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
- risk 0.64cvss 9.8epss 0.02
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
- risk 0.64cvss 9.8epss 0.02
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
- risk 0.64cvss 9.8epss 0.02
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
- risk 0.64cvss 9.8epss 0.03
The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter.
- risk 0.64cvss 9.8epss 0.02
The newstatpress plugin before 1.0.1 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.
- risk 0.64cvss 9.8epss 0.02
The liveforms plugin before 3.2.0 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The events-manager plugin before 5.6 for WordPress has code injection.
- risk 0.64cvss 9.8epss 0.02
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
- risk 0.64cvss 9.8epss 0.03
A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers…
- risk 0.64cvss 9.8epss 0.02
The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.
- risk 0.64cvss 9.8epss 0.04
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
- risk 0.64cvss 9.8epss 0.04
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
- risk 0.64cvss 9.8epss 0.05
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no sanitization prior to use in a SQL query in getResultByPointsTrivia. This allows…
- risk 0.64cvss 9.8epss 0.05
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitization prior to use in a SQL query in saveQuestionVote. This allows an…
- risk 0.64cvss 9.8epss 0.04
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
- risk 0.64cvss 9.8epss 0.02
TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.
- risk 0.64cvss 9.8epss 0.04
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
- risk 0.64cvss 9.8epss 0.03
The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
Page 30 of 664