VYPR

Vendor CVEs

WordPress

All CVEs

33,190 total · sorted by risk
  • CVE-2019-13413CriJul 8, 2019
    risk 0.64cvss 9.8epss 0.02

    The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php.

  • CVE-2018-16613CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction.

  • CVE-2019-11185CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.04

    The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with…

  • CVE-2019-12241CriMay 20, 2019
    risk 0.64cvss 9.8epss 0.02

    The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.

  • CVE-2019-12240CriMay 20, 2019
    risk 0.64cvss 9.8epss 0.02

    The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.

  • CVE-2012-6652CriMay 13, 2019
    risk 0.64cvss 9.8epss 0.04

    Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pageflipbook_language parameter.

  • CVE-2019-11223CriApr 18, 2019
    risk 0.64cvss 9.8epss 0.09

    An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.

  • CVE-2018-18018CriApr 15, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.

  • CVE-2018-19488CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.04

    The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote unauthenticated attackers to reset the password of a user's account.

  • CVE-2015-4615CriFeb 15, 2019
    risk 0.64cvss 9.8epss 0.02

    Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables

  • CVE-2019-7412CriFeb 5, 2019
    risk 0.64cvss 9.8epss 0.03

    The PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values.

  • CVE-2016-1000271CriFeb 4, 2019
    risk 0.64cvss 9.8epss 0.02

    Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitable if the attacker can reach the web server.

  • CVE-2018-18461CriOct 18, 2018
    risk 0.64cvss 9.8epss 0.04

    The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.

  • CVE-2015-9272CriOct 5, 2018
    risk 0.64cvss 9.8epss 0.05

    The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.

  • CVE-2015-9271CriOct 4, 2018
    risk 0.64cvss 9.8epss 0.04

    The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code,…

  • CVE-2018-17573CriSep 28, 2018
    risk 0.64cvss 9.8epss 0.03

    The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fckeditor/editor/filemanager/browser/default/browser.html, fckeditor/editor/filemanager/connectors/test.html, and…

  • CVE-2017-18345CriAug 26, 2018
    risk 0.64cvss 9.8epss 0.03

    The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=configuration.php request.

  • CVE-2018-12426CriJul 2, 2018
    risk 0.64cvss 9.8epss 0.05

    The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remote_upload request with a .php filename and the image/jpeg content type.

  • CVE-2018-12534CriJun 18, 2018
    risk 0.64cvss 9.8epss 0.01

    A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress.

  • CVE-2018-11309CriMay 28, 2018
    risk 0.64cvss 9.8epss 0.02

    Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated attacker to dump the WordPress MySQL database via an applyCoupon action in an admin-ajax.php request.

  • CVE-2018-11515CriMay 28, 2018
    risk 0.64cvss 9.8epss 0.02

    The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.

  • CVE-2014-5014CriApr 25, 2018
    risk 0.64cvss 9.8epss 0.04

    The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.

  • CVE-2014-3114CriApr 10, 2018
    risk 0.64cvss 9.8epss 0.04

    The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to execute arbitrary commands via the cmd parameter to functions/ezpz-archive-cmd.php.

  • CVE-2014-5170CriMar 29, 2018
    risk 0.64cvss 9.8epss 0.04

    The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess file contents after SA-CORE-2013-003.

  • CVE-2018-8711CriMar 14, 2018
    risk 0.64cvss 9.8epss 0.02

    A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The vulnerability is due to the lack of args/input validation on render_html…

  • CVE-2018-8710CriMar 14, 2018
    risk 0.64cvss 9.8epss 0.04

    A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemented a page redraw AJAX function accessible to anyone without…

  • CVE-2018-1000131CriMar 14, 2018
    risk 0.64cvss 9.8epss 0.02

    Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be…

  • CVE-2018-5749CriJan 23, 2018
    risk 0.64cvss 9.8epss 0.02

    install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before saving database connection information in connect.php, which might allow remote attackers to execute arbitrary PHP code via the (1)…

  • CVE-2014-4972CriJan 8, 2018
    risk 0.64cvss 9.8epss 0.05

    Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under…

  • CVE-2015-7669CriDec 27, 2017
    risk 0.64cvss 9.8epss 0.07

    Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter related to "upload file…

  • CVE-2017-15919CriOct 26, 2017
    risk 0.64cvss 9.8epss 0.02

    The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.

  • CVE-2014-8621CriOct 16, 2017
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.

  • CVE-2017-14760CriSep 27, 2017
    risk 0.64cvss 9.8epss 0.02

    SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.php.

  • CVE-2015-7670CriSep 26, 2017
    risk 0.64cvss 9.8epss 0.03

    Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) id parameter.

  • CVE-2017-14125CriSep 25, 2017
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.

  • CVE-2017-1002028CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.02

    Vulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transformation/gallery.php via $jpic parameter being unsanitized before being passed into an SQL query.

  • CVE-2017-1002027CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.03

    Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php.

  • CVE-2017-1002023CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.03

    Vulnerability in wordpress plugin Easy Team Manager v1.3.2, The code does not sanitize id before making it part of an SQL statement in file ./easy-team-manager/inc/easy_team_manager_desc_edit.php

  • CVE-2017-1002022CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.04

    Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL query.

  • CVE-2017-1002021CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.04

    Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query.

  • CVE-2017-1002020CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.04

    Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query.

  • CVE-2017-1002019CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.02

    Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and event_form.php code do not sanitize input, this allows for blind SQL injection via the event parameter.

  • CVE-2017-1002018CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.02

    Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and attendees.php code do not sanitize input, this allows for blind SQL injection via the event parameter.

  • CVE-2017-1002016CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.03

    Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticated or that they have permission to upload files.

  • CVE-2017-1002015CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.03

    Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.

  • CVE-2017-1002014CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.03

    Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.

  • CVE-2017-1002013CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.03

    Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.

  • CVE-2017-1002012CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.03

    Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.

  • CVE-2017-1002010CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.02

    Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete_media function.

  • CVE-2017-1002009CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.02

    Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function.

Page 31 of 664