VYPR

Vendor CVEs

WordPress

All CVEs

36,965 total · sorted by risk
  • CVE-2025-12348MedDec 12, 2025
    risk 0.27cvss 5.3epss 0.00

    The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.9.10. This is due to the plugin not properly verifying that a user is authorized to perform an action in…

  • CVE-2025-13440MedDec 12, 2025
    risk 0.27cvss 5.3epss 0.00

    The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.10. This is due to a missing capability check on the deleteWishlist() function. This makes it possible for authenticated attackers, with…

  • CVE-2025-63008MedDec 9, 2025
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.16.7.

  • CVE-2025-13748MedDec 6, 2025
    risk 0.27cvss 5.3epss 0.00

    The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user…

  • CVE-2025-13358MedDec 6, 2025
    risk 0.27cvss 5.3epss 0.00

    The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing authorization checks in versions up to, and including, 1.0.0. This is due to the plugin not performing capability checks in the `Settings::createPage()`…

  • CVE-2025-12721MedDec 6, 2025
    risk 0.27cvss 5.3epss 0.00

    The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract…

  • CVE-2025-12720MedDec 6, 2025
    risk 0.27cvss 5.3epss 0.00

    The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the handle_enqueue_only() function in all versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to…

  • CVE-2025-13620MedDec 5, 2025
    risk 0.27cvss 5.3epss 0.00

    The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache…

  • CVE-2025-12876MedDec 5, 2025
    risk 0.27cvss 5.3epss 0.00

    The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pto_delete_file AJAX action in all versions up to, and including, 5.1.19. This makes it possible for unauthenticated…

  • CVE-2025-13696MedDec 2, 2025
    risk 0.27cvss 5.3epss 0.00

    The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.5. This is due to the plugin exposing a public AJAX endpoint that retrieves form submission data without performing authorization checks to verify ownership or…

  • CVE-2025-13001MedDec 2, 2025
    risk 0.27cvss 4.1epss 0.00

    The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users, such as admin to perform SQL injection attacks

  • CVE-2025-13381MedNov 27, 2025
    risk 0.27cvss 5.3epss 0.00

    The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for…

  • CVE-2025-13157MedNov 27, 2025
    risk 0.27cvss 5.3epss 0.00

    The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the 'qode_wishlist_for_woocommerce_wishlist_table_item_callback' function due to missing validation on a user controlled key.…

  • CVE-2025-13405MedNov 25, 2025
    risk 0.27cvss 5.3epss 0.00

    The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing authorization validation on the cptb_delete_custom_taxonomy() function in all versions up to, and including, 1.9. This makes it possible for authenticated…

  • CVE-2025-13389MedNov 25, 2025
    risk 0.27cvss 5.3epss 0.00

    The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `get_order_by_id()` function in all versions up to, and including, 14. This makes it possible for…

  • CVE-2025-12877MedNov 22, 2025
    risk 0.27cvss 5.3epss 0.00

    The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability check on the panding_blood_request_action() function in all versions up to, and including, 2.1.15. This makes…

  • CVE-2025-12747MedNov 21, 2025
    risk 0.27cvss 5.3epss 0.00

    The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content without adequate protection. This makes it possible for unauthenticated attackers to extract…

  • CVE-2025-66109MedNov 21, 2025
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Octolize Shipping Plugins Cart Weight for WooCommerce woo-cart-weight allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cart Weight for WooCommerce: from n/a through <= 1.9.11.

  • CVE-2025-66072MedNov 21, 2025
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47.

  • CVE-2025-12894MedNov 21, 2025
    risk 0.27cvss 5.3epss 0.00

    The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.17 via the import/export functionality and a lack of .htaccess protection. This makes it possible…

  • CVE-2025-12778MedNov 20, 2025
    risk 0.27cvss 5.3epss 0.00

    The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handle_filter_users function in all versions up to, and including, 2.3. This makes it possible for…

  • CVE-2025-12770MedNov 19, 2025
    risk 0.27cvss 5.3epss 0.00

    The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and including, 3.0.9 due to insufficient API key validation using loose equality comparison. This makes it possible for unauthenticated attackers to retrieve personally…

  • CVE-2025-12681MedNov 13, 2025
    risk 0.27cvss 5.3epss 0.00

    The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.0 via the 'ajax_get_comment' function. This makes it possible for unauthenticated attackers to extract sensitive data…

  • CVE-2025-12891MedNov 13, 2025
    risk 0.27cvss 5.3epss 0.00

    The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results' AJAX endpoint in all versions up to, and including, 5.1.9.4. This makes it possible for unauthenticated attackers to view all…

  • CVE-2025-12892MedNov 13, 2025
    risk 0.27cvss 5.3epss 0.00

    The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 5.1.9.4. This makes it possible for unauthenticated attackers to update the…

  • CVE-2025-12788MedNov 11, 2025
    risk 0.27cvss 5.3epss 0.00

    The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment verification to unauthenticated payment bypass in all versions up to, and including, 1.1.27. This is due to the plugin accepting client-controlled payment…

  • CVE-2025-12787MedNov 11, 2025
    risk 0.27cvss 5.3epss 0.00

    The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's "tfhb_meeting_form_submit_callback" function using insufficiently…

  • CVE-2025-11999MedNov 11, 2025
    risk 0.27cvss 5.3epss 0.00

    The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and amm_save_map_api() functions in all versions up to, and including, 1.2. This makes it possible for…

  • CVE-2025-12621MedNov 8, 2025
    risk 0.27cvss 5.3epss 0.00

    The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'create_refund' function in all versions up to, and including, 1.0.42. This makes it possible for…

  • CVE-2025-12353MedNov 8, 2025
    risk 0.27cvss 5.3epss 0.00

    The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 3.6.2. This is due to the plugin relying on a user controlled…

  • CVE-2025-22288MedNov 6, 2025
    risk 0.27cvss 4.1epss 0.00

    Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and Optimization wp-smushit allows Path Traversal.This issue affects Smush Image Compression and Optimization: from n/a through <= 3.17.0.

  • CVE-2025-12192MedNov 5, 2025
    risk 0.27cvss 5.3epss 0.00

    The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean…

  • CVE-2025-11835MedNov 5, 2025
    risk 0.27cvss 5.3epss 0.00

    The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability and validation check on the PMS_AJAX_Checkout_Handler::process_payment()…

  • CVE-2025-11816MedNov 1, 2025
    risk 0.27cvss 5.3epss 0.00

    The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disconnect_account_request() function in all versions up to, and…

  • CVE-2025-11174MedNov 1, 2025
    risk 0.27cvss 5.3epss 0.00

    The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dll_load_posts which returns a JSON table of document data without performing…

  • CVE-2025-12094MedOct 31, 2025
    risk 0.27cvss 5.3epss 0.00

    The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to IP Header Spoofing in all versions up to, and including, 1.2.53. This is due to the plugin trusting client-controlled forwarded headers (such as…

  • CVE-2025-11881MedOct 30, 2025
    risk 0.27cvss 5.3epss 0.00

    The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'myappp_verify' function in all versions up to, and including, 4.5.0. This makes it possible for unauthenticated attackers to…

  • CVE-2025-10008MedOct 30, 2025
    risk 0.27cvss 5.3epss 0.00

    The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clean_options' function in all versions up to, and including, 5.1. This makes it possible for unauthenticated…

  • CVE-2025-64296MedOct 29, 2025
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Facebook Facebook for WooCommerce facebook-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Facebook for WooCommerce: from n/a through <= 3.5.7.

  • CVE-2025-10637MedOct 25, 2025
    risk 0.27cvss 5.3epss 0.00

    The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4.9.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…

  • CVE-2025-11269MedOct 25, 2025
    risk 0.27cvss 5.3epss 0.00

    The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'approveNotice' action in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to update the…

  • CVE-2025-10694MedOct 25, 2025
    risk 0.27cvss 5.3epss 0.00

    The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `maybe_load_onboarding_wizard` function in all versions up to, and including,…

  • CVE-2025-12134MedOct 24, 2025
    risk 0.27cvss 5.3epss 0.00

    The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_popup_status() function in all versions up to, and…

  • CVE-2025-10705MedOct 23, 2025
    risk 0.27cvss 5.3epss 0.00

    The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.4.6. This is due to insufficient validation of user-supplied URLs in the PDF processing functionality. This makes it possible…

  • CVE-2025-10648MedOct 15, 2025
    risk 0.27cvss 5.3epss 0.00

    The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'moym_display_test_attributes' function in all versions up to, and including, 1.1.7. This makes it possible for…

  • CVE-2025-8484MedOct 11, 2025
    risk 0.27cvss 5.3epss 0.00

    The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

  • CVE-2025-10645MedOct 7, 2025
    risk 0.27cvss 5.3epss 0.00

    The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when debugging is enabled (default). This makes it possible for unauthenticated attackers to extract sensitive license…

  • CVE-2025-8492MedSep 11, 2025
    risk 0.27cvss 5.3epss 0.00

    The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax function in all versions up to, and including, 10.22. This makes it possible…

  • CVE-2025-58835MedSep 5, 2025
    risk 0.27cvss 5.3epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in calliko Bonus for Woo bonus-for-woo allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bonus for Woo: from n/a through <= 7.6.6.

  • CVE-2025-7956MedAug 28, 2025
    risk 0.27cvss 5.3epss 0.00

    The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in its AJAX search handler in all versions up to, and including, 4.13.1. This makes it possible for unauthenticated attackers to issue repeated AJAX requests to…

Page 665 of 740