VYPR

Vendor CVEs

WordPress

All CVEs

36,965 total · sorted by risk
  • CVE-2025-0968MedFeb 19, 2025
    risk 0.27cvss 5.3epss 0.00

    The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to…

  • CVE-2024-13364MedFeb 19, 2025
    risk 0.27cvss 5.3epss 0.00

    The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_ads_files_reset() and cls_file_reset() functions in all versions up to, and including, 3.6.3. This makes it possible for unauthenticated attackers to reset the…

  • CVE-2024-13555MedFeb 18, 2025
    risk 0.27cvss 5.3epss 0.00

    The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the cancel_actions() function. This makes…

  • CVE-2025-25081MedFeb 7, 2025
    risk 0.27cvss 4.2epss 0.00

    Missing Authorization vulnerability in DeannaS Embed RSS embed-rss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Embed RSS: from n/a through <= 3.1.

  • CVE-2024-13829MedFeb 5, 2025
    risk 0.27cvss 5.3epss 0.00

    The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.0.8 via the 'attachments.php' file. This makes it possible for unauthenticated…

  • CVE-2025-0466MedFeb 4, 2025
    risk 0.27cvss 5.3epss 0.00

    The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.

  • CVE-2024-13428MedFeb 1, 2025
    risk 0.27cvss 5.3epss 0.00

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the deleteCompanyLogo() due to missing validation on a user controlled key.…

  • CVE-2024-13372MedFeb 1, 2025
    risk 0.27cvss 5.3epss 0.00

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the getresumefiledownloadbyid() and getallresumefiles() functions due to…

  • CVE-2024-13371MedFeb 1, 2025
    risk 0.27cvss 5.3epss 0.01

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary emails sending due to a missing capability check on the sendEmailToJobSeeker() function in all versions up to, and including, 2.2.6.…

  • CVE-2024-12041MedFeb 1, 2025
    risk 0.27cvss 5.3epss 0.00

    The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for…

  • CVE-2024-11090MedJan 26, 2025
    risk 0.27cvss 5.3epss 0.00

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from…

  • CVE-2024-13230MedJan 21, 2025
    risk 0.27cvss 5.3epss 0.00

    The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘SuperSocializerKey’ parameter in all versions up to, and including, 7.14 due to insufficient escaping on the user supplied…

  • CVE-2025-0318MedJan 18, 2025
    risk 0.27cvss 5.3epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This…

  • CVE-2024-10815MedJan 9, 2025
    risk 0.27cvss 4.2epss 0.00

    The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

  • CVE-2024-12712MedJan 8, 2025
    risk 0.27cvss 5.3epss 0.00

    The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order…

  • CVE-2024-12316MedJan 7, 2025
    risk 0.27cvss 5.3epss 0.00

    The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in all versions up to, and including, 4.8.5. This makes it possible for unauthenticated attackers to export popup…

  • CVE-2024-56275MedJan 7, 2025
    risk 0.27cvss 4.1epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Envato Envato Elements allows Server Side Request Forgery.This issue affects Envato Elements: from n/a through 2.0.14.

  • CVE-2024-11282MedJan 7, 2025
    risk 0.27cvss 5.3epss 0.00

    The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive…

  • CVE-2024-9697MedJan 7, 2025
    risk 0.27cvss 5.3epss 0.00

    The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tweet_settings_save() and tweet_settings_update() functions in all versions up to, and including, 1.3.4. This makes it…

  • CVE-2024-12559MedJan 7, 2025
    risk 0.27cvss 5.3epss 0.00

    The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions in all versions up to, and including, 1.8.0. This makes it possible for…

  • CVE-2023-45061MedJan 2, 2025
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in awsm.in WP Job Openings wp-job-openings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Openings: from n/a through <= 3.4.1.

  • CVE-2024-12413MedDec 25, 2024
    risk 0.27cvss 5.3epss 0.00

    The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like 'marketking_delete_team_member', 'marketkingrejectuser',…

  • CVE-2024-12103MedDec 24, 2024
    risk 0.27cvss 5.3epss 0.00

    The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.1.2 via the eos_dyn_get_content action due to insufficient restrictions on which posts can be included. This makes…

  • CVE-2024-11291MedDec 18, 2024
    risk 0.27cvss 5.3epss 0.00

    The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.4 via the WordPress core search feature. This makes it possible…

  • CVE-2024-11295MedDec 18, 2024
    risk 0.27cvss 5.3epss 0.00

    The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts…

  • CVE-2024-11280MedDec 17, 2024
    risk 0.27cvss 5.3epss 0.00

    The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts…

  • CVE-2024-11294MedDec 17, 2024
    risk 0.27cvss 5.3epss 0.00

    The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.73.9 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been…

  • CVE-2024-11712MedDec 14, 2024
    risk 0.27cvss 5.3epss 0.00

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This…

  • CVE-2024-12309MedDec 13, 2024
    risk 0.27cvss 5.3epss 0.00

    The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.4 via the get_post_status() due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2024-12579MedDec 13, 2024
    risk 0.27cvss 5.3epss 0.00

    The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 2.1.10. This is due to processing user-supplied input as a regular expression. This makes it possible for unauthenticated attackers to create…

  • CVE-2024-11351MedDec 11, 2024
    risk 0.27cvss 5.3epss 0.00

    The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.8 via the WordPress core search feature. This makes it possible for…

  • CVE-2024-12294MedDec 11, 2024
    risk 0.27cvss 5.3epss 0.00

    The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the 'get_legacy_cookies' function. This makes it possible for unauthenticated attackers to extract sensitive data including…

  • CVE-2024-11008MedDec 11, 2024
    risk 0.27cvss 5.3epss 0.00

    The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive…

  • CVE-2024-11106MedDec 10, 2024
    risk 0.27cvss 5.3epss 0.00

    The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.7 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been…

  • CVE-2024-9706MedDec 6, 2024
    risk 0.27cvss 5.3epss 0.00

    The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ucsm_activate_lite_template_lite function in all versions up to, and including, 1.0.9. This makes it possible for…

  • CVE-2024-11325MedDec 3, 2024
    risk 0.27cvss 5.2epss 0.01

    The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject…

  • CVE-2024-10580MedNov 27, 2024
    risk 0.27cvss 5.3epss 0.00

    The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on the submit_form() function in all versions up to, and including, 7.8.5. This makes it possible for…

  • CVE-2024-11083MedNov 27, 2024
    risk 0.27cvss 5.3epss 0.00

    The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been…

  • CVE-2024-10813MedNov 23, 2024
    risk 0.27cvss 5.3epss 0.01

    The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1 via the var_dump_table parameter. This makes it possible for unauthenticated attackers var…

  • CVE-2024-9828MedNov 21, 2024
    risk 0.27cvss 4.1epss 0.00

    The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks

  • CVE-2024-11197MedNov 21, 2024
    risk 0.27cvss 4.2epss 0.00

    The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5. This is due to permitting application password logins when user accounts are locked. This makes it possible for authenticated attackers, with existing…

  • CVE-2024-10393MedNov 21, 2024
    risk 0.27cvss 5.3epss 0.01

    The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers…

  • CVE-2024-10861MedNov 16, 2024
    risk 0.27cvss 5.3epss 0.00

    The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it…

  • CVE-2024-10531MedNov 13, 2024
    risk 0.27cvss 5.3epss 0.01

    The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with…

  • CVE-2024-10529MedNov 13, 2024
    risk 0.27cvss 5.3epss 0.01

    The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with…

  • CVE-2024-10540MedNov 2, 2024
    risk 0.27cvss 5.3epss 0.01

    The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL Injection via the 'service' parameter of the bookingpress_form shortcode in all versions up to, and including, 1.1.16 due to insufficient escaping on the user…

  • CVE-2024-47358MedNov 1, 2024
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Daniel Iser Popup Maker popup-maker.This issue affects Popup Maker: from n/a through <= 1.19.2.

  • CVE-2024-43277MedNov 1, 2024
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in AyeCode Ltd UsersWP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.15.

  • CVE-2024-9700MedOct 31, 2024
    risk 0.27cvss 5.3epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.36.0 via the submit_quizzes() function due to missing validation on the 'entry_id' user…

  • CVE-2024-49683MedOct 24, 2024
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Schema & Structured Data for WP & AMP: from n/a through <= 1.3.5.

Page 667 of 740