VYPR

Vendor CVEs

WordPress

All CVEs

36,965 total · sorted by risk
  • CVE-2024-0908MedMay 2, 2024
    risk 0.27cvss 5.3epss 0.01

    The Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the apbPosts() function hooked via an AJAX action in all versions up to, and including, 1.13.4.…

  • CVE-2024-3682MedApr 26, 2024
    risk 0.27cvss 5.3epss 0.01

    The WP STAGING and WP STAGING Pro plugins for WordPress are vulnerable to Sensitive Information Exposure in versions up to, and including, 3.4.3, and versions up to, and including, 5.4.3, respectively, via the ajaxSendReport function. This makes it possible for unauthenticated…

  • CVE-2024-3678MedApr 26, 2024
    risk 0.27cvss 5.3epss 0.01

    The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password protected posts.

  • CVE-2024-3733MedApr 25, 2024
    risk 0.27cvss 5.3epss 0.01

    The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(),…

  • CVE-2024-32078MedApr 24, 2024
    risk 0.27cvss 4.1epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.44.7212.

  • CVE-2023-52211MedApr 12, 2024
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.0.0.

  • CVE-2024-2966MedApr 11, 2024
    risk 0.27cvss 5.3epss 0.00

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.5.6 via the element_pack_ajax_search function. This makes it…

  • CVE-2024-2974MedApr 9, 2024
    risk 0.27cvss 5.3epss 0.01

    The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated…

  • CVE-2024-1473MedMar 20, 2024
    risk 0.27cvss 5.3epss 0.01

    The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.99 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page contents via REST API thus…

  • CVE-2024-1640MedMar 13, 2024
    risk 0.27cvss 5.3epss 0.00

    The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient user validation on the bitforms_update_form_entry AJAX action in all…

  • CVE-2024-1435MedFeb 29, 2024
    risk 0.27cvss 5.3epss 0.01

    Insertion of Sensitive Information Into Sent Data vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.20.6.

  • CVE-2024-1322MedFeb 29, 2024
    risk 0.27cvss 5.3epss 0.01

    The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes…

  • CVE-2024-0978MedFeb 29, 2024
    risk 0.27cvss 5.3epss 0.00

    The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.14 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's site privacy feature and view restricted page and…

  • CVE-2024-0708MedFeb 15, 2024
    risk 0.27cvss 5.3epss 0.00

    The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.2. This makes it possible for unauthenticated attackers to access landing pages that may not…

  • CVE-2024-1122MedFeb 9, 2024
    risk 0.27cvss 5.3epss 0.00

    The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible…

  • CVE-2024-0965MedFeb 8, 2024
    risk 0.27cvss 5.3epss 0.00

    The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page…

  • CVE-2024-1110MedFeb 7, 2024
    risk 0.27cvss 5.3epss 0.01

    The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init() function in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to import the…

  • CVE-2024-1109MedFeb 7, 2024
    risk 0.27cvss 5.3epss 0.01

    The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_download() and init() functions in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to…

  • CVE-2024-1079MedFeb 7, 2024
    risk 0.27cvss 5.3epss 0.01

    The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. This makes it possible for unauthenticated attackers to fetch arbitrary quiz…

  • CVE-2024-0969MedFeb 5, 2024
    risk 0.27cvss 5.3epss 0.00

    The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Default Restriction" feature and view restricted post…

  • CVE-2024-1047MedFeb 2, 2024
    risk 0.27cvss 5.3epss 0.01

    Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to update…

  • CVE-2023-6855MedJan 11, 2024
    risk 0.27cvss 5.3epss 0.01

    The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the…

  • CVE-2023-6582MedJan 11, 2024
    risk 0.27cvss 5.3epss 0.01

    The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft,…

  • CVE-2023-51517MedDec 29, 2023
    risk 0.27cvss 4.1epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28.

  • CVE-2022-47597MedDec 20, 2023
    risk 0.27cvss 5.3epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Popup Maker Popup Maker – Popup for opt-ins, lead gen, & more.This issue affects Popup Maker – Popup for opt-ins, lead gen, & more: from n/a through 1.17.1.

  • CVE-2023-6109MedNov 14, 2023
    risk 0.27cvss 5.3epss 0.00

    The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible for unauthenticated attackers to place multiple votes on a single poll even when…

  • CVE-2023-46207MedNov 13, 2023
    risk 0.27cvss 4.1epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6.

  • CVE-2023-31219MedNov 13, 2023
    risk 0.27cvss 4.1epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.

  • CVE-2022-3622MedOct 20, 2023
    risk 0.27cvss 4.1epss 0.01

    The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings…

  • CVE-2023-4469MedOct 6, 2023
    risk 0.27cvss 5.3epss 0.00

    The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to…

  • CVE-2023-4917MedSep 13, 2023
    risk 0.27cvss 5.3epss 0.01

    The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data…

  • CVE-2023-3371MedJun 27, 2023
    risk 0.27cvss 5.3epss 0.01

    The EmbedPress plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3. This makes it possible for unauthenticated…

  • CVE-2022-32970MedMay 10, 2023
    risk 0.27cvss 4.1epss 0.00

    Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Themify Themify Portfolio Post plugin <= 1.2.4 versions.

  • CVE-2022-43458MedApr 16, 2023
    risk 0.27cvss 4.1epss 0.00

    Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Code Tides Advanced Floating Content plugin <= 1.2.1 versions.

  • CVE-2022-3244MedOct 17, 2022
    risk 0.27cvss 4.2epss 0.00

    The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce

  • CVE-2021-36915MedOct 11, 2022
    risk 0.27cvss 4.2epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on.

  • CVE-2022-40213MedSep 23, 2022
    risk 0.27cvss 4.1epss 0.00

    Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin <= 1.9.6 at WordPress.

  • CVE-2022-37339MedSep 23, 2022
    risk 0.27cvss 4.1epss 0.00

    Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 at WordPress.

  • CVE-2022-37338MedSep 23, 2022
    risk 0.27cvss 4.1epss 0.00

    Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <= 1.0.7 at WordPress.

  • CVE-2022-36390MedSep 21, 2022
    risk 0.27cvss 4.1epss 0.01

    Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.

  • CVE-2022-37407MedSep 9, 2022
    risk 0.27cvss 4.1epss 0.01

    Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.

  • CVE-2022-34347MedAug 22, 2022
    risk 0.27cvss 4.2epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

  • CVE-2022-33900MedAug 22, 2022
    risk 0.27cvss 4.1epss 0.01

    PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.

  • CVE-2022-34853MedJul 22, 2022
    risk 0.27cvss 4.1epss 0.01

    Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.

  • CVE-2022-34650MedJul 22, 2022
    risk 0.27cvss 4.1epss 0.01

    Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.

  • CVE-2022-33191MedJul 22, 2022
    risk 0.27cvss 4.1epss 0.01

    Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Chinmoy Paul's Testimonials plugin <= 3.0.1 at WordPress.

  • CVE-2022-29443MedJun 15, 2022
    risk 0.27cvss 4.1epss 0.01

    Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin <= 3.0 at WordPress.

  • CVE-2022-29406MedJun 15, 2022
    risk 0.27cvss 4.1epss 0.01

    Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in DynamicWebLab's WordPress Team Manager plugin <= 1.6.9 at WordPress.

  • CVE-2022-27859MedJun 15, 2022
    risk 0.27cvss 4.1epss 0.01

    Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.o.o. Travel Management plugin <= 2.0 at WordPress.

  • CVE-2022-29428MedMay 20, 2022
    risk 0.27cvss 4.1epss 0.01

    Cross-Site Scripting (XSS) vulnerability in Muneeb's WP Slider Plugin <= 1.4.5 at WordPress.

Page 669 of 740