VYPR

Vendor CVEs

WordPress

All CVEs

36,963 total · sorted by risk
  • CVE-2024-1790MedApr 9, 2024
    risk 0.25cvss 4.9epss 0.01

    The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the…

  • CVE-2024-0628LowFeb 7, 2024
    risk 0.25cvss 3.8epss 0.00

    The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level access and above, to make…

  • CVE-2023-5126MedOct 25, 2023
    risk 0.25cvss 4.9epss 0.00

    The Delete Me plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'plugin_delete_me' shortcode in versions up to, and including, 3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

  • CVE-2023-3404MedAug 31, 2023
    risk 0.25cvss 4.9epss 0.01

    The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0. This is due to the passphrase and iv being hardcoded in the 'pm_encrypt_decrypt_pass' function and used across all sites running the…

  • CVE-2023-2354MedAug 31, 2023
    risk 0.25cvss 4.9epss 0.00

    The CHP Ads Block Detector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings reachable though an AJAX action in versions up to, and including, 3.9.4 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2023-2434LowMay 31, 2023
    risk 0.25cvss 3.8epss 0.01

    The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to…

  • CVE-2023-2735MedMay 20, 2023
    risk 0.25cvss 4.9epss 0.00

    The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gh_form' shortcode in versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

  • CVE-2023-23677LowMar 30, 2023
    risk 0.25cvss 3.8epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in GTmetrix GTmetrix for WordPress plugin <= 0.4.5 versions.

  • CVE-2022-4031LowNov 29, 2022
    risk 0.25cvss 3.8epss 0.01

    The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.8 via the 'file' parameter which does not properly restrict files to be edited in the context of the plugin. This makes it possible with attackers, with…

  • CVE-2021-36865LowSep 30, 2022
    risk 0.25cvss 3.8epss 0.00

    Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.

  • CVE-2022-2046MedAug 8, 2022
    risk 0.25cvss 4.9epss 0.01

    The Directorist WordPress plugin before 7.2.3 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets the zip files from. This could allow administrators to run code on the server, which is a problem in…

  • CVE-2022-29423LowMay 6, 2022
    risk 0.25cvss 3.8epss 0.01

    Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.

  • CVE-2022-1001MedApr 18, 2022
    risk 0.25cvss 4.8epss 0.05

    The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" settings, but does not sanitise and escape it server side, allowing high privilege users such as admin to perform Cross-Site attacks even when the unfiltered_html…

  • CVE-2021-24242LowApr 22, 2021
    risk 0.25cvss 3.8epss 0.01

    The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerability through the maliciously constructed sub_page parameter of the plugin's Tools, allowing high privilege users to include any local php file

  • CVE-2017-6816MedMar 12, 2017
    risk 0.25cvss 4.9epss 0.03

    In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.

  • CVE-2026-19220LowAug 26, 2026
    risk 0.24cvss 3.7epss 0.00

    The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.

  • CVE-2026-18356LowAug 21, 2026
    risk 0.24cvss 3.7epss 0.00

    The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate…

  • CVE-2026-14213LowAug 13, 2026
    risk 0.24cvss 3.7epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked…

  • CVE-2026-18044LowAug 12, 2026
    risk 0.24cvss 3.7epss 0.00

    The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body…

  • CVE-2026-17016LowAug 10, 2026
    risk 0.24cvss 3.7epss 0.00

    The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the…

  • CVE-2026-15452MedAug 5, 2026
    risk 0.24cvss 4.7epss 0.00

    The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query String in all versions up to, and including, 6.11.3 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2026-16993LowAug 5, 2026
    risk 0.24cvss 3.7epss 0.00

    The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an…

  • CVE-2026-11366LowAug 4, 2026
    risk 0.24cvss 3.7epss 0.00

    The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets…

  • CVE-2026-11882LowAug 1, 2026
    risk 0.24cvss 3.7epss 0.00

    The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access…

  • CVE-2026-15381LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

  • CVE-2026-14927LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer…

  • CVE-2026-14862LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.

  • CVE-2026-14849LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII)…

  • CVE-2026-12002MedJul 8, 2026
    risk 0.24cvss 4.7epss 0.00

    The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes…

  • CVE-2026-49043MedJun 15, 2026
    risk 0.24cvss 4.7epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions.

  • CVE-2026-5721MedApr 20, 2026
    risk 0.24cvss 4.7epss 0.00

    The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.0.4. This is due to insufficient input sanitization and output escaping in the…

  • CVE-2026-22204LowMar 13, 2026
    risk 0.24cvss 3.7epss 0.00

    wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers can craft a malicious cookie value that, when processed through urldecode() and…

  • CVE-2026-2722MedMar 7, 2026
    risk 0.24cvss 4.8epss 0.00

    The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.26.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-2721MedMar 7, 2026
    risk 0.24cvss 4.8epss 0.00

    The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-1787MedFeb 21, 2026
    risk 0.24cvss 4.8epss 0.00

    The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_migrated_data' function in all versions up to, and including, 4.1.0. This makes it possible for…

  • CVE-2026-1582LowFeb 18, 2026
    risk 0.24cvss 3.7epss 0.00

    The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.14 via the export download endpoint. This is due to a PHP type juggling vulnerability in the security token comparison which uses loose comparison…

  • CVE-2026-1356MedFeb 12, 2026
    risk 0.24cvss 4.8epss 0.00

    The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.5.1 via the PassthruLoader::load_image_source function. This makes it possible for unauthenticated…

  • CVE-2025-12826MedDec 4, 2025
    risk 0.24cvss 4.8epss 0.00

    The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to the plugin not verifying that a user has the required capability to perform actions in the "cptui_process_post_type" function. This…

  • CVE-2025-11244LowOct 25, 2025
    risk 0.24cvss 3.7epss 0.00

    The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar…

  • CVE-2025-11167MedOct 11, 2025
    risk 0.24cvss 4.7epss 0.00

    The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.5.6. This is due to insufficient validation on the redirect url supplied via the 'redirect_url'…

  • CVE-2025-58204MedAug 27, 2025
    risk 0.24cvss 4.7epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress allows Phishing.This issue affects Podlove Podcast Publisher: from n/a through <= 4.2.5.

  • CVE-2025-8767MedAug 12, 2025
    risk 0.24cvss 4.8epss 0.00

    The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16.17 via the 'download_csv_players' and 'download_csv_games' functions. This makes it possible for authenticated attackers, with Administrator-level access and…

  • CVE-2025-4654LowJul 2, 2025
    risk 0.24cvss 3.7epss 0.00

    The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper authorization checks on the make_signature function in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to…

  • CVE-2025-4955MedJun 18, 2025
    risk 0.24cvss 4.7epss 0.00

    The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

  • CVE-2024-8542MedMay 15, 2025
    risk 0.24cvss 4.8epss 0.00

    The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2024-7762LowMay 15, 2025
    risk 0.24cvss 3.7epss 0.00

    The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes

  • CVE-2024-13730MedMay 15, 2025
    risk 0.24cvss 4.8epss 0.00

    The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…

  • CVE-2024-13729MedMay 15, 2025
    risk 0.24cvss 4.8epss 0.00

    The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…

  • CVE-2024-12808MedMay 15, 2025
    risk 0.24cvss 4.8epss 0.00

    The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks…

  • CVE-2024-12770MedMay 15, 2025
    risk 0.24cvss 4.8epss 0.00

    The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

Page 672 of 740