VYPR

Vendor CVEs

WordPress

All CVEs

36,963 total · sorted by risk
  • CVE-2024-10554LowMar 25, 2025
    risk 0.23cvss 3.5epss 0.00

    The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for…

  • CVE-2025-1203LowMar 24, 2025
    risk 0.23cvss 3.5epss 0.00

    The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is…

  • CVE-2025-1062LowMar 24, 2025
    risk 0.23cvss 3.5epss 0.00

    The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is…

  • CVE-2024-13124LowMar 24, 2025
    risk 0.23cvss 3.5epss 0.00

    The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…

  • CVE-2024-10558LowMar 24, 2025
    risk 0.23cvss 3.5epss 0.00

    The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2025-1624LowMar 16, 2025
    risk 0.23cvss 3.5epss 0.00

    The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…

  • CVE-2025-1623LowMar 16, 2025
    risk 0.23cvss 3.5epss 0.00

    The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…

  • CVE-2025-1622LowMar 16, 2025
    risk 0.23cvss 3.5epss 0.00

    The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…

  • CVE-2024-13615LowMar 11, 2025
    risk 0.23cvss 3.5epss 0.00

    The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin through 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting…

  • CVE-2025-1363LowMar 9, 2025
    risk 0.23cvss 3.5epss 0.00

    The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the…

  • CVE-2024-10545LowFeb 25, 2025
    risk 0.23cvss 3.5epss 0.00

    The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is…

  • CVE-2024-13585LowFeb 21, 2025
    risk 0.23cvss 3.5epss 0.00

    The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2024-13314LowFeb 21, 2025
    risk 0.23cvss 3.5epss 0.00

    The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is…

  • CVE-2024-12173LowFeb 19, 2025
    risk 0.23cvss 3.5epss 0.00

    The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…

  • CVE-2025-0692LowFeb 13, 2025
    risk 0.23cvss 3.5epss 0.00

    The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for…

  • CVE-2024-13121LowFeb 13, 2025
    risk 0.23cvss 3.5epss 0.00

    The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site…

  • CVE-2023-24375LowDec 9, 2024
    risk 0.23cvss 3.5epss 0.00

    Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter,…

  • CVE-2024-7056LowNov 25, 2024
    risk 0.23cvss 3.5epss 0.00

    The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2024-10710LowNov 25, 2024
    risk 0.23cvss 3.5epss 0.00

    The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2024-10515LowNov 20, 2024
    risk 0.23cvss 3.5epss 0.00

    In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

  • CVE-2024-6792LowSep 6, 2024
    risk 0.23cvss 3.5epss 0.00

    The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public page.

  • CVE-2024-37234LowJul 6, 2024
    risk 0.23cvss 3.5epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.

  • CVE-2024-3920LowMay 23, 2024
    risk 0.23cvss 3.5epss 0.00

    The Flattr WordPress plugin through 1.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

  • CVE-2024-2220LowMay 23, 2024
    risk 0.23cvss 3.5epss 0.00

    The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2024-2108MedMar 29, 2024
    risk 0.23cvss 4.6epss 0.00

    The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output…

  • CVE-2023-7149LowDec 29, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in code-projects QR Code Generator 1.0. It has been classified as problematic. This affects an unknown part of the file /download.php?file=author.png. The manipulation of the argument file with the input ">…

  • CVE-2023-3209LowJul 10, 2023
    risk 0.23cvss 3.5epss 0.00

    The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.

  • CVE-2022-3343LowJan 9, 2023
    risk 0.23cvss 3.5epss 0.00

    The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer Discy WordPress themes) incorrectly tries to validate that a user already follows another in the wpqa_following_you_ajax action, allowing a user to inflate their score on the…

  • CVE-2022-2844LowAug 16, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This affects an unknown part of the file /wp/?cpmvc_id=1&cpmvc_do_action=mvparse&f=datafeed&calid=1&month_index=1&method=adddetails&id=2 of the component Calendar…

  • CVE-2022-2843LowAug 16, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /wp-admin/admin-ajax.php of the component Quick Edit. The manipulation of the argument post_title with the…

  • CVE-2017-20108LowJun 29, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in Easy Table Plugin 1.6. This affects an unknown part of the file /wordpress/wp-admin/options-general.php. The manipulation with the input "> leads to basic cross site scripting. It is possible to…

  • CVE-2017-20097LowJun 24, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.

  • CVE-2017-20096LowJun 24, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in WP-SpamFree Anti-Spam Plugin 2.1.1.4. This affects an unknown part. The manipulation leads to basic cross site scripting. It is possible to initiate the attack remotely.

  • CVE-2017-20056LowJun 16, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in weblizar User Login Log Plugin 2.2.1. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Stored). It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2017-20055LowJun 16, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2017-20054LowJun 16, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed…

  • CVE-2021-25075LowFeb 21, 2022
    risk 0.23cvss 3.5epss 0.01

    The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings,…

  • CVE-2021-25014LowFeb 14, 2022
    risk 0.23cvss 3.5epss 0.01

    The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting…

  • CVE-2026-11358MedJun 18, 2026
    risk 0.22cvss 4.4epss 0.00

    The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping.…

  • CVE-2026-9062LowJun 13, 2026
    risk 0.22cvss 3.4epss 0.00

    The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and…

  • CVE-2025-9989MedMay 13, 2026
    risk 0.22cvss 4.4epss 0.00

    The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.53.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-1055MedFeb 19, 2026
    risk 0.22cvss 4.4epss 0.00

    The TalkJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

  • CVE-2026-2281MedFeb 18, 2026
    risk 0.22cvss 4.4epss 0.00

    The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in all versions up to, and including, 0.0.4. This is due to insufficient input sanitization and output escaping on the plugin's label text option. This makes it…

  • CVE-2026-1302MedJan 24, 2026
    risk 0.22cvss 4.4epss 0.00

    The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-1191MedJan 24, 2026
    risk 0.22cvss 4.4epss 0.00

    The JavaScript Notifier plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 1.2.8. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the `wp_footer` action.…

  • CVE-2026-0725MedJan 17, 2026
    risk 0.22cvss 4.4epss 0.00

    The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

  • CVE-2025-15021MedJan 14, 2026
    risk 0.22cvss 4.4epss 0.00

    The Gotham Block Extra Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2025-13974MedJan 7, 2026
    risk 0.22cvss 4.4epss 0.00

    The Email Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email template content in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2025-14054MedDec 21, 2025
    risk 0.22cvss 4.4epss 0.00

    The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'heading_color' parameter (and multiple other styling parameters) of the `wpbforwpbakery_product_additional_information` shortcode in all versions…

  • CVE-2025-14056MedDec 13, 2025
    risk 0.22cvss 4.4epss 0.00

    The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter during custom post type import in all versions up to, and including, 1.18.1 due to insufficient input sanitization and output escaping. This makes it possible for…

Page 675 of 740