VYPR

Vendor CVEs

WordPress

All CVEs

36,948 total · sorted by risk
  • CVE-2024-2258MedApr 27, 2024
    risk 0.22cvss 4.4epss 0.00

    The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name autofilled into forms in all versions up to, and including, 1.15.24 due to insufficient input sanitization and…

  • CVE-2024-1571MedApr 9, 2024
    risk 0.22cvss 4.4epss 0.00

    The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in all versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2024-2656MedApr 6, 2024
    risk 0.22cvss 4.4epss 0.00

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to insufficient input…

  • CVE-2024-0614MedMar 13, 2024
    risk 0.22cvss 4.4epss 0.01

    The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2023-4839MedMar 13, 2024
    risk 0.22cvss 4.4epss 0.00

    The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

  • CVE-2024-0602MedFeb 29, 2024
    risk 0.22cvss 4.4epss 0.01

    The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2024-0630MedFeb 5, 2024
    risk 0.22cvss 4.4epss 0.00

    The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, 4.23.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2024-0618MedJan 27, 2024
    risk 0.22cvss 4.4epss 0.01

    The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output…

  • CVE-2024-0688MedJan 25, 2024
    risk 0.22cvss 4.4epss 0.00

    The "WebSub (FKA. PubSubHubbub)" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2024-22308LowJan 24, 2024
    risk 0.22cvss 3.4epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.4.1.

  • CVE-2023-6924MedJan 11, 2024
    risk 0.22cvss 4.4epss 0.00

    The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

  • CVE-2023-6446MedJan 11, 2024
    risk 0.22cvss 4.4epss 0.00

    The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.40 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2023-34382MedDec 19, 2023
    risk 0.22cvss 4.4epss 0.01

    Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from…

  • CVE-2023-6160LowNov 22, 2023
    risk 0.22cvss 3.3epss 0.01

    The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 7.4.2 via the maybe_serve_export function. This makes it possible for authenticated attackers, with administrator or LMS manager…

  • CVE-2023-4648MedOct 20, 2023
    risk 0.22cvss 4.4epss 0.00

    The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2023-3996MedOct 20, 2023
    risk 0.22cvss 4.4epss 0.00

    The ARMember Lite - Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.0.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2023-4271MedOct 20, 2023
    risk 0.22cvss 4.4epss 0.00

    The Photospace Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘psres_button_size’ parameter in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2023-4423MedSep 27, 2023
    risk 0.22cvss 4.4epss 0.01

    The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.1.37.1 due to insufficient input sanitization and output escaping.…

  • CVE-2023-4636MedSep 5, 2023
    risk 0.22cvss 4.4epss 0.01

    The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2022-27856LowMay 10, 2023
    risk 0.22cvss 3.4epss 0.00

    Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Atlas Gondal Export All URLs plugin <= 4.1 versions.

  • CVE-2023-1470MedMar 17, 2023
    risk 0.22cvss 4.4epss 0.00

    The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2023-0553MedJan 27, 2023
    risk 0.22cvss 4.4epss 0.01

    The Quick Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2022-45082LowNov 18, 2022
    risk 0.22cvss 3.4epss 0.00

    Multiple Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabilities in Accordions plugin <= 2.0.3 on WordPress via &addons-style-name and &accordions_or_faqs_license_key.

  • CVE-2021-36864LowOct 28, 2022
    risk 0.22cvss 3.4epss 0.00

    Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.

  • CVE-2022-40215LowSep 23, 2022
    risk 0.22cvss 3.4epss 0.00

    Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress.

  • CVE-2022-37328LowSep 23, 2022
    risk 0.22cvss 3.4epss 0.00

    Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin <= 1.0.5 at WordPress.

  • CVE-2022-38703LowSep 23, 2022
    risk 0.22cvss 3.4epss 0.00

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <= 9.2 at WordPress

  • CVE-2022-36343LowAug 1, 2022
    risk 0.22cvss 3.4epss 0.01

    Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.

  • CVE-2022-30536LowJul 21, 2022
    risk 0.22cvss 3.4epss 0.01

    Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin <= 6.0.7 at WordPress.

  • CVE-2021-36849LowJul 20, 2022
    risk 0.22cvss 3.4epss 0.01

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons plugin <= 3.8.1 at WordPress.

  • CVE-2022-29452LowJun 15, 2022
    risk 0.22cvss 3.4epss 0.01

    Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress.

  • CVE-2022-29432LowMay 20, 2022
    risk 0.22cvss 3.4epss 0.01

    Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-Plugins wpDataTables plugin <= 2.1.27 on WordPress via &data-link-text, &data-link-url, &data, &data-shortcode, &data-star-num vulnerable parameters.

  • CVE-2021-36844LowMay 2, 2022
    risk 0.22cvss 3.4epss 0.01

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress.

  • CVE-2022-27848LowApr 14, 2022
    risk 0.22cvss 3.4epss 0.01

    Authenticated (admin+ user) Stored Cross-Site Scripting (XSS) in Modern Events Calendar Lite (WordPress plugin) <= 6.5.1

  • CVE-2021-36910LowApr 11, 2022
    risk 0.22cvss 3.4epss 0.01

    Authenticated (admin user role) Stored Cross-Site Scripting (XSS) in WP-Appbox (WordPress plugin) <= 4.3.20.

  • CVE-2021-36848LowApr 11, 2022
    risk 0.22cvss 3.4epss 0.01

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versions <= 2.0.4

  • CVE-2022-25618LowApr 4, 2022
    risk 0.22cvss 3.4epss 0.01

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpDataTables (WordPress plugin) versions <= 2.1.27

  • CVE-2022-25610LowMar 25, 2022
    risk 0.22cvss 3.4epss 0.01

    Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code. However, the attack requires specific conditions, making it hard to exploit.

  • CVE-2021-36889LowDec 20, 2021
    risk 0.22cvss 3.4epss 0.01

    Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.6).

  • CVE-2026-5093MedAug 22, 2026
    risk 0.21cvss 4.3epss 0.00

    The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the 'gspb_update_global_wp_settings' function that only verifies…

  • CVE-2026-4244MedAug 22, 2026
    risk 0.21cvss 4.3epss 0.00

    The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all versions up to, and including, 3.0.11. This is due to the function not verifying that the user has…

  • CVE-2026-4245MedAug 22, 2026
    risk 0.21cvss 4.3epss 0.00

    The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the…

  • CVE-2025-11729MedAug 19, 2026
    risk 0.21cvss 4.3epss 0.00

    The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for…

  • CVE-2025-10308MedAug 14, 2026
    risk 0.21cvss 4.3epss 0.00

    The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete…

  • CVE-2026-12385MedJul 13, 2026
    risk 0.21cvss 4.3epss 0.00

    The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles and…

  • CVE-2026-15080MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4.

  • CVE-2026-12955MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in…

  • CVE-2026-11364MedJun 27, 2026
    risk 0.21cvss 4.3epss 0.00

    The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and including 0.8.9. This is due to a missing capability check and missing nonce verification in the __invoke() methods of…

  • CVE-2026-9013MedJun 19, 2026
    risk 0.21cvss 4.3epss 0.00

    The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the bogo_rest_create_post_translation. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the raw…

  • CVE-2026-10623MedJun 18, 2026
    risk 0.21cvss 4.3epss 0.00

    The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.0 via the 'rule_id' parameter due to missing validation on a user controlled key. This…

Page 676 of 739