VYPR

Vendor CVEs

WordPress

All CVEs

36,944 total · sorted by risk
  • CVE-2025-49976MedJun 20, 2025
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in WANotifier Notifier notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notifier: from n/a through <= 2.7.12.

  • CVE-2025-3880MedJun 17, 2025
    risk 0.21cvss 4.3epss 0.00

    The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on several functions in all versions up to, and including, 19.9.0. This makes it possible for authenticated…

  • CVE-2025-6059MedJun 14, 2025
    risk 0.21cvss 4.3epss 0.00

    The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing or incorrect nonce validation on the 'OnAdminApi_CacheOpBegin' function. This makes it possible for unauthenticated…

  • CVE-2025-5930MedJun 13, 2025
    risk 0.21cvss 4.3epss 0.00

    The WP2HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to update plugin settings…

  • CVE-2025-4047MedJun 3, 2025
    risk 0.21cvss 4.3epss 0.00

    The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the ajax_full_status and ajax_dashboard_status functions in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers,…

  • CVE-2025-4431MedMay 30, 2025
    risk 0.21cvss 4.3epss 0.00

    The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fip_save_attach_featured function in all versions up to, and including, 1.6.4. This makes it possible for…

  • CVE-2025-4419MedMay 22, 2025
    risk 0.21cvss 4.3epss 0.00

    The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 via the 'path' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to access arbitrary images with allowed…

  • CVE-2025-48268MedMay 19, 2025
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in Guru Team Bot for Telegram on WooCommerce bot-for-telegram-on-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bot for Telegram on WooCommerce: from n/a through <= 1.2.6.

  • CVE-2025-4101MedMay 17, 2025
    risk 0.21cvss 4.3epss 0.00

    The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss of data due to a misconfigured capability check on the 'delete_fpm_product' function in all versions up to, and including, 4.2.22. This makes it possible…

  • CVE-2024-8009MedMay 15, 2025
    risk 0.21cvss 4.3epss 0.00

    The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

  • CVE-2025-3949MedMay 9, 2025
    risk 0.21cvss 4.3epss 0.01

    The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'seedprod_lite_get_revisisons' function in all versions up to,…

  • CVE-2025-47528MedMay 7, 2025
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in pewilliams Ovation Elements ovation-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ovation Elements: from n/a through <= 1.1.2.

  • CVE-2025-2168MedMay 1, 2025
    risk 0.21cvss 4.3epss 0.00

    The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1. This is due to…

  • CVE-2025-3452MedApr 29, 2025
    risk 0.21cvss 4.3epss 0.00

    The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'secupress_reinstall_plugins_admin_ajax_cb' function in all versions up to, and including, 2.3.9. This makes it possible for…

  • CVE-2025-3915MedApr 26, 2025
    risk 0.21cvss 4.3epss 0.00

    The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'aeropageDeletePost' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with…

  • CVE-2025-3292MedApr 12, 2025
    risk 0.21cvss 4.3epss 0.00

    The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_update_profile_details() due to missing…

  • CVE-2024-13337MedApr 12, 2025
    risk 0.21cvss 4.3epss 0.00

    The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.2. This is due to missing or incorrect nonce validation on the 'setup-wbcr_clearfy' page.…

  • CVE-2025-2871MedApr 12, 2025
    risk 0.21cvss 4.3epss 0.00

    The WordPress Mega Menu – QuadMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the ajax_dismiss_notice() function. This makes it possible for…

  • CVE-2025-30897MedMar 27, 2025
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through <= 5.5.1.

  • CVE-2025-30851MedMar 27, 2025
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.5.2.

  • CVE-2024-13737MedMar 22, 2025
    risk 0.21cvss 4.3epss 0.00

    The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. This makes…

  • CVE-2025-1314MedMar 20, 2025
    risk 0.21cvss 4.3epss 0.00

    The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5. This is due to missing or incorrect nonce validation on the ctf_clear_cache_admin() function. This makes it…

  • CVE-2025-1530MedMar 15, 2025
    risk 0.21cvss 4.3epss 0.00

    The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.9. This is due to missing nonce validation. This makes it possible for unauthenticated attackers to delete arbitrary results via a forged request granted they…

  • CVE-2024-13407MedMar 14, 2025
    risk 0.21cvss 4.3epss 0.00

    The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via the megamenu block due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level…

  • CVE-2024-13703MedMar 13, 2025
    risk 0.21cvss 4.3epss 0.00

    The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae() function in all versions up to, and including, 2.7.5. This makes it possible for authenticated attackers,…

  • CVE-2024-13430MedMar 12, 2025
    risk 0.21cvss 4.3epss 0.00

    The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can be…

  • CVE-2024-13228MedMar 11, 2025
    risk 0.21cvss 4.3epss 0.00

    The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, with Contributor-level access and above,…

  • CVE-2024-10326MedMar 8, 2025
    risk 0.21cvss 4.3epss 0.00

    The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options and reset_widgets functions in all versions up to, and including, 1.5.3. This makes it possible for authenticated…

  • CVE-2025-1322MedMar 8, 2025
    risk 0.21cvss 4.3epss 0.00

    The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the 'feed' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for…

  • CVE-2024-12114MedMar 8, 2025
    risk 0.21cvss 4.3epss 0.00

    The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing…

  • CVE-2024-13635MedMar 7, 2025
    risk 0.21cvss 4.3epss 0.00

    The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data…

  • CVE-2024-13552MedMar 7, 2025
    risk 0.21cvss 4.3epss 0.00

    The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.0 via file upload due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2025-1383MedMar 6, 2025
    risk 0.21cvss 4.3epss 0.00

    The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.2. This is due to missing or incorrect nonce validation on the ajax_transcript_delete() function. This makes it possible for unauthenticated…

  • CVE-2025-1463MedMar 5, 2025
    risk 0.21cvss 4.3epss 0.00

    The Spreadsheet Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.2. This is due to improper nonce validation within the class-wpgsi-show.php script. This makes it possible for unauthenticated attackers to…

  • CVE-2024-13546MedMar 1, 2025
    risk 0.21cvss 4.3epss 0.00

    The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.1 via the 'get_image_description' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract…

  • CVE-2024-13518MedMar 1, 2025
    risk 0.21cvss 4.3epss 0.00

    The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.12. This is due to missing or incorrect nonce validation on the 'sp_save_edited_post' function. This makes it possible for unauthenticated attackers…

  • CVE-2024-13832MedFeb 28, 2025
    risk 0.21cvss 4.3epss 0.00

    The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.8 via the 'ut_elementor' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated…

  • CVE-2024-13716MedFeb 28, 2025
    risk 0.21cvss 4.3epss 0.00

    The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_settings_callback() function in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with…

  • CVE-2025-1506MedFeb 28, 2025
    risk 0.21cvss 4.3epss 0.00

    The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function. This makes it possible…

  • CVE-2024-13217MedFeb 27, 2025
    risk 0.21cvss 4.3epss 0.00

    The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attackers, with Contributor-level access and…

  • CVE-2024-13560MedFeb 26, 2025
    risk 0.21cvss 4.3epss 0.00

    The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to…

  • CVE-2024-13873MedFeb 22, 2025
    risk 0.21cvss 4.3epss 0.00

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.8 via the deleteUserPhoto() function due to missing validation on a user…

  • CVE-2024-13883MedFeb 21, 2025
    risk 0.21cvss 4.3epss 0.00

    The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.51. This is due to missing or incorrect nonce validation on the 'save_custom_css_request' function. This makes it possible for unauthenticated…

  • CVE-2024-13855MedFeb 20, 2025
    risk 0.21cvss 4.3epss 0.00

    The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.1 via the pae_global_block shortcode due to missing validation on a user controlled key. This makes it possible for authenticated…

  • CVE-2024-13439MedFeb 15, 2025
    risk 0.21cvss 4.3epss 0.00

    The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including, 4.4.9. This makes it possible for authenticated attackers, with Subscriber-level…

  • CVE-2025-0935MedFeb 15, 2025
    risk 0.21cvss 4.3epss 0.00

    The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including, 8.3.0. This makes it possible for authenticated attackers, with Author-level access…

  • CVE-2024-13639MedFeb 13, 2025
    risk 0.21cvss 4.3epss 0.00

    The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the expmDeleteData() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with…

  • CVE-2025-0661MedFeb 13, 2025
    risk 0.21cvss 4.3epss 0.00

    The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated…

  • CVE-2024-13229MedFeb 13, 2025
    risk 0.21cvss 4.3epss 0.00

    The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated…

  • CVE-2024-13601MedFeb 12, 2025
    risk 0.21cvss 4.3epss 0.00

    The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via the 'exportusereraserequest' function due to missing validation on a user…

Page 681 of 739