VYPR

Vendor CVEs

WordPress

All CVEs

36,944 total · sorted by risk
  • CVE-2025-0808MedFeb 12, 2025
    risk 0.21cvss 4.3epss 0.00

    The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to missing or incorrect nonce validation on the "deleteexport" action. This makes it possible for unauthenticated attackers to…

  • CVE-2024-13514MedFeb 4, 2025
    risk 0.21cvss 4.3epss 0.00

    The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.5 via the 'bsb-slider' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for…

  • CVE-2024-12046MedFeb 4, 2025
    risk 0.21cvss 4.3epss 0.00

    The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.2 via the 'namedical_elementor_template' shortcode due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2024-13607MedFeb 4, 2025
    risk 0.21cvss 4.3epss 0.00

    The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on a user controlled key. This makes it…

  • CVE-2024-13429MedFeb 1, 2025
    risk 0.21cvss 4.3epss 0.00

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the 'jobenforcedelete' due to missing validation on a user controlled key.…

  • CVE-2024-13425MedFeb 1, 2025
    risk 0.21cvss 4.3epss 0.00

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the enforcedelete() function due to missing validation on a user controlled…

  • CVE-2024-13449MedJan 25, 2025
    risk 0.21cvss 4.3epss 0.00

    The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'bf_admin_action' function in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with Subscriber-level access…

  • CVE-2024-13368MedJan 25, 2025
    risk 0.21cvss 4.3epss 0.00

    The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzify_offer_banner() function in all versions up to, and including, 1.3.4.…

  • CVE-2024-13709MedJan 25, 2025
    risk 0.21cvss 4.3epss 0.00

    The Linear plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1. This is due to missing or incorrect nonce validation on the 'linear-debug'. This makes it possible for unauthenticated attackers to reset the plugin's cache…

  • CVE-2024-10324MedJan 24, 2025
    risk 0.21cvss 4.3epss 0.00

    The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.2 via the register_controls function in widgets/offcanvas-rometheme.php. This makes it possible for authenticated attackers, with…

  • CVE-2024-13335MedJan 24, 2025
    risk 0.21cvss 4.3epss 0.00

    The Spexo Addons for Elementor – Free Elementor Addons, Widgets and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the tmpcoder_theme_install_func() function in all versions up to, and including, 1.0.14. This makes it…

  • CVE-2024-13447MedJan 22, 2025
    risk 0.21cvss 4.3epss 0.00

    The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with…

  • CVE-2024-10789MedJan 16, 2025
    risk 0.21cvss 4.3epss 0.00

    The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for unauthenticated attackers…

  • CVE-2024-13215MedJan 15, 2025
    risk 0.21cvss 4.3epss 0.01

    The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with…

  • CVE-2024-11851MedJan 15, 2025
    risk 0.21cvss 4.3epss 0.00

    The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the nitropack_rml_notification function in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with…

  • CVE-2025-22800MedJan 13, 2025
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 2.9.11.

  • CVE-2024-12606MedJan 10, 2025
    risk 0.21cvss 4.3epss 0.00

    The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the engine_request_data()…

  • CVE-2024-12616MedJan 9, 2025
    risk 0.21cvss 4.3epss 0.00

    The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 2.7.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-12605MedJan 9, 2025
    risk 0.21cvss 4.3epss 0.00

    The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5. This is due to missing or…

  • CVE-2024-12584MedJan 8, 2025
    risk 0.21cvss 4.3epss 0.00

    The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6.2 via the 'duplicate' function. This makes it possible for authenticated attackers, with Contributor-level…

  • CVE-2024-12532MedJan 7, 2025
    risk 0.21cvss 4.3epss 0.00

    The BWD Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.18 in widgets/bwdeb-content-switcher.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to…

  • CVE-2024-12033MedJan 7, 2025
    risk 0.21cvss 4.3epss 0.00

    The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sync_libraries() function in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and…

  • CVE-2024-12719MedJan 7, 2025
    risk 0.21cvss 4.3epss 0.00

    The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated attackers, with…

  • CVE-2024-10536MedJan 7, 2025
    risk 0.21cvss 4.3epss 0.00

    The FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handle_block_shortcode_export() function in all versions up to,…

  • CVE-2024-12538MedJan 7, 2025
    risk 0.21cvss 4.3epss 0.00

    The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.5 via the 'dpp_duplicate_as_draft' function. This makes it possible for authenticated attackers, with Contributor-level…

  • CVE-2023-47778MedJan 2, 2025
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control luckywp-scripts-control allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LuckyWP Scripts Control: from n/a through <= 1.2.1.

  • CVE-2024-37518MedJan 2, 2025
    risk 0.21cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through <= 6.5.1.4.

  • CVE-2024-37235MedJan 2, 2025
    risk 0.21cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Adrian Tobey Groundhogg groundhogg allows Cross Site Request Forgery.This issue affects Groundhogg: from n/a through <= 3.4.2.3.

  • CVE-2023-45765MedJan 2, 2025
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.12.6.

  • CVE-2024-12190MedDec 25, 2024
    risk 0.21cvss 4.3epss 0.00

    The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the bitform-form-entry-edit endpoint in all versions…

  • CVE-2024-9503MedDec 20, 2024
    risk 0.21cvss 4.3epss 0.00

    The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option',…

  • CVE-2024-12560MedDec 19, 2024
    risk 0.21cvss 4.3epss 0.00

    The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via the 'btn_block_duplicate_post' function. This makes it possible for authenticated…

  • CVE-2024-12340MedDec 18, 2024
    risk 0.21cvss 4.3epss 0.00

    The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the 'render' function in widgets/content-slider.php and widgets/tabs.php. This makes it possible for authenticated attackers,…

  • CVE-2024-12596MedDec 18, 2024
    risk 0.21cvss 4.3epss 0.00

    The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all versions up to, and including, 7.8.5. This makes it possible for…

  • CVE-2024-10356MedDec 17, 2024
    risk 0.21cvss 4.3epss 0.00

    The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This makes it possible for authenticated attackers, with Contributor-level access…

  • CVE-2024-54268MedDec 13, 2024
    risk 0.21cvss 4.3epss 0.01

    Missing Authorization vulnerability in Greg - SiteOrigin SiteOrigin Widgets Bundle so-widgets-bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SiteOrigin Widgets Bundle: from n/a through <= 1.64.0.

  • CVE-2024-11724MedDec 12, 2024
    risk 0.21cvss 4.3epss 0.00

    The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_script_save AJAX action in all versions up…

  • CVE-2024-11181MedDec 12, 2024
    risk 0.21cvss 4.3epss 0.00

    The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 9.9.9.3 via the 'wp_reusable_render' shortcode due to insufficient restrictions on which posts can be included. This makes it…

  • CVE-2024-12018MedDec 12, 2024
    risk 0.21cvss 4.3epss 0.00

    The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorization in all versions up to, and including, 4.1.6. Note that a nonce is used as authentication here, but the value is leaked. This makes it possible for…

  • CVE-2023-25993MedDec 9, 2024
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in WebberZone Top 10 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Top 10: from n/a through 3.2.3.

  • CVE-2024-12115MedDec 7, 2024
    risk 0.21cvss 4.3epss 0.00

    The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on the duplicate_poll() function. This makes it…

  • CVE-2024-12026MedDec 7, 2024
    risk 0.21cvss 4.3epss 0.00

    The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveFilter() function in all versions up to, and including, 1.6.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-12027MedDec 6, 2024
    risk 0.21cvss 4.3epss 0.00

    The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateFilter() and deleteFilter() functions in all versions up to, and including, 1.6.3. This makes it possible for…

  • CVE-2024-11444MedDec 6, 2024
    risk 0.21cvss 4.3epss 0.00

    The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due to missing or incorrect nonce validation on the cluevo_render_module_ui() function. This makes it possible for…

  • CVE-2024-10692MedDec 6, 2024
    risk 0.21cvss 4.3epss 0.00

    The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 via the Content Reveal widget due to insufficient restrictions on which posts can be included. This…

  • CVE-2024-11341MedDec 5, 2024
    risk 0.21cvss 4.3epss 0.00

    The Simple Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the settings_page() function. This makes it possible for unauthenticated attackers to update…

  • CVE-2024-11844MedDec 3, 2024
    risk 0.21cvss 4.3epss 0.00

    The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions up to, and including, 8.71. This makes it possible for authenticated attackers, with…

  • CVE-2024-10798MedNov 28, 2024
    risk 0.21cvss 4.3epss 0.00

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for…

  • CVE-2024-10521MedNov 27, 2024
    risk 0.21cvss 4.3epss 0.00

    The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for…

  • CVE-2024-8899MedNov 26, 2024
    risk 0.21cvss 4.3epss 0.00

    The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with…

Page 682 of 739