VYPR

Vendor CVEs

WordPress

All CVEs

36,928 total · sorted by risk
  • CVE-2015-10116MedJun 6, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function install_new_favicon of the file admin/class-favicon-by-realfavicongenerator-admin.php. The manipulation leads to cross-site…

  • CVE-2013-10030MedJun 5, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this issue is some unknown functionality of the file wordpress-exit-box-lite.php. The manipulation leads to information disclosure. The attack may be…

  • CVE-2013-10029MedJun 5, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this vulnerability is the function exitboxadmin of the file wordpress-exit-box-lite.php. The manipulation leads to cross-site request forgery. The attack can be…

  • CVE-2015-10115MedJun 5, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress. This affects the function process_request of the file classes/class-woosidebars-sbm-converter.php. The manipulation leads to open redirect.…

  • CVE-2015-10114MedJun 5, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the function enable_custom_post_sidebars of the file classes/class-woo-sidebars.php. The manipulation of the argument sendback leads to…

  • CVE-2015-10112MedJun 5, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of the argument url leads to open redirect. It is possible to…

  • CVE-2013-10027MedJun 4, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affected is the function start/restart of the file blogger-importer.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack…

  • CVE-2023-0583MedJun 3, 2023
    risk 0.21cvss 4.3epss 0.01

    The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings…

  • CVE-2015-10109MedJun 1, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in Video Playlist and Gallery Plugin up to 1.136 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the file wp-media-cincopa.php. The manipulation leads to cross-site request forgery. The attack may…

  • CVE-2015-10108MedMay 31, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as problematic. Affected by this issue is the function displayShortcode of the file inline-gdocs-viewer.php. The manipulation leads to cross-site request forgery.…

  • CVE-2012-10015MedMay 31, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. It has been classified as problematic. Affected is the function twttr_settings_page of the file twitter.php of the component Settings Page. The manipulation leads to cross-site request forgery. It…

  • CVE-2014-125102MedMay 29, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in Bestwebsoft Relevant Plugin up to 1.0.7 on WordPress. Affected by this vulnerability is an unknown functionality of the component Thumbnail Handler. The manipulation leads to information disclosure. The attack can be…

  • CVE-2023-2715MedMay 20, 2023
    risk 0.21cvss 4.3epss 0.01

    The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_ticket' function in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers to create a support ticket that…

  • CVE-2023-2714MedMay 20, 2023
    risk 0.21cvss 4.3epss 0.01

    The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_license' functions in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2012-10010MedApr 9, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in BestWebSoft Contact Form 3.21. It has been classified as problematic. This affects the function cntctfrm_settings_page of the file contact_form.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely.…

  • CVE-2013-10025MedApr 8, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. Affected by this issue is the function exitpageadmin of the file exitpage.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. Upgrading…

  • CVE-2023-1931MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the deleteCssAndJsCacheToolbar function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access…

  • CVE-2023-1930MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the wpfc_clear_cache_of_allsites_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with…

  • CVE-2023-1929MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_purgecache_varnish_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with…

  • CVE-2023-1928MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_preload_single_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with…

  • CVE-2023-1927MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCssAndJsCacheToolbar function. This makes it possible for unauthenticated attackers to…

  • CVE-2023-1926MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCacheToolbar function. This makes it possible for unauthenticated attackers to perform…

  • CVE-2023-1925MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_clear_cache_of_allsites_callback function. This makes it possible for unauthenticated…

  • CVE-2023-1924MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_toolbar_save_settings_callback function. This makes it possible for unauthenticated…

  • CVE-2023-1923MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_remove_cdn_integration_ajax_request_callback function. This makes it possible for…

  • CVE-2023-1922MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_pause_cdn_integration_ajax_request_callback function. This makes it possible for…

  • CVE-2023-1921MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_start_cdn_integration_ajax_request_callback function. This makes it possible for…

  • CVE-2023-1920MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_purgecache_varnish_callback function. This makes it possible for unauthenticated…

  • CVE-2023-1919MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_save_settings_callback function. This makes it possible for…

  • CVE-2023-1918MedApr 6, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_callback function. This makes it possible for unauthenticated attackers…

  • CVE-2023-1870MedApr 5, 2023
    risk 0.21cvss 4.3epss 0.00

    The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation on the saveLang function. This makes it possible for unauthenticated attackers to change the plugin's…

  • CVE-2023-1346MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.00

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_page_cache function. This makes it possible for unauthenticated…

  • CVE-2023-1345MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.00

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the queue_posts function. This makes it possible for unauthenticated attackers…

  • CVE-2023-1344MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.00

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the uucss_update_rule function. This makes it possible for unauthenticated…

  • CVE-2023-1343MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.00

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the attach_rule function. This makes it possible for unauthenticated attackers…

  • CVE-2023-1342MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.00

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect function. This makes it possible for unauthenticated…

  • CVE-2023-1341MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.00

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated…

  • CVE-2023-1340MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.00

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_uucss_logs function. This makes it possible for unauthenticated…

  • CVE-2023-1339MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.01

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the uucss_update_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with…

  • CVE-2023-1338MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.01

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the attach_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with…

  • CVE-2023-1337MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.01

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with…

  • CVE-2023-1336MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.01

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with…

  • CVE-2023-1335MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.01

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the ucss_connect function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with…

  • CVE-2023-1334MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.01

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the queue_posts function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with…

  • CVE-2023-1333MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.01

    The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_page_cache function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with…

  • CVE-2014-125093MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability has been found in Ad Blocking Detector Plugin up to 1.2.1 on WordPress and classified as problematic. This vulnerability affects unknown code of the file ad-blocking-detector.php. The manipulation leads to information disclosure. The attack can be initiated…

  • CVE-2023-1028MedFeb 28, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Meta SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.3. This is due to missing or incorrect nonce validation on the setIgnore function. This makes it possible for unauthenticated attackers to update plugin options…

  • CVE-2023-1027MedFeb 28, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the checkAllCategoryInSitemap function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level…

  • CVE-2023-1026MedFeb 28, 2023
    risk 0.21cvss 4.3epss 0.01

    The WP Meta SEO plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the listPostsCategory function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to get…

  • CVE-2023-1024MedFeb 28, 2023
    risk 0.21cvss 4.3epss 0.01

    The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the regenerateSitemaps function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to…

Page 688 of 739