VYPR

Vendor CVEs

WordPress

All CVEs

36,919 total · sorted by risk
  • CVE-2022-0384MedMar 7, 2022
    risk 0.21cvss 4.3epss 0.01

    The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog

  • CVE-2022-0164MedFeb 21, 2022
    risk 0.21cvss 4.3epss 0.00

    The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users

  • CVE-2016-10148MedJan 18, 2017
    risk 0.21cvss 4.3epss 0.02

    The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin…

  • CVE-2015-5715MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.06

    The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.

  • CVE-2024-13900MedFeb 21, 2025
    risk 0.20cvss 4.1epss 0.00

    The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject PHP Code in multisite environments.

  • CVE-2024-10527LowJan 7, 2025
    risk 0.20cvss 3.1epss 0.00

    The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the motech_spacer_callback() function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level access…

  • CVE-2023-23825LowDec 9, 2024
    risk 0.20cvss 3.1epss 0.01

    Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.

  • CVE-2024-7501MedAug 16, 2024
    risk 0.20cvss 4.2epss 0.00

    The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on the download_theme() function. This makes it possible for…

  • CVE-2024-6434LowJul 4, 2024
    risk 0.20cvss 3.1epss 0.01

    The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. This is due to processing user-supplied input as a regular expression. This makes it possible for authenticated…

  • CVE-2024-5770MedJun 8, 2024
    risk 0.20cvss 4.2epss 0.00

    The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_setting' function in versions up to, and including, 1.66. This makes it possible for authenticated attackers,…

  • CVE-2023-22676LowDec 29, 2023
    risk 0.20cvss 3.1epss 0.00

    Missing Authorization vulnerability in Anders Thorborg.This issue affects Anders Thorborg: from n/a through 1.4.12.

  • CVE-2023-6120MedDec 9, 2023
    risk 0.20cvss 4.1epss 0.00

    The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 via the upload_certificate_file function. This makes it possible for administrators to upload .pem or .crt files to arbitrary locations on the server.

  • CVE-2023-2010LowJul 4, 2023
    risk 0.20cvss 3.1epss 0.00

    The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Condition that may allow a single user to vote multiple times on a poll.

  • CVE-2023-2599LowJun 9, 2023
    risk 0.20cvss 3.1epss 0.00

    The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and…

  • CVE-2023-2608LowMay 17, 2023
    risk 0.20cvss 3.1epss 0.00

    The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to missing nonce verification on the projects_list function and…

  • CVE-2022-47163LowMar 14, 2023
    risk 0.20cvss 3.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, josh401 WP CSV to Database – Insert CSV file content into WordPress plugin <= 2.6 versions.

  • CVE-2022-4309LowJan 16, 2023
    risk 0.20cvss 3.1epss 0.00

    The Subscribe2 WordPress plugin before 10.38 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete arbitrary users by knowing their email via a CSRF attack.

  • CVE-2022-4102LowJan 9, 2023
    risk 0.20cvss 3.1epss 0.00

    The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts…

  • CVE-2022-42494LowNov 8, 2022
    risk 0.20cvss 3.0epss 0.01

    Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.

  • CVE-2022-33994LowJul 30, 2022
    risk 0.20cvss 3.0epss 0.01

    The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by…

  • CVE-2022-29454LowJul 20, 2022
    risk 0.20cvss 3.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated.

  • CVE-2022-25613MedApr 4, 2022
    risk 0.20cvss 4.1epss 0.01

    Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.

  • CVE-2022-0279LowFeb 21, 2022
    risk 0.20cvss 3.1epss 0.00

    The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users

  • CVE-2024-7388MedAug 13, 2024
    risk 0.19cvss 4.0epss 0.00

    The WP Bannerize Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via banner alt data in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-77003LowAug 23, 2026
    risk 0.18cvss 2.7epss 0.00

    The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability.

  • CVE-2026-14187LowAug 22, 2026
    risk 0.18cvss 2.7epss 0.00

    The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.

  • CVE-2026-13176LowAug 21, 2026
    risk 0.18cvss 2.7epss 0.00

    The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts.

  • CVE-2026-19435LowAug 21, 2026
    risk 0.18cvss 2.7epss 0.00

    The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft…

  • CVE-2026-19085LowAug 21, 2026
    risk 0.18cvss 2.7epss 0.00

    The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable.

  • CVE-2026-16577LowAug 21, 2026
    risk 0.18cvss 2.7epss 0.00

    The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their…

  • CVE-2026-19699LowAug 20, 2026
    risk 0.18cvss 2.7epss 0.00

    The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.

  • CVE-2026-19406LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names,…

  • CVE-2026-14826LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the…

  • CVE-2026-14825LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.

  • CVE-2026-13173LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and…

  • CVE-2026-16957LowAug 9, 2026
    risk 0.18cvss 2.7epss 0.00

    The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published…

  • CVE-2026-14225LowAug 6, 2026
    risk 0.18cvss 2.7epss 0.00

    The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with…

  • CVE-2025-15674LowAug 6, 2026
    risk 0.18cvss 2.7epss 0.00

    The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read…

  • CVE-2026-16746LowAug 5, 2026
    risk 0.18cvss 2.7epss 0.00

    The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.

  • CVE-2026-16070LowAug 4, 2026
    risk 0.18cvss 2.7epss 0.00

    The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request parameter that is different from the one used in the write operation, allowing users with Contributor-level…

  • CVE-2026-16276LowAug 3, 2026
    risk 0.18cvss 2.7epss 0.00

    The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators…

  • CVE-2026-16274LowAug 3, 2026
    risk 0.18cvss 2.7epss 0.00

    The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site…

  • CVE-2026-15231LowAug 3, 2026
    risk 0.18cvss 2.7epss 0.00

    The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts…

  • CVE-2026-15939LowAug 2, 2026
    risk 0.18cvss 2.7epss 0.00

    The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission…

  • CVE-2026-14214LowAug 1, 2026
    risk 0.18cvss 2.7epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the…

  • CVE-2026-14195LowAug 1, 2026
    risk 0.18cvss 2.7epss 0.00

    The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft…

  • CVE-2026-14188LowJul 30, 2026
    risk 0.18cvss 2.7epss 0.00

    The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.

  • CVE-2026-10753LowJun 24, 2026
    risk 0.18cvss 2.7epss 0.00

    The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing access (such as Editors) to modify a site-wide Site Kit by Google WordPress…

  • CVE-2026-39510LowApr 8, 2026
    risk 0.18cvss 2.7epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a…

  • CVE-2026-3339LowMar 21, 2026
    risk 0.18cvss 2.7epss 0.00

    The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and including, 2.1.1 via the `kbd_open_upload_dir` AJAX action. This is due to insufficient validation of the `kbd_path` parameter, which is only sanitized with…

Page 689 of 739