VYPR

Vendor CVEs

WordPress

All CVEs

36,919 total · sorted by risk
  • CVE-2026-32445LowMar 13, 2026
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.35.5.

  • CVE-2025-14270LowFeb 19, 2026
    risk 0.18cvss 2.7epss 0.00

    The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action in the wa_order_number_save_number_field function. This…

  • CVE-2026-1831LowFeb 18, 2026
    risk 0.18cvss 2.7epss 0.00

    The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and activation due to missing capability checks on the 'yaymail_install_yaysmtp' AJAX action and `/yaymail/v1/addons/activate` REST endpoint in all versions up to,…

  • CVE-2025-12958LowJan 7, 2026
    risk 0.18cvss 2.7epss 0.00

    The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect capability check on the 'rankology_code_block' page in all versions up to, and including, 2.0. This makes it possible for authenticated attackers,…

  • CVE-2025-68585LowDec 24, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in Ben Balter WP Document Revisions wp-document-revisions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Document Revisions: from n/a through <= 3.7.2.

  • CVE-2025-12654LowDec 21, 2025
    risk 0.18cvss 2.7epss 0.00

    The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories…

  • CVE-2025-54004LowDec 16, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce wc-frontend-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM – Frontend Manager for WooCommerce: from n/a through <= 6.7.24.

  • CVE-2025-49300LowDec 16, 2025
    risk 0.18cvss 2.7epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option Tree custom-option-tree allows Retrieve Embedded Sensitive Data.This issue affects Traveler Option Tree: from n/a through <= 2.8.

  • CVE-2025-64255LowDec 9, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 8.0.8.

  • CVE-2025-64254LowDec 9, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in Ronald Huereca Photo Block photo-block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Block: from n/a through <= 1.5.1.

  • CVE-2025-12954LowDec 3, 2025
    risk 0.18cvss 2.7epss 0.00

    The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading to arbitrary event disclosure when to users with a role as low as Contributor.

  • CVE-2025-64352LowOct 31, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.2.4.

  • CVE-2025-10723LowOct 24, 2025
    risk 0.18cvss 2.7epss 0.00

    The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks

  • CVE-2025-10173LowSep 26, 2025
    risk 0.18cvss 2.7epss 0.00

    The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible…

  • CVE-2025-58866LowSep 5, 2025
    risk 0.18cvss 2.7epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Rami Yushuvaev Site Info site-info-dashboard-widget allows Retrieve Embedded Sensitive Data.This issue affects Site Info: from n/a through <= 1.1.

  • CVE-2025-8013LowAug 15, 2025
    risk 0.18cvss 3.8epss 0.00

    The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to…

  • CVE-2024-10098LowMay 15, 2025
    risk 0.18cvss 2.7epss 0.00

    The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain

  • CVE-2025-32205LowApr 10, 2025
    risk 0.18cvss 2.7epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Forms piotnetforms.This issue affects Piotnet Forms: from n/a through <= 1.0.30.

  • CVE-2025-31003LowApr 9, 2025
    risk 0.18cvss 2.7epss 0.01

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze squeeze allows Retrieve Embedded Sensitive Data.This issue affects Squeeze: from n/a through <= 1.6.

  • CVE-2025-30877LowMar 27, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in fatcatapps Quiz Cat quiz-cat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz Cat: from n/a through <= 3.0.8.

  • CVE-2025-1911LowMar 26, 2025
    risk 0.18cvss 2.7epss 0.00

    The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.5.0. This makes it…

  • CVE-2025-1972LowMar 22, 2025
    risk 0.18cvss 2.7epss 0.00

    The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with…

  • CVE-2024-13922LowMar 20, 2025
    risk 0.18cvss 2.7epss 0.00

    The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. This makes it possible for authenticated…

  • CVE-2024-13116LowJan 27, 2025
    risk 0.18cvss 3.8epss 0.00

    The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2024-10562LowJan 7, 2025
    risk 0.18cvss 2.7epss 0.00

    The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2024-10102LowJan 7, 2025
    risk 0.18cvss 2.7epss 0.01

    The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

  • CVE-2024-51671LowNov 19, 2024
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Otter - Gutenberg Block: from n/a through <= 3.0.3.

  • CVE-2024-10672LowNov 12, 2024
    risk 0.18cvss 2.7epss 0.01

    The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the mpg_upsert_project_source_block() function in all versions up to, and including, 4.0.2. This makes it possible for…

  • CVE-2024-8350LowSep 25, 2024
    risk 0.18cvss 2.7epss 0.00

    The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated…

  • CVE-2024-37253LowJul 9, 2024
    risk 0.18cvss 2.7epss 0.00

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDirectoryKit WP Directory Kit allows Code Injection.This issue affects WP Directory Kit: from n/a through 1.3.6.

  • CVE-2024-3073LowJun 13, 2024
    risk 0.18cvss 2.7epss 0.00

    The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.3.0. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings.…

  • CVE-2024-4214LowMay 17, 2024
    risk 0.18cvss 2.7epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a through 4.15.

  • CVE-2024-3034LowApr 27, 2024
    risk 0.18cvss 2.7epss 0.01

    The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse…

  • CVE-2024-30507LowMar 29, 2024
    risk 0.18cvss 2.7epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through 4.7.7.

  • CVE-2023-46311LowDec 20, 2023
    risk 0.18cvss 2.7epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a through 7.6.3.

  • CVE-2023-4216LowSep 4, 2023
    risk 0.18cvss 2.7epss 0.01

    The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content…

  • CVE-2023-2117LowMay 30, 2023
    risk 0.18cvss 2.7epss 0.01

    The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

  • CVE-2022-4109LowJan 2, 2023
    risk 0.18cvss 2.7epss 0.01

    The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite)

  • CVE-2021-36906LowNov 3, 2022
    risk 0.18cvss 2.7epss 0.01

    Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.

  • CVE-2022-2556LowAug 29, 2022
    risk 0.18cvss 2.7epss 0.01

    The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan…

  • CVE-2022-1690LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection

  • CVE-2022-1689LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQL statement when updating a note via the admin dashboard, leading to an SQL injection

  • CVE-2022-1688LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections

  • CVE-2022-1687LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it in a SQL statement via the Manage Slider Images admin page, leading to an SQL Injection

  • CVE-2022-1686LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection

  • CVE-2022-1684LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in various SQL queries, leading to SQL Injections exploitable by high privileged users such as admin

  • CVE-2022-27844LowApr 11, 2022
    risk 0.18cvss 2.7epss 0.01

    Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70

  • CVE-2021-25109LowFeb 14, 2022
    risk 0.18cvss 2.7epss 0.01

    The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high privilege users to extract data from the database as well as used to perform Cross-Site Scripting (XSS) against logged in admins by making send open a…

  • CVE-2021-24371LowAug 2, 2021
    risk 0.18cvss 2.7epss 0.01

    The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a result, a high privilege user could use that feature to…

  • CVE-2026-58038MedJul 1, 2026
    risk 0.17cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files includes/Timeline.Php, scripts/EasyTimeline.Pl. This issue affects timeline: from…

Page 690 of 739