VYPR

Vendor CVEs

WordPress

All CVEs

36,919 total · sorted by risk
  • CVE-2016-15027LowFeb 20, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function mtphr_post_duplicator_notice of the file includes/notices.php. The manipulation of the argument post-duplicated leads to cross…

  • CVE-2012-10007LowFeb 19, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in madgicweb BuddyStream Plugin up to 3.2.7 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file ShareBox.php. The manipulation of the argument content/link/shares leads to cross site…

  • CVE-2015-10078LowFeb 12, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in atwellpub Resend Welcome Email Plugin 1.0.1 on WordPress. This issue affects the function send_welcome_email_url of the file resend-welcome-email.php. The manipulation leads to cross site scripting. The…

  • CVE-2015-10013LowJan 5, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in WebDevStudios taxonomy-switcher Plugin up to 1.0.3 on WordPress. It has been classified as problematic. Affected is the function taxonomy_switcher_init of the file taxonomy-switcher.php. The manipulation leads to cross site scripting. It is possible…

  • CVE-2022-4632LowDec 21, 2022
    risk 0.16cvss 3.5epss 0.01

    A vulnerability has been found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 3.3.1 is able to…

  • CVE-2020-4050LowJun 12, 2020
    risk 0.16cvss 3.5epss 0.01

    In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This…

  • CVE-2026-12971LowAug 10, 2026
    risk 0.14cvss 2.2epss 0.00

    The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.

  • CVE-2026-14823LowAug 1, 2026
    risk 0.14cvss 2.2epss 0.00

    The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of…

  • CVE-2026-13235LowJul 10, 2026
    risk 0.14cvss 3.3epss 0.00

    Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.

  • CVE-2026-11909LowJul 10, 2026
    risk 0.14cvss 3.3epss 0.00

    Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.

  • CVE-2026-0682LowJan 17, 2026
    risk 0.14cvss 2.2epss 0.00

    The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.28 due to insufficient validation of user-supplied URLs in the 'audio_url' parameter. This makes it possible for authenticated attackers, with…

  • CVE-2024-6692LowAug 12, 2024
    risk 0.14cvss 3.3epss 0.00

    The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Agreement Text value in all versions up to, and including, 3.3.2 due to insufficient input…

  • CVE-2023-6164LowNov 22, 2023
    risk 0.14cvss 2.2epss 0.00

    The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficient input sanitization. This makes it possible for…

  • CVE-2023-4505LowSep 27, 2023
    risk 0.14cvss 2.2epss 0.01

    The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers,…

  • CVE-2026-3155LowApr 16, 2026
    risk 0.13cvss 3.1epss 0.00

    The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…

  • CVE-2023-7048LowJan 11, 2024
    risk 0.13cvss 3.1epss 0.00

    The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.6. This is due to missing or incorrect nonce validation in mystickymenu-contact-leads.php. This makes it possible for unauthenticated attackers to trigger…

  • CVE-2026-12102LowJun 18, 2026
    risk 0.11cvss 2.7epss 0.00

    The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter due to missing validation on a…

  • CVE-2026-2419LowFeb 18, 2026
    risk 0.11cvss 2.7epss 0.01

    The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'download_path' configuration parameter. This is due to insufficient validation of the download path setting, which allows directory traversal sequences…

  • CVE-2025-11888LowOct 25, 2025
    risk 0.11cvss 2.7epss 0.00

    The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up…

  • CVE-2024-6694LowJul 20, 2024
    risk 0.11cvss 2.7epss 0.01

    The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated attackers,…

  • CVE-2023-2252LowJan 16, 2024
    risk 0.11cvss 2.7epss 0.01

    The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

  • CVE-2015-10093LowMar 6, 2023
    risk 0.10cvss 2.6epss 0.01

    A vulnerability was found in Mark User as Spammer Plugin 1.0.0/1.0.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function user_row_actions of the file plugin/plugin.php. The manipulation of the argument url leads to cross site…

  • CVE-2015-10075LowFeb 7, 2023
    risk 0.10cvss 2.6epss 0.01

    A vulnerability was found in Custom-Content-Width 1.0. It has been declared as problematic. Affected by this vulnerability is the function override_content_width/register_settings of the file custom-content-width.php. The manipulation leads to cross site scripting. The attack…

  • CVE-2025-8606LowOct 11, 2025
    risk 0.09cvss 2.4epss 0.00

    The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 1.3.23. This is due to missing or incorrect nonce validation on the activate_plugin and deactivate_plugin functions. This makes it possible…

  • CVE-2014-125105LowJun 5, 2023
    risk 0.09cvss 2.4epss 0.01

    A vulnerability was found in Broken Link Checker Plugin up to 1.10.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function options_page of the file core/core.php of the component Settings Page. The manipulation of the argument…

  • CVE-2014-125103LowMay 31, 2023
    risk 0.09cvss 2.4epss 0.01

    A vulnerability was found in BestWebSoft Twitter Plugin up to 1.3.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function twttr_settings_page of the file twitter.php. The manipulation of the argument…

  • CVE-2015-10094LowMar 6, 2023
    risk 0.09cvss 2.4epss 0.01

    A vulnerability was found in Fastly Plugin up to 0.97 on WordPress. It has been rated as problematic. Affected by this issue is the function post of the file lib/api.php. The manipulation of the argument url leads to cross site scripting. The attack may be launched remotely.…

  • CVE-2020-4049LowJun 12, 2020
    risk 0.09cvss 2.4epss 0.03

    In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been…

  • CVE-2015-6522Aug 19, 2015
    risk 0.09cvss epss 0.74

    SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the size parameter to get_album_item.php.

  • CVE-2014-9735Jun 30, 2015
    risk 0.09cvss epss 0.76

    The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files…

  • CVE-2014-5460Sep 11, 2014
    risk 0.09cvss epss 0.71

    Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in…

  • CVE-2015-4133May 28, 2015
    risk 0.08cvss epss 0.62

    Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file…

  • CVE-2015-1172Feb 11, 2015
    risk 0.08cvss epss 0.59

    Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 and earlier for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request…

  • CVE-2014-10021Jan 13, 2015
    risk 0.08cvss epss 0.59

    Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in server/php/.

  • CVE-2007-2426May 2, 2007
    risk 0.08cvss epss 0.63

    PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the myPath parameter.

  • CVE-2023-5775LowFeb 26, 2024
    risk 0.07cvss 2.2epss 0.00

    The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated…

  • CVE-2023-4506LowSep 27, 2023
    risk 0.07cvss 2.2epss 0.01

    The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with…

  • CVE-2012-4915May 29, 2014
    risk 0.07cvss epss 0.50

    Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php.

  • CVE-2008-1060Feb 28, 2008
    risk 0.07cvss epss 0.44

    Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via the text parameter.

  • CVE-2008-1059Feb 28, 2008
    risk 0.07cvss epss 0.48

    PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter.

  • CVE-2007-2484May 3, 2007
    risk 0.07cvss epss 0.45

    PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

  • CVE-2007-2485May 3, 2007
    risk 0.07cvss epss 0.55

    PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

  • CVE-2015-2065Feb 24, 2015
    risk 0.06cvss epss 0.41

    SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the vid parameter in a rss action to wp-admin/admin-ajax.php.

  • CVE-2015-1376Jan 28, 2015
    risk 0.06cvss epss 0.34

    pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.

  • CVE-2014-8586Nov 4, 2014
    risk 0.06cvss epss 0.40

    SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.

  • CVE-2007-5800Nov 3, 2007
    risk 0.06cvss epss 0.37

    Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute arbitrary PHP code via a URL in the bkpwp_plugin_path parameter to (1) plugins/BackUp/Archive.php; and (2) Predicate.php, (3)…

  • CVE-2007-2481May 3, 2007
    risk 0.06cvss epss 0.40

    PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

  • CVE-2014-9734Jun 30, 2015
    risk 0.05cvss epss 0.21

    Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php.

  • CVE-2015-1579Feb 11, 2015
    risk 0.05cvss epss 0.22

    Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of…

  • CVE-2014-5368Aug 22, 2014
    risk 0.05cvss epss 0.19

    Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Source Control (wp-source-control) plugin 3.0.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter.

Page 692 of 739