Vendor CVEs
WordPress
All CVEs
36,868 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-11581 | Med | 0.00 | 5.9 | 0.00 | Jun 30, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store… | ||
| CVE-2026-8944 | Med | 0.00 | 4.3 | 0.00 | Jun 30, 2026 | The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the Google Analytics settings page (ga.php). This makes it possible… | ||
| CVE-2026-12560 | Med | 0.00 | 4.4 | 0.00 | Jun 30, 2026 | The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Link URL' Field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for… | ||
| CVE-2026-12349 | Med | 0.00 | 5.3 | 0.00 | Jun 30, 2026 | The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX… | ||
| CVE-2026-12073 | Cri | 0.00 | 9.8 | 0.01 | Jun 30, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't… | ||
| CVE-2026-11367 | Med | 0.00 | 6.5 | 0.01 | Jun 30, 2026 | The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the move_image_on_server function. This makes it possible for authenticated attackers, with author-level access and above, to write… | ||
| CVE-2026-12114 | Med | 0.00 | 4.4 | 0.00 | Jun 30, 2026 | The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for… | ||
| CVE-2026-57341 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions. | ||
| CVE-2026-57340 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions. | ||
| CVE-2026-57339 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions. | ||
| CVE-2026-57338 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | ||
| CVE-2026-57337 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions. | ||
| CVE-2026-57336 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions. | ||
| CVE-2026-57335 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions. | ||
| CVE-2026-57334 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | ||
| CVE-2026-57333 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions. | ||
| CVE-2026-57332 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. | ||
| CVE-2026-57331 | Cri | 0.00 | 9.9 | 0.01 | Jun 29, 2026 | Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions. | ||
| CVE-2026-57330 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions. | ||
| CVE-2026-57329 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions. | ||
| CVE-2026-57328 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. | ||
| CVE-2026-57327 | Med | 0.00 | 6.3 | 0.00 | Jun 29, 2026 | Subscriber Broken Access Control in MainWP <= 6.1.1 versions. | ||
| CVE-2026-57326 | Med | 0.00 | 6.1 | 0.00 | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. | ||
| CVE-2026-57320 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions. | ||
| CVE-2026-57346 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3. | ||
| CVE-2026-57676 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9. | ||
| CVE-2026-9676 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with Subscriber-level access and above to modify the parent and menu order of arbitrary posts. | ||
| CVE-2026-10083 | Hig | 0.00 | 7.5 | 0.00 | Jun 29, 2026 | The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site Scripting vulnerability. When a persistent object cache is enabled, cache keys derived from unsanitised user input… | ||
| CVE-2026-8095 | Hig | 0.00 | 8.1 | 0.01 | Jun 28, 2026 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where… | ||
| CVE-2026-9242 | Med | 0.00 | 5.3 | 0.00 | Jun 27, 2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Verification of Data Authenticity in all versions up to and including 6.0.8.6. This is due to the PayPal… | ||
| CVE-2026-9233 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | ||
| CVE-2026-3462 | Med | 0.00 | 6.5 | 0.00 | Jun 27, 2026 | The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and including, 1.8.9. This makes it possible for authenticated attackers, with… | ||
| CVE-2026-13295 | Med | 0.00 | 6.4 | 0.00 | Jun 27, 2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | ||
| CVE-2026-12471 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | ||
| CVE-2026-12432 | Med | 0.00 | 5.3 | 0.01 | Jun 27, 2026 | The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying… | ||
| CVE-2026-12399 | Med | 0.00 | 4.4 | 0.00 | Jun 27, 2026 | The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for… | ||
| CVE-2026-11987 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user… | ||
| CVE-2026-11783 | Med | 0.00 | 6.4 | 0.00 | Jun 27, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and… | ||
| CVE-2026-11773 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | ||
| CVE-2026-11597 | Med | 0.00 | 6.4 | 0.00 | Jun 27, 2026 | The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied 'account' and… | ||
| CVE-2026-9677 | Med | 0.00 | 4.8 | 0.00 | Jun 27, 2026 | The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via the generateshariff() function, which could allow high privilege users such as admin to perform Stored… | ||
| CVE-2026-13245 | Med | 0.00 | 6.1 | 0.00 | Jun 27, 2026 | The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, and including, 9.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | ||
| CVE-2026-12404 | Med | 0.00 | 5.3 | 0.00 | Jun 27, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible… | ||
| CVE-2026-10820 | Hig | 0.00 | 8.1 | 0.00 | Jun 27, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user… | ||
| CVE-2026-12415 | Cri | 0.00 | 9.8 | 0.01 | Jun 27, 2026 | The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account,… | ||
| CVE-2026-13422 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and… | ||
| CVE-2026-13335 | Med | 0.00 | 6.4 | 0.00 | Jun 27, 2026 | The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | ||
| CVE-2026-13333 | Med | 0.00 | 6.5 | 0.01 | Jun 27, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient… | ||
| CVE-2026-13331 | Med | 0.00 | 6.5 | 0.00 | Jun 27, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient… | ||
| CVE-2026-11356 | Med | 0.00 | 4.4 | 0.00 | Jun 27, 2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insufficient input sanitization and output escaping. This makes… |
- risk 0.00cvss 5.9epss 0.00
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store…
- risk 0.00cvss 4.3epss 0.00
The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the Google Analytics settings page (ga.php). This makes it possible…
- risk 0.00cvss 4.4epss 0.00
The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Link URL' Field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for…
- risk 0.00cvss 5.3epss 0.00
The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX…
- risk 0.00cvss 9.8epss 0.01
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't…
- risk 0.00cvss 6.5epss 0.01
The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the move_image_on_server function. This makes it possible for authenticated attackers, with author-level access and above, to write…
- risk 0.00cvss 4.4epss 0.00
The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for…
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.
- risk 0.00cvss 7.1epss 0.00
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
- risk 0.00cvss 9.9epss 0.01
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
- risk 0.00cvss 6.3epss 0.00
Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
- risk 0.00cvss 6.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.
- risk 0.00cvss 7.1epss 0.00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.
- risk 0.00cvss 4.3epss 0.00
Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9.
- risk 0.00cvss 4.3epss 0.00
The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with Subscriber-level access and above to modify the parent and menu order of arbitrary posts.
- risk 0.00cvss 7.5epss 0.00
The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site Scripting vulnerability. When a persistent object cache is enabled, cache keys derived from unsanitised user input…
- risk 0.00cvss 8.1epss 0.01
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where…
- risk 0.00cvss 5.3epss 0.00
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Verification of Data Authenticity in all versions up to and including 6.0.8.6. This is due to the PayPal…
- risk 0.00cvss 4.3epss 0.00
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
- risk 0.00cvss 6.5epss 0.00
The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and including, 1.8.9. This makes it possible for authenticated attackers, with…
- risk 0.00cvss 6.4epss 0.00
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
- risk 0.00cvss 4.3epss 0.00
The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
- risk 0.00cvss 5.3epss 0.01
The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying…
- risk 0.00cvss 4.4epss 0.00
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for…
- risk 0.00cvss 4.3epss 0.00
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user…
- risk 0.00cvss 6.4epss 0.00
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and…
- risk 0.00cvss 4.3epss 0.00
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
- risk 0.00cvss 6.4epss 0.00
The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied 'account' and…
- risk 0.00cvss 4.8epss 0.00
The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via the generateshariff() function, which could allow high privilege users such as admin to perform Stored…
- risk 0.00cvss 6.1epss 0.00
The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, and including, 9.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
- risk 0.00cvss 5.3epss 0.00
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible…
- risk 0.00cvss 8.1epss 0.00
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user…
- risk 0.00cvss 9.8epss 0.01
The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account,…
- risk 0.00cvss 4.3epss 0.00
The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and…
- risk 0.00cvss 6.4epss 0.00
The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
- risk 0.00cvss 6.5epss 0.01
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient…
- risk 0.00cvss 6.5epss 0.00
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient…
- risk 0.00cvss 4.4epss 0.00
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insufficient input sanitization and output escaping. This makes…
Page 719 of 738