VYPR

Vendor CVEs

WordPress

All CVEs

36,868 total · sorted by risk
  • CVE-2026-39442HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.

  • CVE-2025-69189HigJun 17, 2026
    risk 0.00cvss 7.3epss 0.00

    Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3.

  • CVE-2025-69175HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.

  • CVE-2025-69174HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Etude <= 1.6 versions.

  • CVE-2025-69170HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.

  • CVE-2025-69166HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.

  • CVE-2025-69164HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.

  • CVE-2025-69158HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Granola <= 1.13 versions.

  • CVE-2025-69157HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.

  • CVE-2025-69144HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.

  • CVE-2025-69140HigJun 17, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.

  • CVE-2025-69130HigJun 17, 2026
    risk 0.00cvss 8.8epss 0.00

    Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.

  • CVE-2025-69128HigJun 17, 2026
    risk 0.00cvss 8.6epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a through 7.3.

  • CVE-2025-69127CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.

  • CVE-2025-69126HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions.

  • CVE-2025-69123HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions.

  • CVE-2025-69120HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.

  • CVE-2025-69115HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions.

  • CVE-2025-69111CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.

  • CVE-2025-69106HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.

  • CVE-2025-68524HigJun 17, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.

  • CVE-2025-60236CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.

  • CVE-2025-60231CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.

  • CVE-2025-60230CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.

  • CVE-2025-60229CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.

  • CVE-2025-59554CriJun 17, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.

  • CVE-2025-15657MedJun 17, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.

  • CVE-2025-15546Jun 14, 2026
    risk 0.00cvss epss 0.00

    The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file…

  • CVE-2025-7504HigJul 12, 2025
    risk 0.00cvss 7.5epss 0.01

    The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known…

  • CVE-2024-10222MedFeb 21, 2025
    risk 0.00cvss 6.4epss 0.00

    The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…

  • CVE-2024-23825LowJan 30, 2024
    risk 0.00cvss 3.0epss 0.01

    TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. That user input is filtered insufficiently, which makes it is possible to send requests to unintended network locations and…

  • CVE-2022-0402MedJan 16, 2024
    risk 0.00cvss 6.1epss 0.00

    The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an attribute via the super_language_switcher AJAX action, leading to a Reflected Cross-Site Scripting.…

  • CVE-2023-51700MedDec 27, 2023
    risk 0.00cvss 6.4epss 0.01

    Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability,…

  • CVE-2023-48300MedNov 20, 2023
    risk 0.00cvss 6.3epss 0.01

    The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored Cross-Site Scripting via `embed_privacy_opt_out` shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping…

  • CVE-2023-1979MedMay 8, 2023
    risk 0.00cvss 4.9epss 0.00

    The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only accessible to website visitors after entering the password. In WordPress, users with the "Author" role can create stories, but don't…

  • CVE-2017-20183LowMay 5, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in External Media without Import Plugin up to 1.0.0 on WordPress. It has been declared as problematic. This vulnerability affects the function print_media_new_panel of the file external-media-without-import.php. The manipulation of the argument…

  • CVE-2023-30616MedApr 20, 2023
    risk 0.00cvss 6.5epss 0.00

    Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a missing nonce check. There is potential for a Cross Site Request Forgery for all form blocks, since it allows to send requests to…

  • CVE-2017-20177LowFeb 6, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in WangGuard Plugin 1.8.0 on WordPress. Affected by this issue is the function wangguard_users_info of the file wangguard-user-info.php of the component WGG User List Handler. The manipulation of the argument…

  • CVE-2022-4631LowDec 21, 2022
    risk 0.00cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is…

  • CVE-2021-4252LowDec 18, 2022
    risk 0.00cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the argument $_SERVER["HTTP_USER_AGENT"] leads to cross site scripting. The attack may be initiated…

  • CVE-2022-4604MedDec 18, 2022
    risk 0.00cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in wp-english-wp-admin Plugin up to 1.5.1. Affected by this vulnerability is the function register_endpoints of the file english-wp-admin.php. The manipulation leads to cross-site request forgery. The attack can be launched…

  • CVE-2022-4207MedDec 13, 2022
    risk 0.00cvss 5.5epss 0.01

    The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2022-3966MedNov 13, 2022
    risk 0.00cvss 4.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_template of the file includes/core/class-shortcodes.php of the component Template Handler. The manipulation of the argument tpl leads to…

  • CVE-2022-3506MedOct 14, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.

  • CVE-2022-2433HigSep 6, 2022
    risk 0.00cvss 7.5epss 0.01

    The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR…

  • CVE-2022-29450MedJun 15, 2022
    risk 0.00cvss 5.4epss 0.00

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.

  • CVE-2021-24892HigNov 23, 2021
    risk 0.00cvss 8.8epss 0.02

    Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To…

  • CVE-2021-24884CriOct 25, 2021
    risk 0.00cvss 9.6epss 0.03

    The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick…

  • CVE-2021-24366MedJun 21, 2021
    risk 0.00cvss 5.4epss 0.01

    The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html…

  • CVE-2020-29171MedFeb 10, 2021
    risk 0.00cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.

Page 724 of 738