VYPR
Vendor

Wpdeveloper

Products
17
CVEs
139
Across products
142
Status
Private

Products

17

Recent CVEs

139
View all 139 CVEs →
  • CVE-2023-32243CriMay 12, 2023
    risk 0.70cvss 9.8epss 0.76

    Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.

  • CVE-2023-6623CriJan 15, 2024
    risk 0.68cvss 9.8epss 0.51

    The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.

  • CVE-2022-0349CriMar 7, 2022
    risk 0.66cvss 9.8epss 0.34

    The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection

  • CVE-2022-0320CriFeb 1, 2022
    risk 0.64cvss 9.8epss 0.02

    The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server,…

  • CVE-2024-1698CriFeb 27, 2024
    risk 0.63cvss 9.8epss 0.78

    The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user…

  • CVE-2024-30226CriMar 28, 2024
    risk 0.59cvss 9.0epss 0.01

    Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3.

  • CVE-2023-2833HigJun 6, 2023
    risk 0.59cvss 8.8epss 0.17

    The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a…

  • CVE-2021-4447HigOct 16, 2024
    risk 0.57cvss 8.8epss 0.00

    The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it…

  • CVE-2023-41955HigMay 17, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a through 5.8.8.

  • CVE-2023-26325HigFeb 23, 2023
    risk 0.57cvss 8.8epss 0.01

    The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.

  • CVE-2021-24356HigJun 14, 2021
    risk 0.57cvss 8.8epss 0.03

    In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on…

  • CVE-2021-24354HigJun 14, 2021
    risk 0.57cvss 8.8epss 0.01

    A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.

  • CVE-2021-24353HigJun 14, 2021
    risk 0.57cvss 8.8epss 0.01

    The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.

  • CVE-2021-24352HigJun 14, 2021
    risk 0.57cvss 8.8epss 0.01

    The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects.

  • CVE-2017-18504HigAug 12, 2019
    risk 0.57cvss 8.8epss 0.01

    The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.

  • CVE-2024-43328HigAug 19, 2024
    risk 0.54cvss 8.3epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through 4.0.9.

  • CVE-2023-4386HigOct 20, 2023
    risk 0.53cvss 8.1epss 0.01

    The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the…

  • CVE-2023-4402HigOct 20, 2023
    risk 0.53cvss 8.1epss 0.01

    The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in…

  • CVE-2024-8979HigNov 15, 2024
    risk 0.52cvss 8.0epss 0.00

    The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls'…

  • CVE-2024-3018HigMar 30, 2024
    risk 0.50cvss 8.8epss 0.01

    The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Register Form" widget (disabled by default).…