VYPR

Vendor CVEs

Wpmet

All CVEs

67 total · sorted by risk
  • CVE-2024-32683MedApr 19, 2024
    risk 0.34cvss 5.3epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

  • CVE-2023-0710MedJun 9, 2023
    risk 0.32cvss 4.9epss 0.00

    The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'fname' attribute of the 'mf_thankyou' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with…

  • CVE-2023-6525MedMar 16, 2024
    risk 0.29cvss 5.5epss 0.00

    The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-7063MedAug 15, 2024
    risk 0.28cvss 4.3epss 0.00

    The ElementsKit Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.6 via the 'render_raw' function. This can allow authenticated attackers, with Contributor-level permissions and above, to extract sensitive data…

  • CVE-2023-39993MedJun 19, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Wpmet Elements kit Elementor addons.This issue affects Elements kit Elementor addons: from n/a through 2.9.0.

  • CVE-2024-33570MedMay 6, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3.

  • CVE-2023-6788MedJan 9, 2024
    risk 0.28cvss 5.4epss 0.00

    The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.1. This is due to missing or incorrect nonce validation on the contents function. This makes it possible for unauthenticated…

  • CVE-2023-28987MedNov 12, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

  • CVE-2023-46085MedOct 22, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.

  • CVE-2023-0689MedAug 31, 2023
    risk 0.28cvss 4.3epss 0.00

    The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive…

  • CVE-2023-2517MedJul 12, 2023
    risk 0.28cvss 5.4epss 0.00

    The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on the permalink_setup function. This makes it possible for unauthenticated…

  • CVE-2023-0692MedJun 9, 2023
    risk 0.28cvss 4.3epss 0.01

    The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_status' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive…

  • CVE-2023-0691MedJun 9, 2023
    risk 0.28cvss 4.3epss 0.01

    The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive…

  • CVE-2025-0968MedFeb 19, 2025
    risk 0.27cvss 5.3epss 0.00

    The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to…

  • CVE-2024-4266MedJun 11, 2024
    risk 0.27cvss 5.3epss 0.01

    The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract…

  • CVE-2023-6582MedJan 11, 2024
    risk 0.27cvss 5.3epss 0.01

    The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft,…

  • CVE-2025-1506MedFeb 28, 2025
    risk 0.21cvss 4.3epss 0.00

    The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function. This makes it possible…

Page 2 of 2