VYPR

Vendor CVEs

Wpmudev

All CVEs

68 total · sorted by risk
  • CVE-2023-1478CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

  • CVE-2023-23737CriOct 12, 2023
    risk 0.60cvss 9.3epss 0.01

    Unauth. SQL Injection (SQLi) vulnerability in MainWP MainWP Broken Links Checker Extension plugin <= 4.0 versions.

  • CVE-2023-4596CriAug 30, 2023
    risk 0.58cvss 9.8epss 0.13

    The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated…

  • CVE-2017-20206CriOct 18, 2025
    risk 0.57cvss 9.8epss 0.01

    The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the `wpmudev_appointments` cookie. This allows unauthenticated attackers to inject a PHP Object. Attackers were…

  • CVE-2017-18511HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.

  • CVE-2017-18510HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.

  • CVE-2019-11872HigMay 29, 2019
    risk 0.57cvss 8.8epss 0.02

    The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through…

  • CVE-2017-8558HigJun 29, 2017
    risk 0.57cvss 7.8epss 0.44

    The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703…

  • CVE-2015-9455HigOct 7, 2019
    risk 0.53cvss 8.1epss 0.01

    The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.

  • CVE-2025-6463HigJul 2, 2025
    risk 0.51cvss 8.8epss 0.12

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function in all versions up to, and including, 1.44.2. This makes…

  • CVE-2025-6464HigJul 2, 2025
    risk 0.49cvss 7.5epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via deserialization of untrusted input in the 'entry_delete_upload_files' function. This makes it…

  • CVE-2024-10402HigOct 26, 2024
    risk 0.49cvss 7.5epss 0.01

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers,…

  • CVE-2024-31077HigApr 23, 2024
    risk 0.49cvss 7.2epss 0.30

    Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the database and cause a denial-of-service (DoS) condition.

  • CVE-2024-0368HigMar 13, 2024
    risk 0.49cvss 8.6epss 0.01

    The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data…

  • CVE-2023-5949HigDec 18, 2023
    risk 0.49cvss 7.5epss 0.01

    The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts' content.

  • CVE-2017-15079HigOct 6, 2017
    risk 0.49cvss 7.5epss 0.03

    The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal.

  • CVE-2024-1794HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.01

    The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) in all versions up to, and including, 1.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2024-29777HigMar 27, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator.This issue affects Forminator: from n/a through <= 1.29.0.

  • CVE-2021-36821HigMar 16, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.14.11.

  • CVE-2025-0469MedFeb 27, 2025
    risk 0.42cvss 6.4epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider template data in all versions up to, and including, 1.39.2 due to insufficient input sanitization and output escaping. This…

  • CVE-2024-7389HigAug 2, 2024
    risk 0.42cvss 7.5epss 0.01

    The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API…

  • CVE-2019-9568MedMar 4, 2019
    risk 0.42cvss 6.5epss 0.02

    The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.

  • CVE-2025-0470MedJan 31, 2025
    risk 0.40cvss 6.1epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the title parameter in all versions up to, and including, 1.38.2 due to insufficient input sanitization and output escaping. This…

  • CVE-2024-45625MedSep 9, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web form created by Forminator.

  • CVE-2023-3134MedJul 31, 2023
    risk 0.40cvss 6.1epss 0.04

    The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead to reflected XSS attacks.

  • CVE-2022-2438HigSep 6, 2022
    risk 0.40cvss 7.2epss 0.01

    The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 1.11.16. This makes it possible for authenticated attackers with administrative privileges and above to call files using a…

  • CVE-2022-1009MedMay 30, 2022
    risk 0.40cvss 6.1epss 0.01

    The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back in an admin page when uploading a malicious preset configuration, leading to a Reflected Cross-Site Scripting. For the attack to be successful, an attacker…

  • CVE-2019-16521MedOct 16, 2019
    risk 0.40cvss 6.1epss 0.01

    The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links can be exploited by…

  • CVE-2019-9567MedMar 4, 2019
    risk 0.40cvss 6.1epss 0.01

    The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.

  • CVE-2024-37239MedJul 22, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Branda branda-white-labeling.This issue affects Branda: from n/a through <= 3.4.17.

  • CVE-2024-25592MedMar 15, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Broken Link Checker allows Stored XSS.This issue affects Broken Link Checker: from n/a through 2.2.3.

  • CVE-2023-6133MedNov 15, 2023
    risk 0.36cvss 6.6epss 0.01

    The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level…

  • CVE-2025-5341MedJun 5, 2025
    risk 0.35cvss 6.4epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id' and 'data-size’ parameters in all versions up to, and including, 1.44.1 due to insufficient input sanitization and output…

  • CVE-2025-3487MedApr 17, 2025
    risk 0.35cvss 6.4epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘limit’ parameter in all versions up to, and including, 1.42.0 due to insufficient input sanitization and output escaping. This…

  • CVE-2024-5191MedJun 21, 2024
    risk 0.35cvss 6.4epss 0.00

    The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_types’ parameter in all versions up to, and including, 3.4.17 due to insufficient input sanitization and output escaping. This…

  • CVE-2024-31857MedApr 23, 2024
    risk 0.35cvss 5.4epss 0.01

    Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page contents on the user's web browser.

  • CVE-2024-28890MedApr 23, 2024
    risk 0.35cvss 5.3epss 0.01

    Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the server, alter the site that uses the plugin, and cause a…

  • CVE-2024-3053MedApr 9, 2024
    risk 0.35cvss 6.4epss 0.00

    The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ forminator_form shortcode attribute in versions up to, and including, 1.29.2 due to insufficient input sanitization and output…

  • CVE-2023-5089MedOct 16, 2023
    risk 0.35cvss 5.3epss 0.02

    The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.

  • CVE-2018-18576MedMar 17, 2020
    risk 0.35cvss 5.3epss 0.01

    The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.

  • CVE-2019-17207MedOct 18, 2019
    risk 0.35cvss 5.4epss 0.02

    A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin 1.11.8 for WordPress. This allows unauthorized users to inject client-side JavaScript into an admin-only WordPress page via the…

  • CVE-2026-24998MedFeb 3, 2026
    risk 0.34cvss 5.3epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hustle wordpress-popup allows Retrieve Embedded Sensitive Data.This issue affects Hustle: from n/a through <= 7.8.9.2.

  • CVE-2024-37444MedNov 1, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Defender Security defender-security.This issue affects Defender Security: from n/a through <= 4.7.1.

  • CVE-2024-6554MedJul 11, 2024
    risk 0.34cvss 5.3epss 0.00

    The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.18. This is due the plugin utilizing composer without preventing direct access to the files. This makes it…

  • CVE-2023-47189MedJun 4, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.2.0.

  • CVE-2024-25595MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from n/a through 4.4.1.

  • CVE-2023-51490MedJan 8, 2024
    risk 0.34cvss 5.3epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.This issue affects Defender Security – Malware Scanner, Login Security & Firewall: from n/a through 4.1.0.

  • CVE-2022-44581MedMay 17, 2024
    risk 0.33cvss 5.0epss 0.01

    Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This issue affects Defender Security: from n/a through 3.3.2.

  • CVE-2015-5057MedAug 18, 2017
    risk 0.33cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability exists in the Wordpress admin panel when the Broken Link Checker plugin before 1.10.9 is installed.

  • CVE-2024-8492MedMay 15, 2025
    risk 0.31cvss 4.8epss 0.00

    The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

Page 1 of 2