Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-1502

The IP2Location Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'download_ip2l…

Mitigation only
Fix from $1,600 2025-03-01
Unclassified MEDIUM 6.5
CVE-2024-13746

The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capabi…

Mitigation only
Fix from $1,600 2025-03-01
Whmcs Client Area HIGH 8.8
CVE-2024-9195

The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to…

Fix: 4.3+
Fix from $1,950 2025-02-28
Unclassified HIGH 8.8
CVE-2025-1682

The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on th…

Mitigation only
Fix from $1,950 2025-02-28
Unclassified MEDIUM 5.4
CVE-2025-1681

The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing f…

Mitigation only
Fix from $1,600 2025-02-28
Unclassified HIGH 7.6
CVE-2025-22280

Missing Authorization vulnerability in revmakx DefendWP Firewall defend-wp-firewall allows Exploiting Incorrectly Configured Access Control Security …

Mitigation only
Fix from $1,950 2025-02-27
Unclassified MEDIUM 5.3
CVE-2025-1249

Missing Authorization vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Exploiting Incorrectly Configured Access Control Sec…

No fix yet
Fix from $1,600 2025-02-26
Unclassified MEDIUM 5.4
CVE-2025-26995

Missing Authorization vulnerability in Anton Vanyukov Market Exporter market-exporter allows Exploiting Incorrectly Configured Access Control Securit…

Mitigation only
Fix from $1,600 2025-02-25
Unclassified MEDIUM 5.4
CVE-2025-27000

Missing Authorization vulnerability in George Pattichis Simple Photo Feed simple-photo-feed allows Exploiting Incorrectly Configured Access Control S…

Mitigation only
Fix from $1,600 2025-02-25
Unclassified MEDIUM 5.3
CVE-2025-26975

Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Accessing Functionality Not Properly Constrained by AC…

Mitigation only
Fix from $1,600 2025-02-25
Unclassified MEDIUM 6.5
CVE-2025-26960

Missing Authorization vulnerability in enituretechnology Small Package Quotes – Unishippers Edition small-package-quotes-unishippers-edition allows E…

Mitigation only
Fix from $1,600 2025-02-25
Essential Blocks HIGH 8.8
CVE-2025-26871

Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Co…

Fix: 4.8.4+
Fix from $1,950 2025-02-25
Enfold MEDIUM 5.3
CVE-2024-13693

The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all version…

Fix: 7.0+
Fix from $1,600 2025-02-25
Modernanet MEDIUM 6.5
CVE-2025-1644

A vulnerability classified as problematic has been found in Benner ModernaNet up to 1.2.0. Affected is an unknown function of the file /DadosPessoais…

Fix: 1.2.1+
Fix from $1,600 2025-02-25
Modernanet HIGH 8.8
CVE-2025-1643

A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Fix: 1.1.1+
Fix from $1,950 2025-02-25
Unclassified MEDIUM 5.4
CVE-2025-27356

Missing Authorization vulnerability in Hardik Sticky Header On Scroll sticky-header-on-scroll allows Exploiting Incorrectly Configured Access Control…

Mitigation only
Fix from $1,600 2025-02-24
Unclassified HIGH 7.2
CVE-2025-27296

Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue revenueflex-easy-ads allows Expl…

Mitigation only
Fix from $1,950 2025-02-24
Unclassified MEDIUM 6.5
CVE-2025-26883

Missing Authorization vulnerability in bPlugins Animated Text Block animated-text-block allows Exploiting Incorrectly Configured Access Control Secur…

Mitigation only
Fix from $1,600 2025-02-24
Unclassified MEDIUM 6.5
CVE-2025-26750

Missing Authorization vulnerability in appsbd Vitepos vitepos-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

No fix yet
Fix from $1,600 2025-02-22
Unclassified MEDIUM 6.5
CVE-2025-26764

Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows Exploiting Inco…

Mitigation only
Fix from $1,600 2025-02-22
Country Blocker MEDIUM 5.3
CVE-2025-1361

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due t…

Fix: 2.38.9+
Fix from $1,600 2025-02-22
Event Tickets MEDIUM 5.3
CVE-2025-1402

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_tic…

Fix: 5.19.1.2+
Fix from $1,600 2025-02-21
Ltl Freight Quotes MEDIUM 5.3
CVE-2025-1483

The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec…

Fix: 2.3.13+
Fix from $1,600 2025-02-20
Gift Vouchers MEDIUM 5.3
CVE-2024-13520

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of d…

Fix: after 4.4.6
Fix from $1,600 2025-02-20
Unclassified MEDIUM 6.5
CVE-2024-37363

The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862)  Hitachi Vantar…

Mitigation only
Fix from $1,600 2025-02-20
Elementskit Elementor Addons MEDIUM 5.3
CVE-2025-0968

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 du…

Fix: 3.4.1+
Fix from $1,600 2025-02-19
Raptive Ads MEDIUM 5.3
CVE-2024-13364

The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_ads_files_reset() and cls_fil…

Fix: after 3.6.3
Fix from $1,600 2025-02-19
Portfoliohub MEDIUM 5.3
CVE-2024-13231

The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili…

Fix: after 1.1.7
Fix from $1,600 2025-02-19
Peprodev Ultimate Invoice MEDIUM 5.3
CVE-2024-13719

The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via …

Fix: after 2.0.8
Fix from $1,600 2025-02-19
Unclassified HIGH 7.5
CVE-2024-13468

The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplic…

Mitigation only
Fix from $1,950 2025-02-19