Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified CRITICAL 9.8
CVE-2024-11281

The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0. This is due to …

Mitigation only
Fix from $2,300 2024-12-25
Unclassified MEDIUM 5.3
CVE-2024-12413

The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capab…

No fix yet
Fix from $1,600 2024-12-25
Unclassified HIGH 8.8
CVE-2024-12881

The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary file uploads due to a missing…

Mitigation only
Fix from $1,950 2024-12-24
Unclassified HIGH 8.8
CVE-2024-12594

The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Temporary admin login access , Renam…

Mitigation only
Fix from $1,950 2024-12-24
Unclassified MEDIUM 5.4
CVE-2024-12617

The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions …

Mitigation only
Fix from $1,600 2024-12-24
Unclassified MEDIUM 6.5
CVE-2024-12266

The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec…

Mitigation only
Fix from $1,600 2024-12-24
Unclassified MEDIUM 6.5
CVE-2024-12558

The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit…

Mitigation only
Fix from $1,600 2024-12-21
Teamcity MEDIUM 5.3
CVE-2024-56349

In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs

Fix: 2024.12+
Fix from $1,600 2024-12-20
Wordpress Learning Management System HIGH 8.8
CVE-2024-56048

Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec…

Fix: 1.9.9.1+
Fix from $1,950 2024-12-18
Unclassified HIGH 7.1
CVE-2024-54381

Missing Authorization vulnerability in Dotstore Advance Menu Manager advance-menu-manager.This issue affects Advance Menu Manager: from n/a through <…

No fix yet
Fix from $1,950 2024-12-18
Unclassified MEDIUM 6.5
CVE-2024-55997

Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-location-date-time-free-version all…

Mitigation only
Fix from $1,600 2024-12-18
Unclassified HIGH 7.5
CVE-2024-56008

Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality Not Properly Constrained by …

Mitigation only
Fix from $1,950 2024-12-18
Unclassified MEDIUM 6.5
CVE-2024-52485

Missing Authorization vulnerability in Yudiz Solutions Ltd. WP Menu Image wp-menu-image allows Exploiting Incorrectly Configured Access Control Secur…

Mitigation only
Fix from $1,600 2024-12-18
Unclassified MEDIUM 6.5
CVE-2024-11926

The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '_…

Mitigation only
Fix from $1,600 2024-12-18
Unclassified HIGH 8.8
CVE-2024-12259

The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and inc…

Mitigation only
Fix from $1,950 2024-12-18
Unclassified MEDIUM 5.3
CVE-2024-55999

Missing Authorization vulnerability in Marco Giannini XML Multilanguage Sitemap Generator xml-multilanguage-sitemap-generator.This issue affects XML …

Mitigation only
Fix from $1,600 2024-12-16
Unclassified MEDIUM 6.5
CVE-2024-56001

Missing Authorization vulnerability in ksher thailand Ksher ksher-payment allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…

Mitigation only
Fix from $1,600 2024-12-16
Unclassified MEDIUM 5.4
CVE-2024-56004

Missing Authorization vulnerability in awfowler Easy Site Importer easy-site-importer allows Exploiting Incorrectly Configured Access Control Securit…

Mitigation only
Fix from $1,600 2024-12-16
Unclassified MEDIUM 5.3
CVE-2024-56009

Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality Not Properly Constrained by …

Mitigation only
Fix from $1,600 2024-12-16
Unclassified MEDIUM 5.4
CVE-2024-55992

Missing Authorization vulnerability in Open Tools WooCommerce Basic Ordernumbers woocommerce-basic-ordernumbers allows Exploiting Incorrectly Configu…

Mitigation only
Fix from $1,600 2024-12-16
Unclassified MEDIUM 5.3
CVE-2024-55993

Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,600 2024-12-16
Unclassified MEDIUM 6.1
CVE-2024-55996

Missing Authorization vulnerability in dreamfox Dreamfox Media Payment gateway per Product for Woocommerce woocommerce-product-payments allows Exploi…

Mitigation only
Fix from $1,600 2024-12-16
Unclassified MEDIUM 5.4
CVE-2024-55998

Missing Authorization vulnerability in Eric Sloan Popup Surveys & Polls for WordPress (Mare.io) popup-surveys allows Exploiting Incorrectly Configure…

Mitigation only
Fix from $1,600 2024-12-16
Unclassified MEDIUM 5.3
CVE-2024-54417

Missing Authorization vulnerability in pixelgrade PixProof pixproof allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect…

Mitigation only
Fix from $1,600 2024-12-16
Unclassified HIGH 8.8
CVE-2024-54378

Missing Authorization vulnerability in Quietly Quietly Insights quietly-insights allows Privilege Escalation.This issue affects Quietly Insights: fro…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 8.8
CVE-2024-54379

Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects Minterpress: from n/a throug…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified CRITICAL 9.1
CVE-2024-54369

Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.Th…

Mitigation only
Fix from $2,300 2024-12-16
Unclassified MEDIUM 6.5
CVE-2024-54354

Missing Authorization vulnerability in beat.k Termin-Kalender termin-kalender allows Stored XSS.This issue affects Termin-Kalender: from n/a through …

Mitigation only
Fix from $1,600 2024-12-16
Unclassified HIGH 8.2
CVE-2024-54359

Missing Authorization vulnerability in Saul Morales Pacheco Banner System banner-system allows Exploiting Incorrectly Configured Access Control Secur…

Mitigation only
Fix from $1,950 2024-12-16
Wp Job Portal MEDIUM 5.3
CVE-2024-11712

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data …

Fix: 2.2.3+
Fix from $1,600 2024-12-14