Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Wp Child Theme Generator MEDIUM 5.3
CVE-2024-3610

The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wctg_ea…

Fix: 1.1.2+
Fix from $1,600 2024-06-21
Wheel Of Life MEDIUM 5.4
CVE-2024-3627

The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modification and loss of data due t…

Fix: after 1.1.7
Fix from $1,600 2024-06-20
Materialis MEDIUM 6.5
CVE-2023-3204

The Materialis theme for WordPress is vulnerable to limited arbitrary options updates in versions up to, and including, 1.1.24. This is due to missin…

Fix: 1.1.30+
Fix from $1,600 2024-06-20
Slider Revolution HIGH 8.8
CVE-2024-34444

Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.

Fix: 6.7.0+
Fix from $1,950 2024-06-19
Avada HIGH 8.8
CVE-2023-39312

Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

Fix: 7.11.2+
Fix from $1,950 2024-06-19
Learnpress HIGH 8.8
CVE-2023-36516

Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.

Fix: 4.2.3.1+
Fix from $1,950 2024-06-19
Ninja Forms HIGH 8.8
CVE-2023-38393

Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

Fix: after 3.6.26
Fix from $1,950 2024-06-19
Jupiter X Core HIGH 8.8
CVE-2023-38394

Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.

Fix: 3.3.5+
Fix from $1,950 2024-06-19
Attorney CRITICAL 9.8
CVE-2022-45832

Missing Authorization vulnerability in Hennessey Digital Attorney.This issue affects Attorney: from n/a through 3.

Fix: after 3
Fix from $2,300 2024-06-19
Learnpress CRITICAL 9.8
CVE-2023-36515

Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.

Fix: 4.2.3.1+
Fix from $2,300 2024-06-19
Unclassified MEDIUM 5.4
CVE-2023-39310

Missing Authorization vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.

Mitigation only
Fix from $1,600 2024-06-19
Unclassified MEDIUM 6.5
CVE-2023-36683

Missing Authorization vulnerability in WP SCHEMA PRO Schema Pro.This issue affects Schema Pro: from n/a through 2.7.8.

No fix yet
Fix from $1,600 2024-06-19
Convert Pro CRITICAL 9.8
CVE-2023-36684

Missing Authorization vulnerability in Brainstorm Force Convert Pro.This issue affects Convert Pro: from n/a through 1.7.5.

Fix: 1.7.6+
Fix from $2,300 2024-06-19
Premium Addons HIGH 8.8
CVE-2023-37869

Missing Authorization vulnerability in Premium Addons Premium Addons PRO.This issue affects Premium Addons PRO: from n/a through 2.9.0.

Fix: 2.9.1+
Fix from $1,950 2024-06-19
Unclassified MEDIUM 6.5
CVE-2023-37872

Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a…

Mitigation only
Fix from $1,600 2024-06-19
Spectra HIGH 8.8
CVE-2023-36676

Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.

Fix: 2.6.7+
Fix from $1,950 2024-06-19
Starter Templates MEDIUM 6.5
CVE-2023-41805

Missing Authorization vulnerability in Brainstorm Force Premium Starter Templates, Brainstorm Force Starter Templates astra-sites.This issue affects …

Fix: 3.2.6+
Fix from $1,600 2024-06-19
Paid Memberships Pro HIGH 8.8
CVE-2023-39990

Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.

Fix: 1.2.4+
Fix from $1,950 2024-06-19
Betheme HIGH 7.2
CVE-2023-39998

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1.

Fix: 27.1.2+
Fix from $1,950 2024-06-19
Unclassified HIGH 8.1
CVE-2023-37870

Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.1.9.

Mitigation only
Fix from $1,950 2024-06-19
Ninja Forms CRITICAL 9.8
CVE-2023-38386

Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

Fix: 3.6.26+
Fix from $2,300 2024-06-19
Avada HIGH 8.8
CVE-2023-39922

Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

Fix: 7.11.2+
Fix from $1,950 2024-06-19
Stripe Payment Gateway CRITICAL 9.8
CVE-2023-35049

Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a…

Fix: 7.4.1+
Fix from $2,300 2024-06-19
Unclassified MEDIUM 5.4
CVE-2023-35050

Missing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0.

Mitigation only
Fix from $1,600 2024-06-19
Unclassified MEDIUM 6.5
CVE-2023-36512

Missing Authorization vulnerability in Woo AutomateWoo.This issue affects AutomateWoo: from n/a through 5.7.5.

No fix yet
Fix from $1,600 2024-06-19
Ultra HIGH 8.8
CVE-2023-46148

Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Fix: 7.3.5+
Fix from $1,950 2024-06-19
Unclassified MEDIUM 6.5
CVE-2023-47681EPSS 9%

Missing Authorization vulnerability in QuadLayers WooCommerce Checkout Manager.This issue affects WooCommerce Checkout Manager: from n/a through 7.3.…

Mitigation only
Fix from $1,600 2024-06-19
Betheme HIGH 7.6
CVE-2023-47770

Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1.

Fix: 27.1.2+
Fix from $1,950 2024-06-19
Astra HIGH 8.8
CVE-2023-44148

Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.

Fix: 1.2.8+
Fix from $1,950 2024-06-19
Pre Publish Checklist HIGH 8.8
CVE-2023-44151

Missing Authorization vulnerability in Brainstorm Force Pre-Publish Checklist.This issue affects Pre-Publish Checklist: from n/a through 1.1.1.

Fix: 1.1.2+
Fix from $1,950 2024-06-19