Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Wpbot MEDIUM 5.0
CVE-2024-0451

The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback f…

Fix: 5.3.6+
Fix from $1,600 2024-05-22
Wpbot HIGH 7.7
CVE-2024-0452

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_ca…

Fix: 5.3.6+
Fix from $1,950 2024-05-22
Wpbot HIGH 7.7
CVE-2024-0453

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_ca…

Fix: 5.3.6+
Fix from $1,950 2024-05-22
Youtube Video Gallery MEDIUM 5.3
CVE-2024-3268

The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of…

Fix: 3.4.0+
Fix from $1,600 2024-05-21
Shoplentor HIGH 7.1
CVE-2024-4566

The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function…

Fix: 2.8.9+
Fix from $1,950 2024-05-21
Lunary HIGH 7.5
CVE-2024-3761

In lunary-ai/lunary version 1.2.2, the DELETE endpoint located at `packages/backend/src/api/v1/datasets` is vulnerable to unauthorized dataset deleti…

Fix: 1.2.8+
Fix from $1,950 2024-05-20
Contact Form HIGH 7.5
CVE-2024-2782

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modifica…

Fix: 5.1.17+
Fix from $1,950 2024-05-18
Contact Form CRITICAL 9.8
CVE-2024-2771

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation …

Fix: 5.1.17+
Fix from $2,300 2024-05-18
Unclassified MEDIUM 5.3
CVE-2024-35174

Missing Authorization vulnerability in Flothemes Flo Forms.This issue affects Flo Forms: from n/a through 1.0.42.

Mitigation only
Fix from $1,600 2024-05-17
Unclassified MEDIUM 5.3
CVE-2024-32802

Missing Authorization vulnerability in WordPlus BP Better Messages allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects…

Mitigation only
Fix from $1,600 2024-05-17
Unclassified HIGH 8.2
CVE-2024-32692

Missing Authorization vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress allows Accessing Functionality Not Properly Constrain…

Mitigation only
Fix from $1,950 2024-05-17
Church Admin MEDIUM 6.3
CVE-2024-31281

Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.6.

Fix: 4.1.7+
Fix from $1,600 2024-05-17
Build App Online HIGH 8.8
CVE-2023-51479

Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/…

Fix: 1.0.20+
Fix from $1,950 2024-05-17
Migration\, Backup\, Staging HIGH 8.8
CVE-2023-41243

Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backu…

Fix: 0.9.91+
Fix from $1,950 2024-05-17
Eventprime MEDIUM 5.3
CVE-2023-33321

Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect…

Fix: 3.0.0+
Fix from $1,600 2024-05-17
Unclassified MEDIUM 5.3
CVE-2023-34186

Missing Authorization vulnerability in Imran Sayed Headless CMS.This issue affects Headless CMS: from n/a through 2.0.3.

Mitigation only
Fix from $1,600 2024-05-17
Unclassified HIGH 7.5
CVE-2023-23988

Missing Authorization vulnerability in Joseph C Dolson My Tickets.This issue affects My Tickets: from n/a through 1.9.11.

Mitigation only
Fix from $1,950 2024-05-17
Unclassified MEDIUM 5.3
CVE-2022-45070

Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditional Checkout Fields for WooCo…

No fix yet
Fix from $1,600 2024-05-17
Elementor Header \& Footer Builder MEDIUM 5.4
CVE-2024-2619

The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient …

Fix: 1.6.27+
Fix from $1,600 2024-05-16
Tutor Lms HIGH 8.8
CVE-2024-4352

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability c…

Fix: 2.7.1+
Fix from $1,950 2024-05-16
Tutor Lms HIGH 8.8
CVE-2024-4351

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability c…

Fix: 2.7.1+
Fix from $1,950 2024-05-16
Tutor Lms HIGH 8.2
CVE-2024-4222

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability c…

Fix: 2.7.1+
Fix from $1,950 2024-05-16
Tutor Lms CRITICAL 9.8
CVE-2024-4223

The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check…

Fix: 2.7.1+
Fix from $2,300 2024-05-16
Unclassified HIGH 8.8
CVE-2024-3750

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to …

Mitigation only
Fix from $1,950 2024-05-16
Unclassified HIGH 8.8
CVE-2024-4010

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data du…

Mitigation only
Fix from $1,950 2024-05-15
Unclassified MEDIUM 5.5
CVE-2024-32731

SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successfu…

Mitigation only
Fix from $1,600 2024-05-14
Ruggedcom Crossbow CRITICAL 9.8
CVE-2024-27939

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unau…

Fix: 5.5+
Fix from $2,300 2024-05-14
Learnpress MEDIUM 6.5
CVE-2024-4444

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. Th…

Fix: 4.2.6.6+
Fix from $1,600 2024-05-14
Unclassified MEDIUM 5.3
CVE-2024-4280

The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin fun…

Mitigation only
Fix from $1,600 2024-05-14
Unclassified MEDIUM 5.3
CVE-2024-3915

The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sf_edit_director…

Mitigation only
Fix from $1,600 2024-05-14