Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2024-33919

Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor.This issue affects RomethemeKit For Elementor: from n/a through 1.4.1.

Mitigation only
Fix from $1,600 2024-05-03
Unclassified MEDIUM 5.3
CVE-2024-33920

Missing Authorization vulnerability in Kama Democracy Poll.This issue affects Democracy Poll: from n/a through 6.0.3.

No fix yet
Fix from $1,600 2024-05-03
Unclassified MEDIUM 5.3
CVE-2024-33941

Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour B…

Mitigation only
Fix from $1,600 2024-05-03
Unclassified HIGH 7.6
CVE-2024-32810

Missing Authorization vulnerability in ShortPixel ShortPixel Critical CSS.This issue affects ShortPixel Critical CSS: from n/a through 1.0.2.

Mitigation only
Fix from $1,950 2024-05-03
Unclassified MEDIUM 5.3
CVE-2023-25457

Missing Authorization vulnerability in Richteam Slider Carousel – Responsive Image Slider.This issue affects Slider Carousel – Responsive Image Slide…

Mitigation only
Fix from $1,600 2024-05-03
Prosafe Network Management System HIGH 8.8
CVE-2023-38102

NETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attac…

Fix: 1.7.0.20+
Fix from $1,950 2024-05-03
Wp Datepicker HIGH 8.8
CVE-2024-3895

The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdp_add_new_datep…

Fix: 2.1.1+
Fix from $1,950 2024-05-02
Unclassified MEDIUM 5.3
CVE-2024-3897

The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th…

Mitigation only
Fix from $1,600 2024-05-02
Masterstudy Lms MEDIUM 5.4
CVE-2024-3942

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and …

Fix: 3.3.9+
Fix from $1,600 2024-05-02
Unclassified MEDIUM 5.3
CVE-2024-3585

The Send PDF for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of form submissions due to a missing capability check on th…

Mitigation only
Fix from $1,600 2024-05-02
Wp Cookie Consent MEDIUM 5.3
CVE-2024-3599

The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check…

Fix: 3.1.0+
Fix from $1,600 2024-05-02
Poll Maker MEDIUM 5.3
CVE-2024-3601

The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th…

Fix: 5.1.9+
Fix from $1,600 2024-05-02
Tutor Lms MEDIUM 6.5
CVE-2024-3553

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil…

Fix: 2.7.0+
Fix from $1,600 2024-05-02
Unclassified MEDIUM 5.3
CVE-2024-3287

The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to unauthorized ld+json description injection du…

Mitigation only
Fix from $1,600 2024-05-02
Unclassified MEDIUM 6.5
CVE-2024-3295

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized lo…

Mitigation only
Fix from $1,600 2024-05-02
Unclassified MEDIUM 5.3
CVE-2024-3312

The Easy Custom Auto Excerpt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.12. This …

Mitigation only
Fix from $1,600 2024-05-02
Unclassified MEDIUM 5.3
CVE-2024-2797

The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due to a missing capability check …

Mitigation only
Fix from $1,600 2024-05-02
Unclassified HIGH 8.8
CVE-2024-2417

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escal…

Patch available
Fix from $1,950 2024-05-02
Eleforms MEDIUM 5.3
CVE-2024-2043

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a miss…

Fix: 2.9.9.8+
Fix from $1,600 2024-05-02
Unclassified MEDIUM 5.3
CVE-2024-2109

The Booster Extension plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.0 via the 'boost…

Mitigation only
Fix from $1,600 2024-05-02
Unclassified HIGH 7.1
CVE-2024-1945

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to unauthorized loss of data du…

Mitigation only
Fix from $1,950 2024-05-02
Analytify Google Analytics Dashboard MEDIUM 5.4
CVE-2024-1809

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data …

Fix: 5.2.4+
Fix from $1,600 2024-05-02
Print Labels With Barcodes HIGH 8.8
CVE-2024-1677

The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized ac…

Fix: 3.4.7+
Fix from $1,950 2024-05-02
Unclassified MEDIUM 5.3
CVE-2024-1688

The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_orders_archive() f…

Mitigation only
Fix from $1,600 2024-05-02
Analytify Google Analytics Dashboard MEDIUM 5.3
CVE-2024-1584

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of…

Fix: 5.2.4+
Fix from $1,600 2024-05-02
Unclassified MEDIUM 5.3
CVE-2024-0908

The Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page plugin for WordPress is vulnerable to unauthorized access of data due to…

Mitigation only
Fix from $1,600 2024-05-02
Unclassified MEDIUM 5.3
CVE-2024-0629

The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che…

Mitigation only
Fix from $1,600 2024-05-02
Git Server MEDIUM 6.5
CVE-2024-34146

Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing a…

Fix: after 114.v068a_c7cc2574
Fix from $1,600 2024-05-02
Unclassified MEDIUM 6.5
CVE-2024-33944

Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce AWeber Newsletter Subscripti…

Mitigation only
Fix from $1,600 2024-05-02
Unclassified MEDIUM 6.5
CVE-2024-1371

The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_a…

Mitigation only
Fix from $1,600 2024-04-30