Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified CRITICAL 9.8
CVE-2024-25912

Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

No fix yet
Fix from $2,300 2024-04-11
Unclassified MEDIUM 5.4
CVE-2024-25922

Missing Authorization vulnerability in Peach Payments Peach Payments Gateway.This issue affects Peach Payments Gateway: from n/a through 3.1.9.

Mitigation only
Fix from $1,600 2024-04-11
Unclassified MEDIUM 5.3
CVE-2024-24850

Missing Authorization vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from…

No fix yet
Fix from $1,600 2024-04-11
Unclassified HIGH 7.5
CVE-2023-51672

Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

Mitigation only
Fix from $1,950 2024-04-11
Unclassified MEDIUM 5.4
CVE-2023-27607

Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a t…

No fix yet
Fix from $1,600 2024-04-11
Unclassified MEDIUM 6.5
CVE-2022-44633

Missing Authorization vulnerability in YITH YITH WooCommerce Gift Cards Premium.This issue affects YITH WooCommerce Gift Cards Premium: from n/a thro…

Mitigation only
Fix from $1,600 2024-04-11
Xwiki HIGH 8.8
CVE-2024-31997EPSS 74%

XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as V…

Fix: 14.10.19 / 15.5.4+
Fix from $1,950 2024-04-10
Xwiki HIGH 8.8
CVE-2024-31987

XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who ca…

Fix: 14.10.19 / 15.5.4+
Fix from $1,950 2024-04-10
Xwiki HIGH 8.8
CVE-2024-31981

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, remote code execution is …

Fix: 14.10.19 / 15.5.4+
Fix from $1,950 2024-04-10
Xwiki HIGH 8.8
CVE-2024-31983

XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit right, circumventing the rights…

Fix: 14.10.20 / 15.5.4+
Fix from $1,950 2024-04-10
Unclassified MEDIUM 5.3
CVE-2024-31230

Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images…

Mitigation only
Fix from $1,600 2024-04-10
Unclassified MEDIUM 5.3
CVE-2024-31242

Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.

No fix yet
Fix from $1,600 2024-04-10
Unclassified MEDIUM 6.5
CVE-2024-31342

Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Exporter: from n/a through 1.3.

Mitigation only
Fix from $1,600 2024-04-10
Mp3 Audio Player For Music\, Radio \& Podcast HIGH 7.5
CVE-2024-31343

Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Mus…

Fix: 5.0+
Fix from $1,950 2024-04-10
Wholesale For Woocommerce MEDIUM 5.3
CVE-2024-31297

Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.

Fix: after 2.3.0
Fix from $1,600 2024-04-10
Unclassified HIGH 7.5
CVE-2024-31358

Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel:…

Mitigation only
Fix from $1,950 2024-04-10
Unclassified MEDIUM 5.3
CVE-2024-3235

The Essential Grid Gallery WordPress Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including…

Mitigation only
Fix from $1,600 2024-04-10
Wp Radio MEDIUM 5.4
CVE-2024-1042

The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to…

Fix: after 3.1.9
Fix from $1,600 2024-04-10
Wp Radio MEDIUM 5.4
CVE-2024-1041

The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug…

Fix: after 3.1.9
Fix from $1,600 2024-04-10
Relevanssi HIGH 8.2
CVE-2024-3213

The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rel…

Fix: 4.22.2+
Fix from $1,950 2024-04-09
Nextgen Gallery MEDIUM 5.3
CVE-2024-3097EPSS 38%

The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on…

Fix: 3.59.1+
Fix from $1,600 2024-04-09
Unclassified MEDIUM 5.3
CVE-2024-1984

The Graphene theme for WordPress is vulnerable to unauthorized access of data via meta tag in all versions up to, and including, 2.9.2. This makes it…

Mitigation only
Fix from $1,600 2024-04-09
Registrationmagic HIGH 8.8
CVE-2024-1991

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalat…

Fix: 5.3.1.0+
Fix from $1,950 2024-04-09
Unclassified MEDIUM 6.3
CVE-2024-1850

The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized access, modification or deletion of posts due to a missing capa…

Mitigation only
Fix from $1,600 2024-04-09
Wp Compress HIGH 7.5
CVE-2024-1934

The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'w…

Fix: 6.11.11+
Fix from $1,950 2024-04-09
Newsmatic MEDIUM 5.3
CVE-2024-1587

The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.0 via the 'newsmatic_filt…

Fix: 1.3.5+
Fix from $1,600 2024-04-09
Unclassified MEDIUM 5.4
CVE-2024-1641

The Accordion plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'ac…

Mitigation only
Fix from $1,600 2024-04-09
Classified Listing MEDIUM 5.3
CVE-2024-1352

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access & modification of data …

Fix: 3.0.5+
Fix from $1,600 2024-04-09
Soledad HIGH 7.1
CVE-2024-31367

Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.

Fix: 8.4.6+
Fix from $1,950 2024-04-09
Soledad MEDIUM 6.5
CVE-2024-31368

Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.

Fix: 8.4.6+
Fix from $1,600 2024-04-09