Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Contracts MEDIUM 5.3
CVE-2023-34234

OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer a…

Fix: 4.9.1+
Fix from $1,600 2023-06-07
Add Product Tabs HIGH 8.8
CVE-2021-4337

Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax…

Fix: 1.3.0 / 1.5.0+
Fix from $1,950 2023-06-07
Woocommerce Multi Currency MEDIUM 6.5
CVE-2021-4379

The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wmc_bulk_fixed_pri…

Fix: 2.1.18+
Fix from $1,600 2023-06-07
B2bking MEDIUM 6.5
CVE-2023-3125

The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'b2bking_save_price_impo…

Fix: after 4.6.00
Fix from $1,600 2023-06-07
Wordpress Automatic Plugin CRITICAL 9.8
CVE-2021-4374EPSS 16%

The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to miss…

Fix: after 3.53.2
Fix from $2,300 2023-06-07
Ulisting CRITICAL 9.8
CVE-2021-4381

The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, …

Fix: 1.7+
Fix from $2,300 2023-06-07
Cool Timeline HIGH 8.8
CVE-2022-4950

Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execu…

Fix: 1.2 / 1.3+
Fix from $1,950 2023-06-07
Elementor Pro HIGH 8.8
CVE-2023-3124EPSS 23%

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option fu…

Fix: 3.11.7+
Fix from $1,950 2023-06-07
Frontend File Manager Plugin CRITICAL 9.8
CVE-2021-4356

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. Thi…

Fix: after 18.2
Fix from $2,300 2023-06-07
Ulisting MEDIUM 5.3
CVE-2021-4357

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the Ulisti…

Fix: after 1.6.6
Fix from $1,600 2023-06-07
Frontend File Manager Plugin MEDIUM 5.3
CVE-2021-4359

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This …

Fix: after 18.2
Fix from $1,600 2023-06-07
Jobsearch Wp Job Board HIGH 8.8
CVE-2021-4361

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrat…

Fix: after 1.8.1
Fix from $1,950 2023-06-07
Kiwi Social Share CRITICAL 9.8
CVE-2021-4362

The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_optio…

No fix yet
Fix from $2,300 2023-06-07
Frontend File Manager Plugin HIGH 8.8
CVE-2021-4368

The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to …

Fix: after 18.2
Fix from $1,950 2023-06-07
Frontend File Manager Plugin MEDIUM 5.3
CVE-2021-4369

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due…

Fix: after 18.2
Fix from $1,600 2023-06-07
Ulisting CRITICAL 9.8
CVE-2021-4370

The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack s…

Fix: after 1.6.6
Fix from $2,300 2023-06-07
Ulisting MEDIUM 5.3
CVE-2021-4339

The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file o…

Fix: after 1.6.6
Fix from $1,600 2023-06-07
Ulisting CRITICAL 9.8
CVE-2021-4341

The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a mi…

Fix: after 1.6.6
Fix from $2,300 2023-06-07
Ulisting CRITICAL 9.8
CVE-2021-4343

The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. …

Fix: after 1.6.6
Fix from $2,300 2023-06-07
Ulisting MEDIUM 5.3
CVE-2021-4345

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role…

Fix: after 1.6.6
Fix from $1,600 2023-06-07
Ulisting HIGH 7.5
CVE-2021-4346

The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to …

Fix: after 1.6.6
Fix from $1,950 2023-06-07
Advanced Shipment Tracking For Woocommerce MEDIUM 6.5
CVE-2021-4347

The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable t…

Fix: after 3.2.6
Fix from $1,600 2023-06-07
Ultimate Gdpr \& Ccpa Compliance Toolkit MEDIUM 6.1
CVE-2021-4348

The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export_settings & import_settings f…

Fix: 2.5+
Fix from $1,600 2023-06-07
Frontend File Manager Plugin MEDIUM 5.3
CVE-2021-4350

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to…

Fix: after 18.2
Fix from $1,600 2023-06-07
Frontend File Manager Plugin MEDIUM 5.3
CVE-2021-4351

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due …

Fix: after 18.2
Fix from $1,600 2023-06-07
Welcart E Commerce MEDIUM 5.3
CVE-2021-4355

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list()…

Fix: after 2.2.7
Fix from $1,600 2023-06-07
Listingpro CRITICAL 9.8
CVE-2020-36719

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in ver…

Fix: after 2.6.1
Fix from $2,300 2023-06-07
Kali Forms HIGH 7.1
CVE-2020-36720

The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_…

Fix: after 2.1.1
Fix from $1,950 2023-06-07
Activello MEDIUM 6.5
CVE-2020-36721

The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is …

Fix: 1.0.6 / 1.1.2+
Fix from $1,600 2023-06-07
Ti Woocommerce Wishlist HIGH 8.1
CVE-2020-36725

The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to…

Fix: 1.21.5 / 1.21.12+
Fix from $1,950 2023-06-07