Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2024-33919 Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor.This issue affects RomethemeKit For Elementor: from n/a through 1.4.1. Mitigation only Fix from $1,6002024-05-03 MEDIUM 5.3 CVE-2024-33920 Missing Authorization vulnerability in Kama Democracy Poll.This issue affects Democracy Poll: from n/a through 6.0.3. No fix yet Fix from $1,6002024-05-03 MEDIUM 5.3 CVE-2024-33941 Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour B… Mitigation only Fix from $1,6002024-05-03 HIGH 7.6 CVE-2024-32810 Missing Authorization vulnerability in ShortPixel ShortPixel Critical CSS.This issue affects ShortPixel Critical CSS: from n/a through 1.0.2. Mitigation only Fix from $1,9502024-05-03 MEDIUM 5.3 CVE-2023-25457 Missing Authorization vulnerability in Richteam Slider Carousel – Responsive Image Slider.This issue affects Slider Carousel – Responsive Image Slide… Mitigation only Fix from $1,6002024-05-03 HIGH 8.8 CVE-2023-38102 NETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attac… Prosafe Network Management System 1.7.0.20+ Fix from $1,9502024-05-03 HIGH 8.8 CVE-2024-3895 The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdp_add_new_datep… Wp Datepicker 2.1.1+ Fix from $1,9502024-05-02 MEDIUM 5.3 CVE-2024-3897 The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… Mitigation only Fix from $1,6002024-05-02 MEDIUM 5.4 CVE-2024-3942 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and … Masterstudy Lms 3.3.9+ Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-3585 The Send PDF for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of form submissions due to a missing capability check on th… Mitigation only Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-3599 The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check… Wp Cookie Consent 3.1.0+ Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-3601 The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… Poll Maker 5.1.9+ Fix from $1,6002024-05-02 MEDIUM 6.5 CVE-2024-3553 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… Tutor Lms 2.7.0+ Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-3287 The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to unauthorized ld+json description injection du… Mitigation only Fix from $1,6002024-05-02 MEDIUM 6.5 CVE-2024-3295 The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized lo… Mitigation only Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-3312 The Easy Custom Auto Excerpt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.12. This … Mitigation only Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-2797 The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due to a missing capability check … Mitigation only Fix from $1,6002024-05-02 HIGH 8.8 CVE-2024-2417 The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escal… Patch available Fix from $1,9502024-05-02 MEDIUM 5.3 CVE-2024-2043 The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a miss… Eleforms 2.9.9.8+ Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-2109 The Booster Extension plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.0 via the 'boost… Mitigation only Fix from $1,6002024-05-02 HIGH 7.1 CVE-2024-1945 The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to unauthorized loss of data du… Mitigation only Fix from $1,9502024-05-02 MEDIUM 5.4 CVE-2024-1809 The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data … Analytify Google Analytics Dashboard 5.2.4+ Fix from $1,6002024-05-02 HIGH 8.8 CVE-2024-1677 The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized ac… Print Labels With Barcodes 3.4.7+ Fix from $1,9502024-05-02 MEDIUM 5.3 CVE-2024-1688 The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_orders_archive() f… Mitigation only Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-1584 The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of… Analytify Google Analytics Dashboard 5.2.4+ Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-0908 The Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page plugin for WordPress is vulnerable to unauthorized access of data due to… Mitigation only Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-0629 The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… Mitigation only Fix from $1,6002024-05-02 MEDIUM 6.5 CVE-2024-34146 Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing a… Git Server after 114.v068a_c7cc2574 Fix from $1,6002024-05-02 MEDIUM 6.5 CVE-2024-33944 Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce AWeber Newsletter Subscripti… Mitigation only Fix from $1,6002024-05-02 MEDIUM 6.5 CVE-2024-1371 The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_a… Mitigation only Fix from $1,6002024-04-30