Vulnerability index

Browse CVEs

63 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Woopayments MEDIUM 5.4
CVE-2023-49828

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solut…

Fix: 6.5.0+
Fix from $1,600 2023-12-14
Woocommerce MEDIUM 5.4
CVE-2023-47777

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce …

Fix: after 11.1.1
Fix from $1,600 2023-11-30
Jetpack MEDIUM 5.4
CVE-2023-45050

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – WP Security, Backup, Speed…

Fix: after 12.8-a.1
Fix from $1,600 2023-11-30
Jetpack Crm HIGH 8.8
CVE-2022-3342

The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_ap…

Fix: after 5.3.1
Fix from $1,950 2023-10-20
Activitypub MEDIUM 5.4
CVE-2023-5057

The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role o…

Fix: 1.0.0+
Fix from $1,600 2023-10-16
Activitypub MEDIUM 5.4
CVE-2023-3746

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role …

Fix: 1.0.0+
Fix from $1,600 2023-10-16
Jetpack HIGH 8.8
CVE-2023-2996

The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files o…

Fix: 12.1.1+
Fix from $1,950 2023-06-27
Vaultpress CRITICAL 9.8
CVE-2014-125104

A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is the func…

Fix: 1.6.1+
Fix from $2,300 2023-06-01
Woocommerce Payments CRITICAL 9.8
CVE-2023-28121EPSS 87%

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an …

Fix: 4.8.2 / 5.0.4+
Fix from $2,300 2023-04-12
Jetpack Crm MEDIUM 5.4
CVE-2022-4497

The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, wh…

Fix: 5.5.0+
Fix from $1,600 2023-01-09
Crowdsignal Dashboard HIGH 8.8
CVE-2022-45069

Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.

Fix: 3.0.10+
Fix from $1,950 2022-11-17
Sensei Lms MEDIUM 5.3
CVE-2022-2034

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to acce…

Fix: 4.5.0+
Fix from $1,600 2022-08-29
Crowdsignal Dashboard MEDIUM 6.1
CVE-2022-2386

The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Fix: 3.0.8+
Fix from $1,600 2022-08-08
Vaultpress HIGH 7.5
CVE-2017-20086

A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code…

No fix yet
Fix from $1,950 2022-06-23
Woocommerce Blocks HIGH 7.5
CVE-2021-32789EPSS 17%

woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sit…

Fix: 2.5.16 / 2.6.2+
Fix from $1,950 2021-07-26
Jetpack MEDIUM 5.3
CVE-2021-24374

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to com…

Fix: 9.8+
Fix from $1,600 2021-06-21
Wp Super Cache MEDIUM 5.4
CVE-2021-24329

The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Sto…

Fix: 1.7.3+
Fix from $1,600 2021-06-01
Wp Super Cache HIGH 7.2
CVE-2021-24312

The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of …

Fix: 1.7.3+
Fix from $1,950 2021-06-01
Wp Super Cache HIGH 7.2
CVE-2021-24209EPSS 24%

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure a…

Fix: 1.7.2+
Fix from $1,950 2021-04-05
Canvas HIGH 8.8
CVE-2020-8215

A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a u…

Fix: after 1.6.9
Fix from $1,950 2020-07-20
Mailpoet MEDIUM 6.1
CVE-2019-11843

The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Ref…

Fix: 3.23.2+
Fix from $1,600 2020-06-02
Wp Super Cache CRITICAL 9.8
CVE-2013-2010EPSS 74%

WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability

Fix: after 1.2
Fix from $2,300 2020-02-12
Wp Super Cache HIGH 8.8
CVE-2013-2009EPSS 13%

WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution

Patch available
Fix from $1,950 2020-02-07
Wp Super Cache MEDIUM 6.1
CVE-2013-2008

WordPress Super Cache Plugin 1.3 has XSS.

Patch available
Fix from $1,600 2020-02-07
W3 Super Cache HIGH 8.8
CVE-2013-2011EPSS 5%

WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code.…

Fix: 1.3.2+
Fix from $1,950 2019-12-26
Jetpack MEDIUM 6.1
CVE-2015-9359

The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 3.4.3+
Fix from $1,600 2019-08-28
Akismet MEDIUM 6.1
CVE-2015-9357

The akismet plugin before 3.1.5 for WordPress has XSS.

Fix: 3.1.5+
Fix from $1,600 2019-08-28
Camptix Event Ticketing HIGH 7.5
CVE-2016-10762

The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used.

Fix: 1.5.0+
Fix from $1,950 2019-07-18
Jetpack MEDIUM 6.1
CVE-2016-10705

The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.

Fix: after 4.0.3
Fix from $1,600 2018-01-12
Jetpack MEDIUM 6.1
CVE-2016-10706

The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.

Fix: 4.0.3+
Fix from $1,600 2018-01-12