Vulnerability index

Browse CVEs

63 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-4338 The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/schedule… Activitypub 8.0.2+ Fix from $1,9502026-04-08 MEDIUM 6.1 CVE-2023-54332 Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the p… Jetpack No fix yet Fix from $1,6002026-01-13 CRITICAL 9.1 CVE-2024-6584 The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs. Jetpack Boost 3.4.7+ Fix from $2,3002025-05-15 MEDIUM 5.9 CVE-2024-10076 The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching i… Jetpack 3.4.8 / 13.8+ Fix from $1,6002025-05-15 MEDIUM 5.6 CVE-2024-10075 The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which cou… Jetpack 13.8+ Fix from $1,6002025-05-15 MEDIUM 5.3 CVE-2025-0466 The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_e… Sensei Lms 4.24.4+ Fix from $1,6002025-02-04 MEDIUM 6.1 CVE-2024-10858 The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leadin… Jetpack 14.1+ Fix from $1,6002024-12-25 MEDIUM 6.1 CVE-2024-10103 In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of… Mailpoet 5.3.2+ Fix from $1,6002024-11-19 HIGH 8.8 CVE-2024-43968 Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects… Newspack 3.8.7+ Fix from $1,9502024-11-01 MEDIUM 5.3 CVE-2024-7786 The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email t… Sensei Lms 4.24.2+ Fix from $1,6002024-09-04 MEDIUM 5.4 CVE-2024-43949 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.… Ghacitivity after 1.5.0 Fix from $1,6002024-08-29 MEDIUM 5.4 CVE-2024-37474 Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1. Newspack Ads 1.47.2+ Fix from $1,6002024-07-04 MEDIUM 5.4 CVE-2024-37476 Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2… Newspack Popups 2.31.2+ Fix from $1,6002024-07-04 HIGH 8.8 CVE-2023-47788 Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7. Jetpack 12.7+ Fix from $1,9502024-06-19 MEDIUM 5.4 CVE-2024-4392 The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortco… Jetpack 13.4+ Fix from $1,6002024-05-14 MEDIUM 5.4 CVE-2023-47774 Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a bef… Jetpack 12.7+ Fix from $1,6002024-04-24 HIGH 8.8 CVE-2023-51489 Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dash… Crowdsignal Dashboard 3.1.0+ Fix from $1,9502024-03-16 MEDIUM 5.4 CVE-2023-50875 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes… Sensei Lms after 4.17.0 Fix from $1,6002024-02-12 MEDIUM 6.1 CVE-2023-51488 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls,… Crowdsignal Dashboard after 3.0.11 Fix from $1,6002024-02-10 CRITICAL 9.8 CVE-2023-51502 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Strip… Woocommerce Stripe after 7.6.1 Fix from $2,3002024-01-05 HIGH 7.5 CVE-2023-51503 Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This … Woopayments 6.7.0+ Fix from $1,9502023-12-31 MEDIUM 5.4 CVE-2023-50879 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress.Com Editing Toolkit allows… Wordpress.com Editing Toolkit after 3.78784 Fix from $1,6002023-12-29 HIGH 7.5 CVE-2023-32747 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a … Woocommerce Bookings after 1.15.78 Fix from $1,9502023-12-21 CRITICAL 9.8 CVE-2023-35915 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments – Fully Integrated Solut… Woopayments 5.9.1+ Fix from $2,3002023-12-20 HIGH 7.5 CVE-2023-35914 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a throug… Woocommerce Subscriptions 5.1.3+ Fix from $1,9502023-12-20 HIGH 7.5 CVE-2023-35916 Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This … Woopayments 5.9.1+ Fix from $1,9502023-12-20 HIGH 8.1 CVE-2023-35876 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a thro… Woocommerce Square 3.8.2+ Fix from $1,9502023-12-20 HIGH 7.5 CVE-2023-37871 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6. Woocommerce Gocardless 2.5.7+ Fix from $1,9502023-12-20 HIGH 8.8 CVE-2023-47787 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3. Woocommerce Bookings 2.0.4+ Fix from $1,9502023-12-18 HIGH 8.8 CVE-2023-47789 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shipping Method: from n/a t… Canada Post Shipping Method 2.8.4+ Fix from $1,9502023-12-18