Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Geodirectory MEDIUM 5.9
CVE-2025-6200

The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page…

Fix: 2.8.120+
Fix from $1,600 2025-07-11
Ketchup Shortcodes MEDIUM 5.4
CVE-2024-13590

The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' shortcode in all versions up to, a…

Fix: 0.2.1+
Fix from $1,600 2025-01-22
Geodirectory MEDIUM 5.4
CVE-2024-56259

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored X…

Fix: 2.3.85+
Fix from $1,600 2025-01-02
Geodirectory HIGH 8.8
CVE-2024-43981

Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control S…

Fix: 2.3.71+
Fix from $1,950 2024-11-01
Getpaid HIGH 8.8
CVE-2024-43973

Missing Authorization vulnerability in Stiofan GetPaid invoicing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

Fix: 2.8.12+
Fix from $1,950 2024-11-01
Geodirectory MEDIUM 5.4
CVE-2024-50437

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored X…

Fix: 2.3.81+
Fix from $1,600 2024-10-28
Geodirectory HIGH 8.8
CVE-2024-43145

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDirectory.This issue affects Geo…

Fix: 2.3.62+
Fix from $1,950 2024-08-18
Userswp HIGH 7.5
CVE-2024-6477

The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers …

Fix: 1.2.12+
Fix from $1,950 2024-08-03
Userswp CRITICAL 9.8
CVE-2024-6265

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to ti…

Fix: 1.2.11+
Fix from $2,300 2024-06-29
Geodirectory MEDIUM 5.4
CVE-2024-3732

The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via…

Fix: 2.3.49+
Fix from $1,600 2024-04-23
Userswp MEDIUM 6.4
CVE-2024-2423

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to St…

Fix: 1.2.7+
Fix from $1,600 2024-04-09
Geodirectory HIGH 7.2
CVE-2023-50845

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins …

Fix: after 2.3.28
Fix from $1,950 2023-12-28
Userswp HIGH 8.8
CVE-2022-47442

Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.

Fix: 1.2.3.10+
Fix from $1,950 2023-11-07
Geodirectory MEDIUM 5.4
CVE-2022-4775

The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page…

Fix: 2.2.22+
Fix from $1,600 2023-01-23
Geodirectory MEDIUM 5.4
CVE-2021-24720

The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).

Fix: 2.1.1.3+
Fix from $1,600 2021-10-11
Location Manager CRITICAL 9.8
CVE-2021-24361

In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its …

Fix: 2.1.0.10+
Fix from $2,300 2021-06-21
Getpaid MEDIUM 5.4
CVE-2021-24369

In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, however the Label and Help Tex…

Fix: 2.3.4+
Fix from $1,600 2021-06-21