Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Recipe Maker MEDIUM 5.4
CVE-2024-9650

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip’ parameter in all versions up to, and includin…

Fix: after 9.7.0
Fix from $1,600 2024-10-24
Wp Recipe Maker MEDIUM 5.4
CVE-2024-0383

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [wprm-recipe-instructions] and [wprm-recipe-in…

Fix: 9.1.1+
Fix from $1,600 2024-06-19
Wp Recipe Maker MEDIUM 5.4
CVE-2024-3490

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-roundup-item shortcode in all vers…

Fix: 9.4.0+
Fix from $1,600 2024-05-02
Wp Recipe Maker HIGH 8.8
CVE-2024-1206

The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up to, and including, 9.1.2 due t…

Fix: 9.2.0+
Fix from $1,950 2024-02-29
Wp Recipe Maker MEDIUM 5.4
CVE-2024-0382

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and includ…

Fix: after 9.1.0
Fix from $1,600 2024-02-05
Wp Recipe Maker MEDIUM 5.4
CVE-2024-0384

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Notes in all versions up to, and including, 9.1.0 du…

Fix: after 9.1.0
Fix from $1,600 2024-02-05
Wp Recipe Maker MEDIUM 5.4
CVE-2024-0255

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text-share' shortcode in all vers…

Fix: after 9.1.0
Fix from $1,600 2024-02-05
Wp Recipe Maker MEDIUM 5.4
CVE-2024-0381

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wpr…

Fix: after 9.1.0
Fix from $1,600 2024-01-18
Wp Recipe Maker MEDIUM 6.1
CVE-2023-6970

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and includin…

Fix: after 9.1.0
Fix from $1,600 2024-01-18
Wp Recipe Maker MEDIUM 5.4
CVE-2023-6958

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and includ…

Fix: after 9.1.0
Fix from $1,600 2024-01-18
Easy Affiliate Links MEDIUM 5.4
CVE-2023-0375

The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/p…

Fix: 3.7.1+
Fix from $1,600 2023-02-21
Wp Recipe Maker MEDIUM 5.4
CVE-2022-4468

The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before outputting them back in the pa…

Fix: 8.6.1+
Fix from $1,600 2023-01-09
Dynamic Widgets MEDIUM 5.4
CVE-2021-24933

The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the ter…

Fix: after 1.5.16
Fix from $1,600 2022-02-28
Visual Link Preview MEDIUM 5.4
CVE-2021-24635

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all…

Fix: 2.2.3+
Fix from $1,600 2021-09-20
Wp Ultimate Recipe MEDIUM 5.4
CVE-2019-15836

The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.

Fix: 3.12.7+
Fix from $1,600 2019-08-30