Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Album And Image Gallery Plus Lightbox HIGH 7.3
CVE-2024-4194

The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includin…

Fix: 2.1+
Fix from $1,950 2024-06-06
Audio Player With Playlist Ultimate MEDIUM 5.4
CVE-2023-38516

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Audio Player with Playlist Ultimate plugin…

Fix: after 1.2.2
Fix from $1,600 2023-09-03
Hero Banner Ultimate MEDIUM 5.4
CVE-2022-45818

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate plugin <= 1.3.4 versi…

Fix: after 1.3.4
Fix from $1,600 2023-05-04
Popup Anything HIGH 8.8
CVE-2022-38077

Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversi…

Fix: after 2.2.1
Fix from $1,950 2023-03-29
Product Slider And Carousel With Category With Woocommerce MEDIUM 5.4
CVE-2022-4791

The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attribute…

Fix: 2.8+
Fix from $1,600 2023-02-21
Download Post Category Image With Grid And Slider MEDIUM 5.4
CVE-2022-4747

The Post Category Image With Grid and Slider WordPress plugin before 1.4.8 does not validate and escape some of its shortcode attributes before outpu…

Fix: 1.4.8+
Fix from $1,600 2023-02-06
Wp Blog And Widget MEDIUM 5.4
CVE-2022-4824

The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in th…

Fix: 2.3.1+
Fix from $1,600 2023-02-06
Popup Anything MEDIUM 6.1
CVE-2022-2115

The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a …

Fix: 2.1.7+
Fix from $1,600 2022-07-25
Popup Anything MEDIUM 5.4
CVE-2021-24883

The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role a…

Fix: 2.0.4+
Fix from $1,600 2021-11-29