Vulnerability index

Browse CVEs

73 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wc Builder MEDIUM 6.5
CVE-2025-68533

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WC Builder wc-builder allows Stored X…

Fix: 1.2.1+
Fix from $1,600 2025-12-24
Wp Plugin Manager MEDIUM 6.5
CVE-2025-64271

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Request Forgery.This issue affects…

Fix: 1.4.8+
Fix from $1,600 2025-11-13
Shoplentor CRITICAL 9.8
CVE-2025-12493

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 3.2.6+
Fix from $2,300 2025-11-04
Shoplentor MEDIUM 5.4
CVE-2025-11823

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Stored Cross-S…

Fix: 3.2.5+
Fix from $1,600 2025-10-25
Shoplentor MEDIUM 5.4
CVE-2025-58990

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems ShopLentor woolentor-addons allows Sto…

Fix: 3.2.1+
Fix from $1,600 2025-09-09
Download Contact Form 7 Widget For Elementor Page Builder \& Gutenberg Blocks CRITICAL 9.8
CVE-2025-7360

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file moving d…

Fix: 2.2.2+
Fix from $2,300 2025-07-15
Download Contact Form 7 Widget For Elementor Page Builder \& Gutenberg Blocks CRITICAL 9.8
CVE-2025-7341

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion…

Fix: 2.2.2+
Fix from $2,300 2025-07-15
Download Contact Form 7 Widget For Elementor Page Builder \& Gutenberg Blocks CRITICAL 9.8
CVE-2025-7340

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file uploads …

Fix: 2.2.2+
Fix from $2,300 2025-07-15
Shoplentor MEDIUM 6.5
CVE-2025-3775

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 3.1.3+
Fix from $1,600 2025-04-25
Ht Mega MEDIUM 5.4
CVE-2025-1802

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_c…

Fix: 2.8.4+
Fix from $1,600 2025-03-20
Shoplentor MEDIUM 5.4
CVE-2025-1527

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 3.1.1+
Fix from $1,600 2025-03-12
Ht Mega MEDIUM 5.4
CVE-2025-1261

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown wi…

Fix: after 2.8.2
Fix from $1,600 2025-03-08
Wp Templata MEDIUM 6.1
CVE-2025-26917

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templata wptemplata allows Reflect…

Fix: 1.0.8+
Fix from $1,600 2025-03-03
Ht Mega MEDIUM 6.4
CVE-2024-12599

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in al…

Fix: after 2.8.1
Fix from $1,600 2025-02-11
Ht Mega MEDIUM 5.4
CVE-2024-12597

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' par…

Fix: 2.7.7+
Fix from $1,600 2025-02-04
Ht Politic MEDIUM 5.4
CVE-2024-51673

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems HT Politic wp-politic allows DOM-Based…

Fix: 2.4.5+
Fix from $1,600 2024-11-09
Ht Builder MEDIUM 5.4
CVE-2024-51682

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder …

Fix: 1.3.1+
Fix from $1,600 2024-11-04
Wp Education MEDIUM 5.4
CVE-2024-49630

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems WP Education wp-education allows Store…

Fix: 1.2.9+
Fix from $1,600 2024-10-20
Shoplentor MEDIUM 6.5
CVE-2024-9538

The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' func…

Fix: 2.9.9+
Fix from $1,600 2024-10-11
Woolentor Woocommerce Elementor Addons \+ Builder MEDIUM 5.4
CVE-2024-8668

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 2.9.8+
Fix from $1,600 2024-09-25
Ht Mega HIGH 8.8
CVE-2024-38706

Path Traversal: '.../...//' vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.5.7.

Fix: 2.5.8+
Fix from $1,950 2024-07-12
Ht Mega MEDIUM 5.4
CVE-2024-5215

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up…

Fix: 2.5.6+
Fix from $1,600 2024-06-26
Ht Mega MEDIUM 5.4
CVE-2024-5173

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in…

Fix: 2.5.6+
Fix from $1,600 2024-06-26
Shoplentor MEDIUM 5.4
CVE-2024-5530

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 2.9.1+
Fix from $1,600 2024-06-11
Ht Feed MEDIUM 5.4
CVE-2024-35699

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Feed allows Stored XSS.This…

Fix: 1.2.9+
Fix from $1,600 2024-06-08
Shoplentor MEDIUM 5.4
CVE-2024-34767

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes ShopLentor allows Stored XSS.T…

Fix: 2.8.8+
Fix from $1,600 2024-06-03
Ht Mega MEDIUM 5.4
CVE-2024-4876

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popover_header_text’ parameter…

Fix: 2.5.3+
Fix from $1,600 2024-05-21
Shoplentor HIGH 7.1
CVE-2024-4566

The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function…

Fix: 2.8.9+
Fix from $1,950 2024-05-21
Shoplentor MEDIUM 5.4
CVE-2024-3345

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, an…

Fix: 2.8.9+
Fix from $1,600 2024-05-21
Ht Mega CRITICAL 9.8
CVE-2023-37999

Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.

Fix: 2.2.1+
Fix from $2,300 2024-05-17