Vulnerability index

Browse CVEs

73 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Swatchly HIGH 8.8
CVE-2023-23792

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Swatchly plugin <= 1.2.0 versions.

Fix: 1.2.1+
Fix from $1,950 2023-07-11
Ht Feed HIGH 8.8
CVE-2023-23804

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Feed plugin <= 1.2.7 versions.

Fix: 1.2.8+
Fix from $1,950 2023-07-10
Ht Easy Ga4 \(google Analytics 4\) HIGH 8.8
CVE-2023-23802

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions.

Fix: 1.0.7+
Fix from $1,950 2023-06-15
Really Simple Google Tag Manager HIGH 8.8
CVE-2023-23801

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions.

Fix: 1.0.7+
Fix from $1,950 2023-04-06
Wp Film Studio MEDIUM 6.5
CVE-2023-0500

The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admi…

Fix: 1.3.5+
Fix from $1,600 2023-03-27
Wp Insurance MEDIUM 6.5
CVE-2023-0501

The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins…

Fix: 2.1.4+
Fix from $1,600 2023-03-27
Wp News MEDIUM 6.5
CVE-2023-0502

The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins act…

Fix: after 1.1.9
Fix from $1,600 2023-03-27
Woolentor Woocommerce Elementor Addons \+ Builder MEDIUM 5.4
CVE-2022-46798

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.

Fix: 2.5.2+
Fix from $1,600 2023-03-01
Shoplentor CRITICAL 9.8
CVE-2023-0232

The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead t…

Fix: 2.5.4+
Fix from $2,300 2023-02-21
Shoplentor MEDIUM 5.4
CVE-2023-0231

The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where …

Fix: 2.5.4+
Fix from $1,600 2023-02-21
Hashbar MEDIUM 5.4
CVE-2022-4650

The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as…

Fix: 1.3.6+
Fix from $1,600 2023-01-23
Ht Mega MEDIUM 5.4
CVE-2021-24261

The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site…

Fix: 1.5.7+
Fix from $1,600 2021-05-05
Woolentor Woocommerce Elementor Addons \+ Builder MEDIUM 5.4
CVE-2021-24262

The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting…

Fix: 1.8.6+
Fix from $1,600 2021-05-05