Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp File Download HIGH 7.1
CVE-2025-5034

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Refle…

Fix: 6.2.6+
Fix from $1,950 2025-06-21
Wp Table Manager MEDIUM 6.5
CVE-2024-13374

The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in…

Fix: 4.1.4+
Fix from $1,600 2025-02-12
Wp Meta Seo MEDIUM 5.4
CVE-2024-45456

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomUnited WP Meta SEO wp-meta-seo allows Store…

Fix: 4.5.14+
Fix from $1,600 2024-09-15
Wp Meta Seo MEDIUM 6.1
CVE-2023-6961

The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Referer’ header in all versions up to, and including, 4.5.…

Fix: 4.5.13+
Fix from $1,600 2024-05-02
Wp Meta Seo MEDIUM 5.3
CVE-2023-6962

The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta descri…

Fix: 4.5.13+
Fix from $1,600 2024-05-02
Wp Media Folder HIGH 8.8
CVE-2024-25909

Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.…

Fix: 5.7.3+
Fix from $1,950 2024-02-26
Wp Smart Editor MEDIUM 6.1
CVE-2024-22148

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Smart Editor JoomUnited allows Reflected XSS…

Fix: after 1.3.3
Fix from $1,600 2024-02-01
Wp Meta Seo HIGH 8.8
CVE-2023-1381

The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR d…

Fix: 4.5.5+
Fix from $1,950 2023-04-10
Wp Table Manager MEDIUM 5.4
CVE-2022-47602

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in JoomUnited WP Table Manager plugin <= 3.5.2 versions.

Fix: after 3.5.2
Fix from $1,600 2023-03-29
Wp Meta Seo HIGH 8.8
CVE-2023-0875

The WP Meta SEO WordPress plugin before 4.5.3 does not properly sanitize and escape inputs into SQL queries, leading to a blind SQL Injection vulnera…

Fix: 4.5.3+
Fix from $1,950 2023-03-20
Wp Meta Seo MEDIUM 6.1
CVE-2023-0876

The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data a…

Fix: 4.5.3+
Fix from $1,600 2023-03-20
Wp Latest Posts MEDIUM 6.1
CVE-2016-10913

The wp-latest-posts plugin before 3.7.5 for WordPress has XSS.

Fix: 3.7.5+
Fix from $1,600 2019-08-20