Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Web Stories Enhancer MEDIUM 5.4
CVE-2024-13575

The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'web_stories_…

Fix: 1.4+
Fix from $1,600 2025-02-18
Pwa For Wp \& Amp HIGH 8.8
CVE-2024-47318

Missing Authorization vulnerability in Magazine3 PWA for WP & AMP pwa-for-wp.This issue affects PWA for WP & AMP: from n/a through <= 1.7.72.

Fix: 1.7.73+
Fix from $1,950 2024-11-01
Easy Table Of Contents MEDIUM 6.1
CVE-2024-7082

The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as…

Fix: 2.0.68+
Fix from $1,600 2024-08-06
Schema \& Structured Data For Wp \& Amp MEDIUM 5.4
CVE-2024-5582

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within t…

Fix: 1.34.1+
Fix from $1,600 2024-07-17
Easy Table Of Contents MEDIUM 6.1
CVE-2024-6334

The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users…

Fix: 2.0.67.1+
Fix from $1,600 2024-07-09
Easy Table Of Contents MEDIUM 5.9
CVE-2024-5573

The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users s…

Fix: 2.0.66+
Fix from $1,600 2024-06-26
Schema \& Structured Data For Wp \& Amp MEDIUM 5.4
CVE-2024-1586

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom schema in all versions up …

Fix: 1.27+
Fix from $1,600 2024-02-29
Schema \& Structured Data For Wp \& Amp MEDIUM 5.4
CVE-2024-22146

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP…

Fix: after 1.25
Fix from $1,600 2024-01-31
Amp For Wp MEDIUM 5.4
CVE-2023-6782

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all vers…

Fix: after 1.0.92
Fix from $1,600 2024-01-11
Core Web Vitals \& Pagespeed Booster MEDIUM 6.1
CVE-2023-35883

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magazine3 Core Web Vitals & PageSpeed Booster.This issue affects Core Web Vitals…

Fix: after 1.0.12
Fix from $1,600 2023-12-19
Amp For Wp MEDIUM 5.4
CVE-2023-48321

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmed Kaludi, Mohammed Kaludi AMP for WP – Acce…

Fix: after 1.0.88.1
Fix from $1,600 2023-11-30
Pwa For Wp \& Amp HIGH 8.8
CVE-2021-4354

The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader …

Fix: 1.7.33+
Fix from $1,950 2023-06-07
Amp For Wp MEDIUM 5.4
CVE-2018-20838

ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.

Fix: 0.9.97.21+
Fix from $1,600 2019-05-13