Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Social Share Buttons MEDIUM 6.1
CVE-2024-9219

The WordPress Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appro…

Fix: after 1.19
Fix from $1,600 2024-10-19
Media Library Folders MEDIUM 6.3
CVE-2024-7858

The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the…

Fix: 8.2.4+
Fix from $1,600 2024-08-30
Media Library Folders MEDIUM 6.5
CVE-2024-7857

The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter of the 'mlf_change_sort_type…

Fix: 8.2.3+
Fix from $1,600 2024-08-29
Maxbuttons MEDIUM 5.3
CVE-2024-6499

The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This m…

Fix: 9.8.0+
Fix from $1,600 2024-08-24
Maxbuttons MEDIUM 5.4
CVE-2024-3026

The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a rol…

Fix: 9.7.8+
Fix from $1,600 2024-07-13
Media Library Folders MEDIUM 6.1
CVE-2024-3615

The Media Library Folders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and inclu…

Fix: 8.1.8+
Fix from $1,600 2024-04-19
Media Library Folders MEDIUM 6.5
CVE-2024-31287

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Library Folders.This issue affects …

Fix: 8.1.9+
Fix from $1,600 2024-04-10
Media Library Folders HIGH 8.8
CVE-2024-30486

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Max Foundry Media Library Folders.This issue af…

Fix: 8.1.8+
Fix from $1,950 2024-03-29
Maxbuttons MEDIUM 5.4
CVE-2023-7029

The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all version…

Fix: 9.7.7+
Fix from $1,600 2024-02-05
Maxbuttons MEDIUM 5.4
CVE-2023-36503

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Max Foundry WordPress Button Plugin MaxButtons plugin <= 9.5.3 versions.

Fix: after 9.5.3
Fix from $1,600 2023-07-25
Maxbuttons MEDIUM 6.1
CVE-2014-125092

A vulnerability was found in MaxButtons Plugin up to 1.26.0 on WordPress and classified as problematic. This issue affects the function maxbuttons_st…

Fix: 1.26.1+
Fix from $1,600 2023-03-05
Media Library Folders HIGH 8.8
CVE-2022-41634

Cross-Site Request Forgery (CSRF) vulnerability in Media Library Folders plugin <= 7.1.1 on WordPress.

Fix: 7.1.2+
Fix from $1,950 2022-11-18
Maxbuttons HIGH 8.8
CVE-2022-36346

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress.

Fix: after 9.2
Fix from $1,950 2022-08-22