Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Melapress File Monitor MEDIUM 5.4
CVE-2025-3702

Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting Incorrectly Configured Access …

Fix: 2.2.0+
Fix from $1,600 2025-07-03
Melapress File Monitor MEDIUM 5.4
CVE-2024-9879

The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins…

Fix: 2.1.1+
Fix from $1,600 2025-05-15
Melapress Login Security HIGH 7.2
CVE-2025-39565

Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security melapress-login-security allows Object Injection.This issue aff…

Fix: 2.1.1+
Fix from $1,950 2025-04-16
Melapress Login Security HIGH 8.2
CVE-2025-2876

The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing c…

Fix: 2.1.1+
Fix from $1,950 2025-04-08
Wp Activity Log CRITICAL 9.8
CVE-2025-0767

WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-c…

Mitigation only
Fix from $2,300 2025-02-27
Wp Activity Log MEDIUM 6.1
CVE-2025-0924

The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and includin…

Fix: 5.3.0+
Fix from $1,600 2025-02-17
Wp Activity Log MEDIUM 6.1
CVE-2024-10793

The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including,…

Fix: 5.2.2+
Fix from $1,600 2024-11-15
Wp 2fa HIGH 7.5
CVE-2022-44587

Insertion of Sensitive Information into Log File vulnerability in WP 2FA allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…

Fix: 2.6.4+
Fix from $1,950 2024-06-21
Melapress Login Security HIGH 7.2
CVE-2024-35650

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Melapress MelaPress Login Se…

Fix: 1.3.1+
Fix from $1,950 2024-06-10
Wp 2fa MEDIUM 6.1
CVE-2024-32568

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP 2FA wp-2fa.This issue affects WP 2…

Fix: 2.6.3+
Fix from $1,600 2024-04-18
Wp Activity Log HIGH 8.8
CVE-2024-2018

The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all versions up to, and including, …

Fix: 4.6.4.1+
Fix from $1,950 2024-04-09
Wp 2fa MEDIUM 5.3
CVE-2022-44595

Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0.

Fix: after 2.2.0
Fix from $1,600 2024-03-21
Wp Activity Log MEDIUM 6.1
CVE-2023-50905

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows Stored XSS.Thi…

Fix: 4.6.2+
Fix from $1,600 2024-02-29