Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Registrationmagic CRITICAL 9.8
CVE-2017-20208

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Inject…

Fix: 3.7.9.3+
Fix from $2,300 2025-10-18
Profilegrid MEDIUM 6.1
CVE-2025-6977

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenge…

Fix: 5.9.5.5+
Fix from $1,600 2025-07-16
Download Plugin HIGH 7.2
CVE-2025-6586

The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwap_plugin_locInstall f…

Fix: 2.2.9+
Fix from $1,950 2025-07-04
Eventprime MEDIUM 6.4
CVE-2024-4665

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings …

Fix: 3.5.0+
Fix from $1,600 2025-05-15
Profilegrid HIGH 8.8
CVE-2025-0724

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi…

Fix: 5.9.4.6+
Fix from $1,950 2025-03-22
Profilegrid MEDIUM 6.5
CVE-2025-0723

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and sea…

Fix: 5.9.4.8+
Fix from $1,600 2025-03-22
Profilegrid MEDIUM 5.4
CVE-2024-13741

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up …

Fix: 5.9.4.3+
Fix from $1,600 2025-02-18
Registrationmagic MEDIUM 6.1
CVE-2025-24686

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic custom-registration…

Fix: 6.0.3.4+
Fix from $1,600 2025-01-31
Eventprime MEDIUM 6.1
CVE-2024-12024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_d…

Fix: 4.0.6.0+
Fix from $1,600 2024-12-17
Registrationmagic HIGH 7.5
CVE-2023-49831

Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorre…

Fix: 5.2.3.1+
Fix from $1,950 2024-12-09
Profilegrid HIGH 8.1
CVE-2024-10900

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa…

Fix: 5.9.3.7+
Fix from $1,950 2024-11-20
Registrationmagic CRITICAL 9.8
CVE-2024-10508

The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via accoun…

Fix: 6.0.2.7+
Fix from $2,300 2024-11-09
Eventprime HIGH 8.8
CVE-2024-43223

Missing Authorization vulnerability in EventPrime Events EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Fix: 4.0.4.0+
Fix from $1,950 2024-11-01
Profilegrid HIGH 8.8
CVE-2024-37453

Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels.…

Fix: 5.8.8+
Fix from $1,950 2024-11-01
Eventprime MEDIUM 6.1
CVE-2024-9864

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket names in all vers…

Fix: 4.0.4.8+
Fix from $1,600 2024-10-24
Eventprime MEDIUM 6.1
CVE-2024-9865

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ep_booking_attendee…

Fix: 4.0.4.8+
Fix from $1,600 2024-10-24
Download Plugin MEDIUM 6.5
CVE-2024-9829

The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_downloa…

Fix: 2.2.1+
Fix from $1,600 2024-10-23
Profilegrid MEDIUM 6.5
CVE-2024-49273

Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities.This issue affects ProfileGrid : from …

Fix: after 5.9.3
Fix from $1,600 2024-10-21
Profilegrid MEDIUM 5.4
CVE-2024-8861

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and …

Fix: 5.9.3.3+
Fix from $1,600 2024-09-26
Eventprime MEDIUM 5.3
CVE-2024-8369

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected eve…

Fix: 4.0.4.4+
Fix from $1,600 2024-09-10
Registrationmagic MEDIUM 6.1
CVE-2024-43317

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss User Registration Team Registr…

Fix: 6.0.1.1+
Fix from $1,600 2024-08-19
Registrationmagic MEDIUM 6.1
CVE-2024-39643

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RegistrationMagic Forms RegistrationMagi…

Fix: 6.0.0.2+
Fix from $1,600 2024-08-01
Profilegrid HIGH 8.8
CVE-2024-6411

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi…

Fix: 5.9.0+
Fix from $1,950 2024-07-10
Profilegrid MEDIUM 6.3
CVE-2023-52117

Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6.

Fix: 5.6.7+
Fix from $1,600 2024-06-12
Eventprime CRITICAL 9.8
CVE-2024-31275

Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4.

Fix: 3.3.5+
Fix from $2,300 2024-06-09
Registrationmagic HIGH 7.5
CVE-2023-51543

Authentication Bypass by Spoofing vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This i…

Fix: 5.2.5.1+
Fix from $1,950 2024-06-04
Registrationmagic MEDIUM 5.3
CVE-2023-51544

Improper Control of Interaction Frequency vulnerability in Metagauss RegistrationMagic allows Functionality Misuse.This issue affects RegistrationMag…

Fix: 5.2.5.1+
Fix from $1,600 2024-06-04
Profilegrid HIGH 8.8
CVE-2024-32774

Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This …

Fix: 5.8.3+
Fix from $1,950 2024-05-17
Eventprime MEDIUM 5.3
CVE-2023-33321

Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect…

Fix: 3.0.0+
Fix from $1,600 2024-05-17
Registrationmagic MEDIUM 6.1
CVE-2024-33947

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XS…

Fix: 5.3.2.1+
Fix from $1,600 2024-05-03