Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Profilegrid HIGH 8.8
CVE-2023-3714

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler…

Fix: 5.5.3+
Fix from $1,950 2023-07-18
Download Theme HIGH 8.8
CVE-2022-38062

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Theme plugin <= 1.0.9 versions.

Fix: after 1.0.9
Fix from $1,950 2023-07-17
Eventprime MEDIUM 6.1
CVE-2023-35884

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions.

Fix: after 3.0.5
Fix from $1,600 2023-06-20
Download Plugin HIGH 8.8
CVE-2022-36345

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions.

Fix: 2.0.5+
Fix from $1,950 2023-05-28
Eventprime MEDIUM 6.1
CVE-2023-33326

Unauth. Reflected (XSS) Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 2.8.6 versions.

Fix: 3.0.0+
Fix from $1,600 2023-05-28
Registrationmagic CRITICAL 9.8
CVE-2023-2499

The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insuffici…

Fix: after 5.2.1.0
Fix from $2,300 2023-05-16
Registrationmagic HIGH 7.2
CVE-2023-2548

The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due …

Fix: after 5.2.0.5
Fix from $1,950 2023-05-16
Themeflection Numbers MEDIUM 6.5
CVE-2023-0889

Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the option…

Fix: 2.0.1+
Fix from $1,600 2023-04-17
Profilegrid HIGH 8.8
CVE-2023-0940

The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. Th…

Fix: 5.3.1+
Fix from $1,950 2023-03-20
Registrationmagic HIGH 8.8
CVE-2023-25991

Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.

Fix: 5.1.9.3+
Fix from $1,950 2023-03-13
Profilegrid HIGH 8.8
CVE-2022-41791

Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.

Fix: after 5.1.6
Fix from $1,950 2022-11-17
Profilegrid MEDIUM 6.1
CVE-2022-3578

The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Fix: 5.1.1+
Fix from $1,600 2022-11-14
Registrationmagic HIGH 7.2
CVE-2022-0420

The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the…

Fix: 5.0.2.2+
Fix from $1,950 2022-03-07
Registrationmagic MEDIUM 6.1
CVE-2021-24648

The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before outputting back in an attribu…

Fix: 5.0.1.9+
Fix from $1,600 2022-02-01
Profilegrid MEDIUM 5.4
CVE-2022-0233

The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficien…

Fix: after 4.7.4
Fix from $1,600 2022-01-18
Registrationmagic HIGH 7.2
CVE-2021-24862EPSS 73%

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statemen…

Fix: 5.0.1.6+
Fix from $1,950 2022-01-10
Registrationmagic HIGH 8.1
CVE-2021-4073EPSS 7%

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew …

Fix: after 5.0.1.7
Fix from $1,950 2021-12-14
Download Plugin MEDIUM 5.7
CVE-2021-24703

The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any aut…

Fix: 1.6.1+
Fix from $1,600 2021-11-23
Registrationmagic HIGH 8.1
CVE-2020-8435

An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. There is SQL injection via the rm_analytics_show_form rm_form_id param…

No fix yet
Fix from $1,950 2020-03-12
Registrationmagic MEDIUM 6.1
CVE-2020-8436

XSS was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress via the rm_form_id, rm_tr, or form_name parameter.

No fix yet
Fix from $1,600 2020-03-12
Registrationmagic HIGH 8.8
CVE-2020-9454

A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site admi…

Fix: after 4.6.0.3
Fix from $1,950 2020-03-06
Registrationmagic HIGH 8.8
CVE-2020-9456

In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to ele…

Fix: after 4.6.0.3
Fix from $1,950 2020-03-06
Registrationmagic HIGH 8.8
CVE-2020-9457

The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable fo…

Fix: after 4.6.0.3
Fix from $1,950 2020-03-06
Registrationmagic HIGH 8.8
CVE-2020-9458

In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to exp…

Fix: after 4.6.0.3
Fix from $1,950 2020-03-06
Profilegrid HIGH 8.8
CVE-2019-15873

The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php reque…

Fix: 2.8.6+
Fix from $1,950 2019-09-03