Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Stratum MEDIUM 5.4
CVE-2024-13642

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hotspot widget in all versio…

Fix: 1.5.0+
Fix from $1,600 2025-01-30
Getwid MEDIUM 5.4
CVE-2024-10872

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-custom-field` block in all ver…

Fix: after 2.0.12
Fix from $1,600 2024-11-20
Timetable And Event Schedule CRITICAL 9.8
CVE-2020-36840

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_…

Fix: 2.3.9+
Fix from $2,300 2024-10-16
Getwid MEDIUM 5.3
CVE-2024-6489

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_go…

Fix: after 2.0.10
Fix from $1,600 2024-07-20
Getwid MEDIUM 5.4
CVE-2024-3588

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block in all versions up t…

Fix: after 2.0.7
Fix from $1,600 2024-05-02
Getwid MEDIUM 5.4
CVE-2024-1948

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and incl…

Fix: 2.0.6+
Fix from $1,600 2024-04-09
Getwid MEDIUM 5.3
CVE-2023-6963

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible fo…

Fix: 2.0.5+
Fix from $1,600 2024-02-05
Getwid HIGH 7.5
CVE-2023-6042

Any unauthenticated user may send e-mail from the site with any title or content to the admin

Fix: 2.0.3+
Fix from $1,950 2024-01-08
Hotel Booking Lite CRITICAL 9.8
CVE-2023-5991

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and a…

Fix: 4.8.5+
Fix from $2,300 2023-12-26
Jetblocks For Elementor MEDIUM 6.1
CVE-2023-48756

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor allows Refle…

Fix: after 1.3.8
Fix from $1,600 2023-12-14
Hotel Booking Lite HIGH 8.8
CVE-2023-28498

Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions.

Fix: after 4.6.0
Fix from $1,950 2023-11-12
Getwid CRITICAL 9.6
CVE-2023-1895

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versi…

Fix: after 1.8.3
Fix from $2,300 2023-06-09
Timetable And Event Schedule MEDIUM 6.1
CVE-2022-2843

A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this issue is some unknown functio…

Mitigation only
Fix from $1,600 2022-08-16
Timetable And Event Schedule MEDIUM 6.1
CVE-2022-2844

A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This affects an unknown part of the …

Fix: after 1.4.06
Fix from $1,600 2022-08-16
Motopress Slider Lite MEDIUM 5.4
CVE-2021-24544

The Responsive WordPress Slider WordPress plugin through 2.2.0 does not sanitise and escape some of the Slider options, allowing Cross-Site Scripting…

Fix: after 2.2.0
Fix from $1,600 2021-10-25
Timetable And Event Schedule MEDIUM 6.5
CVE-2021-24585

The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive da…

Fix: 2.4.0+
Fix from $1,600 2021-09-20
Timetable And Event Schedule MEDIUM 5.4
CVE-2021-24584

The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with t…

Fix: 2.4.2+
Fix from $1,600 2021-09-20
Timetable And Event Schedule MEDIUM 5.4
CVE-2021-24724

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privileg…

Fix: 2.3.19+
Fix from $1,600 2021-09-13