Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Website Contact Form With File Upload CRITICAL 9.8
CVE-2015-10137

The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'up…

Fix: after 1.3.4
Fix from $2,300 2025-07-22
Memberhero CRITICAL 9.8
CVE-2025-4334

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to ins…

Fix: after 6.3
Fix from $2,300 2025-06-26
Easy Quiz Maker MEDIUM 5.4
CVE-2024-13456

The Easy Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wqt-question' shortcode in all versions up to…

Fix: after 2.0
Fix from $1,600 2025-02-12
Memberhero CRITICAL 9.8
CVE-2024-49604

Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypa…

Fix: after 5.5
Fix from $2,300 2024-10-20
Frontend File Manager CRITICAL 9.8
CVE-2016-15042EPSS 6%

The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploa…

Fix: 1.1 / 4.0+
Fix from $2,300 2024-10-16
Frontend File Manager HIGH 7.5
CVE-2024-25903

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects Frontend File Manager: f…

Fix: 22.8+
Fix from $1,950 2024-03-17
Frontend File Manager Plugin MEDIUM 6.5
CVE-2023-5105

The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and d…

Fix: 22.6+
Fix from $1,600 2023-12-04
Frontend File Manager Plugin CRITICAL 9.8
CVE-2021-4356

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. Thi…

Fix: after 18.2
Fix from $2,300 2023-06-07
Frontend File Manager Plugin HIGH 8.8
CVE-2021-4368

The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to …

Fix: after 18.2
Fix from $1,950 2023-06-07
Frontend File Manager Plugin MEDIUM 6.1
CVE-2021-4365

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. T…

Fix: after 18.2
Fix from $1,600 2023-06-07
Frontend File Manager Plugin MEDIUM 5.3
CVE-2021-4359

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This …

Fix: after 18.2
Fix from $1,600 2023-06-07
Frontend File Manager Plugin MEDIUM 5.3
CVE-2021-4369

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due…

Fix: after 18.2
Fix from $1,600 2023-06-07
Frontend File Manager Plugin MEDIUM 5.4
CVE-2021-4344

The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking m…

Fix: after 18.2
Fix from $1,600 2023-06-07
Frontend File Manager Plugin MEDIUM 5.3
CVE-2021-4350

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to…

Fix: after 18.2
Fix from $1,600 2023-06-07
Frontend File Manager Plugin MEDIUM 5.3
CVE-2021-4351

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due …

Fix: after 18.2
Fix from $1,600 2023-06-07
Woocommerce Checkout Field Manager CRITICAL 9.8
CVE-2022-4328

The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attacke…

Fix: 18.0+
Fix from $2,300 2023-03-06
Frontend File Manager HIGH 8.8
CVE-2022-3125

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary ex…

Fix: 21.3+
Fix from $1,950 2022-10-03
Frontend File Manager MEDIUM 5.3
CVE-2022-3124EPSS 7%

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due t…

Fix: 21.3+
Fix from $1,600 2022-10-03
Ppom For Woocommerce MEDIUM 5.4
CVE-2021-25018

The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allo…

Fix: 24.0+
Fix from $1,600 2022-02-14
Ppom For Woocommerce MEDIUM 5.4
CVE-2019-14948

The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.

Fix: 18.4+
Fix from $1,600 2019-08-12
Personalized Woocommerce Cart Page HIGH 8.8
CVE-2019-5979

Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentic…

Fix: after 2.4
Fix from $1,950 2019-07-05
N Media File Uploader MEDIUM 6.5
CVE-2014-5324

Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbi…

Fix: after 3.3
Fix from $1,600 2014-09-26