Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chat For Telegram MEDIUM 5.4
CVE-2025-5236

The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to,…

Fix: 1.2+
Fix from $1,600 2025-05-30
Filebird HIGH 7.2
CVE-2025-26977

Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Contro…

Fix: 6.4.6+
Fix from $1,950 2025-02-25
Gdpr Ccpa Compliance \& Cookie Consent Banner HIGH 8.8
CVE-2025-24591

Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access …

Fix: 2.7.2+
Fix from $1,950 2025-01-24
Filebird MEDIUM 6.5
CVE-2023-25966

Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…

Fix: 5.1.5+
Fix from $1,600 2024-12-09
Filebird HIGH 7.2
CVE-2024-53825

Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Fix: after 6.3.2
Fix from $1,950 2024-12-06
Filester HIGH 8.8
CVE-2024-8066

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function …

Fix: 1.8.7+
Fix from $1,950 2024-11-28
Filester HIGH 7.2
CVE-2024-9669

The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via…

Fix: 1.8.6+
Fix from $1,950 2024-11-28
Click To Chat MEDIUM 5.4
CVE-2024-10055

The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsaio_s…

Fix: 2.3.4+
Fix from $1,600 2024-10-18
Click To Chat MEDIUM 5.4
CVE-2024-49281

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ninja Team Click to Chat – WP Support All…

Fix: 2.3.4+
Fix from $1,600 2024-10-17
Multi Step For Contact Form 7 CRITICAL 9.8
CVE-2024-47331

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ninja Team Multi Step for Contact Form cf7-mult…

Fix: 2.7.8+
Fix from $2,300 2024-10-11
Filester HIGH 8.8
CVE-2024-7031

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt…

Fix: 1.8.3+
Fix from $1,950 2024-08-03
Gdpr Ccpa Compliance \& Cookie Consent Banner MEDIUM 5.4
CVE-2024-5607

The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Fix: 2.7.1+
Fix from $1,600 2024-06-07
Filebird HIGH 7.5
CVE-2024-35166

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3.

Fix: 5.6.4+
Fix from $1,950 2024-05-14
Filebird MEDIUM 5.4
CVE-2024-2345

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the folder name p…

Fix: 5.6.4+
Fix from $1,600 2024-05-02
Filebird MEDIUM 5.4
CVE-2024-2346

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Fix: 5.6.4+
Fix from $1,600 2024-05-02
Wp Chat App MEDIUM 5.4
CVE-2024-2837

The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin…

Fix: 3.6.4+
Fix from $1,600 2024-04-26
Wp Chat App MEDIUM 5.4
CVE-2024-2513

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in all versions up to, and inclu…

Fix: 3.6.3+
Fix from $1,600 2024-04-09
Wp Chat App MEDIUM 5.4
CVE-2024-1761

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including,…

Fix: after 3.6.1
Fix from $1,600 2024-03-07
Fastdup MEDIUM 5.3
CVE-2023-6592

The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.

Fix: 2.2+
Fix from $1,600 2024-01-16
Fastdup HIGH 7.5
CVE-2023-51406

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue …

Fix: after 2.1.7
Fix from $1,950 2024-01-08
Live Chat With Facebook Messenger MEDIUM 5.4
CVE-2023-5740

The Live Chat with Facebook Messenger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'messenger' shortcode in all…

Fix: after 1.0
Fix from $1,600 2023-10-25
Filester HIGH 7.2
CVE-2023-4861

The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be…

Fix: 1.8.1+
Fix from $1,950 2023-10-16
Filester HIGH 8.8
CVE-2023-4827EPSS 7%

The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to m…

Fix: 1.8+
Fix from $1,950 2023-10-16
Gpdr Ccpa Compliance Support CRITICAL 9.8
CVE-2020-36718

The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization…

Fix: after 2.3
Fix from $2,300 2023-06-07
Filebird CRITICAL 9.8
CVE-2021-24385

The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post requ…

No fix yet
Fix from $2,300 2021-07-12
Video Downloader For Tiktok CRITICAL 9.8
CVE-2020-24142

Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted request…

Mitigation only
Fix from $2,300 2021-07-07
Video Downloader For Tiktok HIGH 7.5
CVE-2020-24143

Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are…

Mitigation only
Fix from $1,950 2021-07-07