Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cost Calculator Builder MEDIUM 5.3
CVE-2025-14757

The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions up to, and including, 3.6.9 o…

Fix: 3.6.10+
Fix from $1,600 2026-01-16
Motors Car Dealer\, Classifieds \& Listing MEDIUM 5.4
CVE-2025-2808

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number param…

Fix: 1.4.64+
Fix from $1,600 2025-04-08
Motors Car Dealer\, Classifieds \& Listing HIGH 8.8
CVE-2025-2807

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capabi…

Fix: 1.4.65+
Fix from $1,950 2025-04-08
Ulisting HIGH 8.8
CVE-2025-1653

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2…

Fix: after 2.1.7
Fix from $1,950 2025-03-15
Ulisting HIGH 8.8
CVE-2025-1657

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection d…

Fix: after 2.1.7
Fix from $1,950 2025-03-15
Motors Car Dealer\, Classifieds \& Listing MEDIUM 5.4
CVE-2024-10970

The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc…

Fix: 1.4.44+
Fix from $1,600 2025-01-16
Masterstudy Lms HIGH 8.8
CVE-2024-37093

Cross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cross Site Request Forg…

Fix: 3.2.2+
Fix from $1,950 2025-01-02
Cost Calculator Builder MEDIUM 5.4
CVE-2024-10892

The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged…

Fix: 3.2.43+
Fix from $1,600 2024-12-18
Masterstudy Lms CRITICAL 9.8
CVE-2024-37094

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This …

Fix: 3.2.13+
Fix from $2,300 2024-11-01
Cost Calculator Builder HIGH 7.2
CVE-2024-8379

The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, lead…

Fix: 3.2.29+
Fix from $1,950 2024-09-30
Cost Calculator Builder MEDIUM 5.3
CVE-2024-6010

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.2.1. This is due to …

Fix: after 3.1.96
Fix from $1,600 2024-09-07
Cost Calculator Builder CRITICAL 9.8
CVE-2024-43144

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows S…

Fix: 3.2.16+
Fix from $2,300 2024-08-29
Masterstudy Lms HIGH 8.8
CVE-2024-5973

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used…

Fix: 3.3.24+
Fix from $1,950 2024-07-22
Consulting Elementor Widgets HIGH 8.8
CVE-2024-37090

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Masterstudy Elementor Widgets, S…

Fix: after 1.3.0
Fix from $1,950 2024-07-09
Motors Car Dealer\, Classifieds \& Listing MEDIUM 5.3
CVE-2024-5545

The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch…

Fix: 1.4.11+
Fix from $1,600 2024-07-02
Consulting Elementor Widgets HIGH 8.8
CVE-2024-37092

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PH…

Fix: 1.3.1+
Fix from $1,950 2024-06-24
Consulting Elementor Widgets HIGH 8.8
CVE-2024-37091

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, Sty…

Fix: 1.3.1+
Fix from $1,950 2024-06-24
Consulting Elementor Widgets CRITICAL 9.8
CVE-2024-37089

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PH…

Fix: 1.3.1+
Fix from $2,300 2024-06-24
Mega Menu CRITICAL 9.8
CVE-2024-35677

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu allows PHP Local File Inclusi…

Fix: 2.3.13+
Fix from $2,300 2024-06-10
Masterstudy Lms MEDIUM 5.4
CVE-2024-3942

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and …

Fix: 3.3.9+
Fix from $1,600 2024-05-02
Masterstudy Lms CRITICAL 9.8
CVE-2024-3136EPSS 5%

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' paramet…

Fix: 3.3.4+
Fix from $2,300 2024-04-09
Masterstudy Lms CRITICAL 9.8
CVE-2024-2409

The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficie…

Fix: 3.3.2+
Fix from $2,300 2024-03-29
Masterstudy Lms CRITICAL 9.8
CVE-2024-2411

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter.…

Fix: 3.3.1+
Fix from $2,300 2024-03-29
Masterstudy Lms HIGH 7.5
CVE-2024-2106

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to,…

Fix: 3.2.11+
Fix from $1,950 2024-03-13
Masterstudy Lms CRITICAL 9.8
CVE-2024-1512EPSS 78%

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user…

Fix: after 3.2.5
Fix from $2,300 2024-02-17
Bookit HIGH 7.2
CVE-2023-50852

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Booking Calendar | Appointment B…

Fix: 2.4.4+
Fix from $1,950 2023-12-28
Motors Car Dealer\, Classifieds \& Listing HIGH 7.5
CVE-2023-46207

Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer,…

Fix: after 1.4.6
Fix from $1,950 2023-11-13
Motors Car Dealer\, Classifieds \& Listing MEDIUM 6.1
CVE-2023-46208

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.

Fix: after 1.4.6
Fix from $1,600 2023-10-27
Masterstudy Lms HIGH 7.5
CVE-2023-4278

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to regis…

Fix: 3.0.18+
Fix from $1,950 2023-09-11
Bookit CRITICAL 9.8
CVE-2023-2834

The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verificat…

Fix: after 2.3.7
Fix from $2,300 2023-06-30