Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Masterstudy Lms MEDIUM 6.5
CVE-2023-35093

Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions al…

Fix: after 3.0.8
Fix from $1,600 2023-06-22
Masterstudy Lms MEDIUM 5.4
CVE-2023-35090

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Educ…

Fix: after 3.0.7
Fix from $1,600 2023-06-22
Ulisting CRITICAL 9.8
CVE-2021-4381

The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, …

Fix: 1.7+
Fix from $2,300 2023-06-07
Ulisting CRITICAL 9.8
CVE-2021-4370

The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack s…

Fix: after 1.6.6
Fix from $2,300 2023-06-07
Ulisting MEDIUM 5.3
CVE-2021-4357

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the Ulisti…

Fix: after 1.6.6
Fix from $1,600 2023-06-07
Ulisting CRITICAL 9.8
CVE-2021-4341

The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a mi…

Fix: after 1.6.6
Fix from $2,300 2023-06-07
Ulisting CRITICAL 9.8
CVE-2021-4343

The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. …

Fix: after 1.6.6
Fix from $2,300 2023-06-07
Ulisting HIGH 7.5
CVE-2021-4340

The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due t…

Fix: after 1.6.6
Fix from $1,950 2023-06-07
Ulisting HIGH 7.5
CVE-2021-4346

The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to …

Fix: after 1.6.6
Fix from $1,950 2023-06-07
Ulisting MEDIUM 5.3
CVE-2021-4339

The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file o…

Fix: after 1.6.6
Fix from $1,600 2023-06-07
Ulisting MEDIUM 5.3
CVE-2021-4345

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role…

Fix: after 1.6.6
Fix from $1,600 2023-06-07
Pearl Header Builder HIGH 8.8
CVE-2022-38356

Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes WordPress Header Builder Plugin – Pearl plugin <= 1.3.4 versions.

Fix: after 1.3.4
Fix from $1,950 2023-05-25
Motors Car Dealer\, Classifieds \& Listing HIGH 8.8
CVE-2022-38716

Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions.

Fix: after 1.4.4
Fix from $1,950 2023-05-25
Gdpr Compliance \& Cookie Consent HIGH 8.8
CVE-2022-45815

Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes GDPR Compliance & Cookie Consent plugin <= 1.2 versions.

Fix: after 1.2
Fix from $1,950 2023-05-25
Motors Car Dealer\, Classifieds \& Listing HIGH 8.8
CVE-2022-3989

The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowin…

Fix: 1.4.4+
Fix from $1,950 2022-12-12
Masterstudy Lms CRITICAL 9.8
CVE-2022-0441EPSS 85%

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated use…

Fix: 2.7.6+
Fix from $2,300 2022-03-07
Ulisting CRITICAL 9.8
CVE-2021-36879

Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user …

Fix: after 2.0.5
Fix from $2,300 2021-09-27
Ulisting CRITICAL 9.8
CVE-2021-36880

Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.

Fix: after 2.0.3
Fix from $2,300 2021-09-27
Ulisting HIGH 8.8
CVE-2021-36874

Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).

Fix: after 2.0.5
Fix from $1,950 2021-09-27
Ulisting HIGH 8.8
CVE-2021-36876

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin adminis…

Fix: after 2.0.5
Fix from $1,950 2021-09-27
Ulisting MEDIUM 6.5
CVE-2021-36877

Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.

Fix: after 2.0.5
Fix from $1,600 2021-09-27
Motors Car Dealer\, Classifieds \& Listing MEDIUM 6.1
CVE-2019-17229

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress h…

Fix: after 1.4.0
Fix from $1,600 2020-02-24
Motors Car Dealer\, Classifieds \& Listing MEDIUM 6.5
CVE-2019-17228

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress a…

Fix: after 1.4.0
Fix from $1,600 2020-02-24