Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Orbit Fox MEDIUM 5.4
CVE-2025-22659

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fox by ThemeIsle themeisle-comp…

Fix: after 2.10.44
Fix from $1,600 2025-03-27
Multiple Page Generator HIGH 8.1
CVE-2024-10705

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.…

Fix: 4.0.6+
Fix from $1,950 2025-01-26
Orbit Fox MEDIUM 5.4
CVE-2024-13183

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and…

Fix: 2.10.44+
Fix from $1,600 2025-01-10
Orbit Fox MEDIUM 5.4
CVE-2025-0311

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up…

Fix: 2.10.44+
Fix from $1,600 2025-01-10
Otter Blocks HIGH 7.5
CVE-2024-11219

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up …

Fix: 3.0.7+
Fix from $1,950 2024-11-27
Multiple Page Generator HIGH 8.8
CVE-2024-47325

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle MPG multiple-pages-generator-by-porth…

Fix: 3.4.8+
Fix from $1,950 2024-10-20
Orbit Fox MEDIUM 5.4
CVE-2024-7778

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and includin…

Fix: 2.10.37+
Fix from $1,600 2024-08-22
Orbit Fox MEDIUM 5.4
CVE-2024-2484

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post Type Grid widgets in all versi…

Fix: 2.10.35+
Fix from $1,600 2024-06-22
Product Addons \& Fields For Woocommerce MEDIUM 5.3
CVE-2024-35728

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce al…

Fix: 32.0.21+
Fix from $1,600 2024-06-10
Otter Blocks MEDIUM 5.3
CVE-2024-35682

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a …

Fix: 2.6.12+
Fix from $1,600 2024-06-08
Visualizer HIGH 8.8
CVE-2024-35736

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer.This issue affects Visuali…

Fix: 3.11.2+
Fix from $1,950 2024-06-08
Otter Blocks MEDIUM 5.4
CVE-2024-3725

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th…

Fix: 2.6.10+
Fix from $1,600 2024-05-02
Product Addons \& Fields For Woocommerce CRITICAL 9.8
CVE-2024-3962

The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the p…

Fix: 32.0.19+
Fix from $2,300 2024-04-26
Otter Blocks MEDIUM 6.1
CVE-2024-2729

The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered…

Fix: 2.6.6+
Fix from $1,600 2024-04-18
Rss Aggregator By Feedzy MEDIUM 6.4
CVE-2023-6805

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-S…

Fix: 4.4.8+
Fix from $1,600 2024-04-17
Multiple Page Generator HIGH 8.8
CVE-2024-31301

Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin –…

Fix: 3.4.1+
Fix from $1,950 2024-04-12
Otter Blocks MEDIUM 5.4
CVE-2024-3343

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th…

Fix: 2.6.9+
Fix from $1,600 2024-04-11
Otter Blocks MEDIUM 5.4
CVE-2024-3344

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV…

Fix: 2.6.9+
Fix from $1,600 2024-04-11
Otter Blocks MEDIUM 5.4
CVE-2024-2226

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th…

Fix: 2.6.5+
Fix from $1,600 2024-04-09
Rss Aggregator By Feedzy MEDIUM 5.4
CVE-2023-6877

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-S…

Fix: 4.3.4+
Fix from $1,600 2024-04-07
Multiple Page Generator HIGH 7.2
CVE-2024-27951

Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Se…

Fix: 3.4.1+
Fix from $1,950 2024-04-03
Otter Blocks MEDIUM 5.4
CVE-2024-2841

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th…

Fix: 2.6.6+
Fix from $1,600 2024-03-29
Multiple Page Generator HIGH 8.8
CVE-2024-30235

Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n…

Fix: 3.4.1+
Fix from $1,950 2024-03-26
Visualizer MEDIUM 6.1
CVE-2024-27958

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Reflected XSS.This …

Fix: 3.10.6+
Fix from $1,600 2024-03-17
Orbit Fox MEDIUM 5.4
CVE-2024-2126

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Registration Form widget in all versions up to, …

Fix: 2.10.33+
Fix from $1,600 2024-03-13
Otter Blocks MEDIUM 6.1
CVE-2024-1691

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi…

Fix: 2.6.4+
Fix from $1,600 2024-03-13
Otter Blocks MEDIUM 5.4
CVE-2024-1684

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th…

Fix: 2.6.4+
Fix from $1,600 2024-03-13
Orbit Fox MEDIUM 5.4
CVE-2024-1497

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form widget addr2_width attribute in all version…

Fix: 2.10.31+
Fix from $1,600 2024-03-13
Orbit Fox MEDIUM 5.4
CVE-2024-1499

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in the $settings['title_ta…

Fix: 2.10.31+
Fix from $1,600 2024-03-13
Rss Aggregator By Feedzy HIGH 8.8
CVE-2024-1317

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection …

Fix: after 4.4.2
Fix from $1,950 2024-02-29