Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rss Aggregator By Feedzy MEDIUM 6.5
CVE-2024-1318

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized m…

Fix: after 4.4.2
Fix from $1,600 2024-02-29
Orbit Fox MEDIUM 5.4
CVE-2024-1323

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type Grid Widget Title in all vers…

Fix: 2.10.31+
Fix from $1,600 2024-02-27
Orbit Fox MEDIUM 5.4
CVE-2024-0508

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table Elementor Widget in all v…

Fix: after 2.10.27
Fix from $1,600 2024-02-05
Orbit Fox MEDIUM 5.3
CVE-2024-1047

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability c…

Fix: after 2.10.28
Fix from $1,600 2024-02-02
Orbit Fox MEDIUM 5.4
CVE-2023-6781

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, an…

Fix: after 2.10.26
Fix from $1,600 2024-01-11
Rss Aggregator By Feedzy MEDIUM 5.4
CVE-2023-6801

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-S…

Fix: 4.3.3+
Fix from $1,600 2024-01-06
Rss Aggregator By Feedzy MEDIUM 5.4
CVE-2023-6798

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized s…

Fix: 4.3.3+
Fix from $1,600 2024-01-06
Cloud Templates \& Patterns Collection HIGH 7.5
CVE-2023-47529

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collection.This issue affects Cloud …

Fix: 1.2.3+
Fix from $1,950 2023-11-23
Multiple Page Generator CRITICAL 9.8
CVE-2023-33927

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG …

Fix: after 3.3.19
Fix from $2,300 2023-10-31
Google Maps Plugin By Intergeo MEDIUM 5.4
CVE-2023-4887

The Google Maps Plugin by Intergeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shortcode in versions up to, and …

Fix: after 2.3.2
Fix from $1,600 2023-09-12
Multiple Page Generator HIGH 7.2
CVE-2023-2607

The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, an…

Fix: after 3.3.17
Fix from $1,950 2023-06-09
Otter HIGH 8.8
CVE-2023-2288EPSS 18%

The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a …

Fix: 2.2.6+
Fix from $1,950 2023-05-30
Product Addons \& Fields For Woocommerce MEDIUM 6.1
CVE-2023-2256

The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cro…

Fix: 32.0.7+
Fix from $1,600 2023-05-30
Visualizer MEDIUM 5.4
CVE-2023-23708

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager for WordPress plugin <= 3.9.4…

Fix: 3.9.5+
Fix from $1,600 2023-05-03
Visualizer MEDIUM 5.4
CVE-2022-46848

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager for WordPress plugin <= 3.9.1…

Fix: 3.9.2+
Fix from $1,600 2023-03-28
Multiple Page Generator HIGH 8.8
CVE-2022-47143

Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG plugin <= 3.3.9 versions.

Fix: after 3.3.9
Fix from $1,950 2023-03-14
Rss Aggregator By Feedzy MEDIUM 5.4
CVE-2022-4667

The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the …

Fix: 4.1.1+
Fix from $1,600 2023-01-30
Visualizer HIGH 8.8
CVE-2022-2444

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data…

Fix: 3.7.10+
Fix from $1,950 2022-07-18
Wp Maintenance Mode \& Coming Soon MEDIUM 6.5
CVE-2022-1576

The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attack…

Fix: 2.4.5+
Fix from $1,600 2022-07-11
Orbit Fox MEDIUM 6.5
CVE-2021-24158

Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the …

Fix: 2.10.3+
Fix from $1,600 2021-04-05
Orbit Fox MEDIUM 5.4
CVE-2021-24157

Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had…

Fix: 2.10.3+
Fix from $1,600 2021-04-05
Visualizer MEDIUM 6.1
CVE-2019-16931

A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an ad…

Fix: after 3.3.0
Fix from $1,600 2019-10-03
Visualizer CRITICAL 10.0
CVE-2019-16932EPSS 39%

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

Fix: 3.3.1+
Fix from $2,300 2019-09-30