Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-22659 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fox by ThemeIsle themeisle-comp… Orbit Fox after 2.10.44 Fix from $1,6002025-03-27 HIGH 8.1 CVE-2024-10705 The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.… Multiple Page Generator 4.0.6+ Fix from $1,9502025-01-26 MEDIUM 5.4 CVE-2024-13183 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and… Orbit Fox 2.10.44+ Fix from $1,6002025-01-10 MEDIUM 5.4 CVE-2025-0311 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up… Orbit Fox 2.10.44+ Fix from $1,6002025-01-10 HIGH 7.5 CVE-2024-11219 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up … Otter Blocks 3.0.7+ Fix from $1,9502024-11-27 HIGH 8.8 CVE-2024-47325 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle MPG multiple-pages-generator-by-porth… Multiple Page Generator 3.4.8+ Fix from $1,9502024-10-20 MEDIUM 5.4 CVE-2024-7778 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and includin… Orbit Fox 2.10.37+ Fix from $1,6002024-08-22 MEDIUM 5.4 CVE-2024-2484 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post Type Grid widgets in all versi… Orbit Fox 2.10.35+ Fix from $1,6002024-06-22 MEDIUM 5.3 CVE-2024-35728 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce al… Product Addons \& Fields For Woocommerce 32.0.21+ Fix from $1,6002024-06-10 MEDIUM 5.3 CVE-2024-35682 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a … Otter Blocks 2.6.12+ Fix from $1,6002024-06-08 HIGH 8.8 CVE-2024-35736 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer.This issue affects Visuali… Visualizer 3.11.2+ Fix from $1,9502024-06-08 MEDIUM 5.4 CVE-2024-3725 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… Otter Blocks 2.6.10+ Fix from $1,6002024-05-02 CRITICAL 9.8 CVE-2024-3962 The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the p… Product Addons \& Fields For Woocommerce 32.0.19+ Fix from $2,3002024-04-26 MEDIUM 6.1 CVE-2024-2729 The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered… Otter Blocks 2.6.6+ Fix from $1,6002024-04-18 MEDIUM 6.4 CVE-2023-6805 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-S… Rss Aggregator By Feedzy 4.4.8+ Fix from $1,6002024-04-17 HIGH 8.8 CVE-2024-31301 Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin –… Multiple Page Generator 3.4.1+ Fix from $1,9502024-04-12 MEDIUM 5.4 CVE-2024-3343 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… Otter Blocks 2.6.9+ Fix from $1,6002024-04-11 MEDIUM 5.4 CVE-2024-3344 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV… Otter Blocks 2.6.9+ Fix from $1,6002024-04-11 MEDIUM 5.4 CVE-2024-2226 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… Otter Blocks 2.6.5+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2023-6877 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-S… Rss Aggregator By Feedzy 4.3.4+ Fix from $1,6002024-04-07 HIGH 7.2 CVE-2024-27951 Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Se… Multiple Page Generator 3.4.1+ Fix from $1,9502024-04-03 MEDIUM 5.4 CVE-2024-2841 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… Otter Blocks 2.6.6+ Fix from $1,6002024-03-29 HIGH 8.8 CVE-2024-30235 Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n… Multiple Page Generator 3.4.1+ Fix from $1,9502024-03-26 MEDIUM 6.1 CVE-2024-27958 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Reflected XSS.This … Visualizer 3.10.6+ Fix from $1,6002024-03-17 MEDIUM 5.4 CVE-2024-2126 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Registration Form widget in all versions up to, … Orbit Fox 2.10.33+ Fix from $1,6002024-03-13 MEDIUM 6.1 CVE-2024-1691 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… Otter Blocks 2.6.4+ Fix from $1,6002024-03-13 MEDIUM 5.4 CVE-2024-1684 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… Otter Blocks 2.6.4+ Fix from $1,6002024-03-13 MEDIUM 5.4 CVE-2024-1497 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form widget addr2_width attribute in all version… Orbit Fox 2.10.31+ Fix from $1,6002024-03-13 MEDIUM 5.4 CVE-2024-1499 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in the $settings['title_ta… Orbit Fox 2.10.31+ Fix from $1,6002024-03-13 HIGH 8.8 CVE-2024-1317 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection … Rss Aggregator By Feedzy after 4.4.2 Fix from $1,9502024-02-29