Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-1318 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized m… Rss Aggregator By Feedzy after 4.4.2 Fix from $1,6002024-02-29 MEDIUM 5.4 CVE-2024-1323 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type Grid Widget Title in all vers… Orbit Fox 2.10.31+ Fix from $1,6002024-02-27 MEDIUM 5.4 CVE-2024-0508 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table Elementor Widget in all v… Orbit Fox after 2.10.27 Fix from $1,6002024-02-05 MEDIUM 5.3 CVE-2024-1047 Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability c… Orbit Fox after 2.10.28 Fix from $1,6002024-02-02 MEDIUM 5.4 CVE-2023-6781 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, an… Orbit Fox after 2.10.26 Fix from $1,6002024-01-11 MEDIUM 5.4 CVE-2023-6801 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-S… Rss Aggregator By Feedzy 4.3.3+ Fix from $1,6002024-01-06 MEDIUM 5.4 CVE-2023-6798 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized s… Rss Aggregator By Feedzy 4.3.3+ Fix from $1,6002024-01-06 HIGH 7.5 CVE-2023-47529 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collection.This issue affects Cloud … Cloud Templates \& Patterns Collection 1.2.3+ Fix from $1,9502023-11-23 CRITICAL 9.8 CVE-2023-33927 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG … Multiple Page Generator after 3.3.19 Fix from $2,3002023-10-31 MEDIUM 5.4 CVE-2023-4887 The Google Maps Plugin by Intergeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shortcode in versions up to, and … Google Maps Plugin By Intergeo after 2.3.2 Fix from $1,6002023-09-12 HIGH 7.2 CVE-2023-2607 The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, an… Multiple Page Generator after 3.3.17 Fix from $1,9502023-06-09 HIGH 8.8 CVE-2023-2288EPSS 18% The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a … Otter 2.2.6+ Fix from $1,9502023-05-30 MEDIUM 6.1 CVE-2023-2256 The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cro… Product Addons \& Fields For Woocommerce 32.0.7+ Fix from $1,6002023-05-30 MEDIUM 5.4 CVE-2023-23708 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager for WordPress plugin <= 3.9.4… Visualizer 3.9.5+ Fix from $1,6002023-05-03 MEDIUM 5.4 CVE-2022-46848 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager for WordPress plugin <= 3.9.1… Visualizer 3.9.2+ Fix from $1,6002023-03-28 HIGH 8.8 CVE-2022-47143 Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG plugin <= 3.3.9 versions. Multiple Page Generator after 3.3.9 Fix from $1,9502023-03-14 MEDIUM 5.4 CVE-2022-4667 The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the … Rss Aggregator By Feedzy 4.1.1+ Fix from $1,6002023-01-30 HIGH 8.8 CVE-2022-2444 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data… Visualizer 3.7.10+ Fix from $1,9502022-07-18 MEDIUM 6.5 CVE-2022-1576 The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attack… Wp Maintenance Mode \& Coming Soon 2.4.5+ Fix from $1,6002022-07-11 MEDIUM 6.5 CVE-2021-24158 Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the … Orbit Fox 2.10.3+ Fix from $1,6002021-04-05 MEDIUM 5.4 CVE-2021-24157 Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had… Orbit Fox 2.10.3+ Fix from $1,6002021-04-05 MEDIUM 6.1 CVE-2019-16931 A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an ad… Visualizer after 3.3.0 Fix from $1,6002019-10-03 CRITICAL 10.0 CVE-2019-16932EPSS 39% A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data. Visualizer 3.3.1+ Fix from $2,3002019-09-30