Vulnerability index

Browse CVEs

63 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-3874 The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3… Wordpress Simple Paypal Shopping Cart 5.1.4+ Fix from $1,6002025-05-01 MEDIUM 5.4 CVE-2025-3890 The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in a… Wordpress Simple Paypal Shopping Cart 5.1.4+ Fix from $1,6002025-05-01 MEDIUM 5.3 CVE-2025-3889 The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3… Wordpress Simple Paypal Shopping Cart 5.1.4+ Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2024-6133 The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leadin… Wp Estore 8.5.6+ Fix from $1,6002024-08-12 MEDIUM 5.4 CVE-2024-6134 The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leadin… Wp Estore 8.5.6+ Fix from $1,6002024-08-12 MEDIUM 5.4 CVE-2024-6136 The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged i… Wp Estore 8.5.6+ Fix from $1,6002024-08-12 MEDIUM 6.1 CVE-2024-5081 The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could … Wp Emember 10.7.0+ Fix from $1,6002024-08-05 MEDIUM 5.5 CVE-2024-5285 The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to ma… Wp Affiliate Platform 6.5.2+ Fix from $1,6002024-07-29 HIGH 8.8 CVE-2024-6075 The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged i… Wp Estore 8.5.5+ Fix from $1,9502024-07-15 MEDIUM 6.1 CVE-2024-6072 The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an … Wp Estore 8.5.5+ Fix from $1,6002024-07-15 MEDIUM 6.1 CVE-2024-6073 The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leadin… Wp Estore 8.5.5+ Fix from $1,6002024-07-15 MEDIUM 6.1 CVE-2024-6074 The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leadin… Wp Estore 8.5.5+ Fix from $1,6002024-07-15 MEDIUM 6.1 CVE-2024-6076 The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leadin… Wp Estore 8.5.5+ Fix from $1,6002024-07-15 HIGH 7.1 CVE-2024-5715 The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected … Wp Emember 10.6.7+ Fix from $1,9502024-07-13 MEDIUM 6.8 CVE-2024-5744 The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which … Wp Emember 10.6.7+ Fix from $1,6002024-07-13 HIGH 8.8 CVE-2024-5080 The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP … Wp Emember 10.6.6+ Fix from $1,9502024-07-13 HIGH 7.1 CVE-2024-5287 The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to … Wp Affiliate Platform 6.5.1+ Fix from $1,9502024-07-13 MEDIUM 6.8 CVE-2024-5077 The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could a… Wp Emember 10.6.6+ Fix from $1,6002024-07-13 MEDIUM 6.8 CVE-2024-5284 The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi… Wp Affiliate Platform 6.5.1+ Fix from $1,6002024-07-13 MEDIUM 6.1 CVE-2024-5079 The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated use… Wp Emember 10.6.7+ Fix from $1,6002024-07-13 MEDIUM 6.1 CVE-2024-5281 The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a … Wp Affiliate Platform 6.5.1+ Fix from $1,6002024-07-13 MEDIUM 6.1 CVE-2024-5282 The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a … Wp Affiliate Platform 6.5.1+ Fix from $1,6002024-07-13 MEDIUM 6.1 CVE-2024-5283 The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a … Wp Affiliate Platform 6.5.1+ Fix from $1,6002024-07-13 HIGH 8.8 CVE-2024-5076 The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform u… Wp Emember 10.6.6+ Fix from $1,9502024-07-13 MEDIUM 5.9 CVE-2024-5075 The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected … Wp Emember 10.6.6+ Fix from $1,6002024-07-13 MEDIUM 5.4 CVE-2024-5074 The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected … Wp Emember 10.6.6+ Fix from $1,6002024-07-13 HIGH 8.3 CVE-2024-4749 The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to … Wp Emember 10.3.9+ Fix from $1,9502024-06-04 CRITICAL 9.8 CVE-2022-47588 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Peter Petreski Simple Photo… Simple Photo Gallery after 1.8.1 Fix from $2,3002023-11-03 HIGH 8.8 CVE-2023-22691 Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions. Category Specific Rss Feed Subscription 2.2+ Fix from $1,9502023-05-03 MEDIUM 5.3 CVE-2023-1431 The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the p… Wordpress Simple Paypal Shopping Cart after 4.6.3 Fix from $1,6002023-03-16