Vulnerability index

Browse CVEs

63 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-0275 The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode attributes before outputting th… Easy Accept Payments For Paypal 4.9.10+ Fix from $1,6002023-02-13 MEDIUM 5.4 CVE-2022-4542 The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes before outputting them back i… Compact Wp Audio Player 1.9.8+ Fix from $1,6002023-01-23 MEDIUM 5.4 CVE-2022-4672 The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them… Wordpress Simple Paypal Shopping Cart 4.6.2+ Fix from $1,6002023-01-23 MEDIUM 5.4 CVE-2022-4465 The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the … Wp Video Lightbox 1.9.7+ Fix from $1,6002023-01-16 MEDIUM 6.5 CVE-2022-3898 The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to mi… Wp Affiliate Platform after 6.3.9 Fix from $1,6002022-11-29 MEDIUM 6.1 CVE-2022-3896 The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and inc… Wp Affiliate Platform after 6.3.9 Fix from $1,6002022-11-29 HIGH 8.8 CVE-2022-44737 Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress. All In One Wp Security \& Firewall after 5.1.0 Fix from $1,9502022-11-22 MEDIUM 6.1 CVE-2022-2189 The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, … Wp Video Lightbox 1.9.5+ Fix from $1,6002022-07-25 MEDIUM 6.5 CVE-2021-24692 The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such… Simple Download Monitor 3.9.5+ Fix from $1,6002022-03-14 HIGH 8.8 CVE-2021-24696 The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) ma… Simple Download Monitor 3.9.9+ Fix from $1,9502022-01-24 MEDIUM 5.4 CVE-2021-24694 The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting… Simple Download Monitor 3.9.11+ Fix from $1,6002022-01-24 CRITICAL 9.0 CVE-2021-24693 The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which co… Simple Download Monitor 3.9.5+ Fix from $2,3002021-11-08 HIGH 7.5 CVE-2021-24695 The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation… Simple Download Monitor 3.9.5+ Fix from $1,9502021-11-08 MEDIUM 6.1 CVE-2021-24697 The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_e… Simple Download Monitor 3.9.5+ Fix from $1,6002021-11-08 MEDIUM 6.5 CVE-2021-24735 The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin chan… Compact Wp Audio Player 1.9.7+ Fix from $1,6002021-10-18 MEDIUM 5.4 CVE-2021-24734 The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as l… Compact Wp Audio Player 1.9.7+ Fix from $1,6002021-10-18 HIGH 8.8 CVE-2021-24711 The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable … Software License Manager 4.5.1+ Fix from $1,9502021-10-11 MEDIUM 6.1 CVE-2021-24560 The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the pag… Software License Manager 4.4.8+ Fix from $1,6002021-09-13 MEDIUM 5.4 CVE-2021-24665 The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributo… Wp Video Lightbox 1.9.3+ Fix from $1,6002021-08-30 HIGH 8.8 CVE-2021-20782 Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authenticat… Software License Manager 4.4.6+ Fix from $1,9502021-07-14 MEDIUM 6.1 CVE-2020-29171 Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-… Wp Security \& Firewall 4.4.6+ Fix from $1,6002021-02-10 HIGH 8.8 CVE-2020-5651 SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially cr… Simple Download Monitor after 3.8.8 Fix from $1,9502020-10-21 MEDIUM 6.1 CVE-2020-5650 Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified… Simple Download Monitor after 3.8.8 Fix from $1,6002020-10-21 HIGH 8.8 CVE-2019-5993 Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack… Category Specific Rss Feed Subscription after 2.0 Fix from $1,9502019-09-12 CRITICAL 9.8 CVE-2016-10888 The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues. All In One Wp Security \& Firewall 4.0.7+ Fix from $2,3002019-08-14 CRITICAL 9.8 CVE-2015-9310 The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues. All In One Wp Security \& Firewall 3.9.1+ Fix from $2,3002019-08-14 CRITICAL 9.8 CVE-2016-10887 The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues. All In One Wp Security \& Firewall 4.0.9+ Fix from $2,3002019-08-14 MEDIUM 6.1 CVE-2016-10866 The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues. All In One Wp Security \& Firewall 4.2.0+ Fix from $1,6002019-08-13 MEDIUM 6.1 CVE-2016-10867 The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages. All In One Wp Security \& Firewall 4.0.6+ Fix from $1,6002019-08-13 MEDIUM 6.1 CVE-2016-10868 The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings p… All In One Wp Security \& Firewall 4.0.5+ Fix from $1,6002019-08-13