Vulnerability index

Browse CVEs

41 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Happy Addons For Elementor MEDIUM 6.1
CVE-2023-41236

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Happy addons Happy Elementor Addons Pro plugin <= 2.8.0 versions.

Fix: after 2.8.0
Fix from $1,600 2023-09-27
Wp Project Manager HIGH 8.8
CVE-2023-3636

The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restric…

Fix: 2.6.5+
Fix from $1,950 2023-08-31
Wp Erp MEDIUM 6.1
CVE-2023-34008

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in weDevs WP ERP plugin <= 1.12.3 versions.

Fix: after 1.12.3
Fix from $1,600 2023-08-30
Happy Addons For Elementor HIGH 8.8
CVE-2023-28989

Cross-Site Request Forgery (CSRF) vulnerability in weDevs Happy Addons for Elementor plugin <= 3.8.2 versions.

Fix: 3.8.3+
Fix from $1,950 2023-07-10
Wp Project Manager HIGH 8.8
CVE-2020-36745

The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missi…

Fix: after 2.4.0
Fix from $1,950 2023-07-01
Wp Erp HIGH 7.2
CVE-2023-2744

The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpo…

Fix: 1.12.4+
Fix from $1,950 2023-06-27
Wp Erp MEDIUM 6.1
CVE-2023-2743

The ERP WordPress plugin before 1.12.4 does not sanitise and escape the employee_name parameter before outputting it back in the page, leading to a R…

Fix: 1.12.4+
Fix from $1,600 2023-06-27
Wp User Frontend CRITICAL 9.8
CVE-2021-24649

The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role f…

Fix: 3.5.29+
Fix from $2,300 2022-11-21
Wp Project Manager MEDIUM 5.4
CVE-2021-36826

Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Man…

Fix: 2.4.14+
Fix from $1,600 2022-04-04
Wp User Frontend HIGH 8.8
CVE-2021-25076EPSS 17%

The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subsc…

Fix: 3.5.26+
Fix from $1,950 2022-01-24
Happy Addons For Elementor MEDIUM 5.4
CVE-2021-24292

The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets…

Fix: 1.17.0 / 2.24.0+
Fix from $1,600 2021-05-17