Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Simple Social Buttons MEDIUM 5.3
CVE-2023-5845

The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthenticated visitors in some meta ta…

Fix: 5.1.1+
Fix from $1,600 2023-11-27
Login Logout Menu MEDIUM 5.4
CVE-2022-4622

The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a p…

Fix: after 1.3.3
Fix from $1,600 2023-02-21
Login Logout Menu MEDIUM 5.4
CVE-2022-4625

The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the …

Fix: 1.4.0+
Fix from $1,600 2023-01-23
Loginpress MEDIUM 5.3
CVE-2022-41839

Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking se…

Fix: after 1.6.2
Fix from $1,600 2022-11-18
Loginpress MEDIUM 6.1
CVE-2022-0347

The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in…

Fix: 1.5.12+
Fix from $1,600 2022-03-07
Simple Social Media Share Buttons MEDIUM 5.4
CVE-2021-24486

The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size param…

Fix: 3.2.3+
Fix from $1,600 2021-08-23
Loginpress CRITICAL 9.8
CVE-2019-15872

The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.

Fix: 1.1.4+
Fix from $2,300 2019-09-03