Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Modula Image Gallery MEDIUM 6.6
CVE-2025-13646

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' fu…

Fix: 2.13.3+
Fix from $1,600 2025-12-03
Modula Image Gallery HIGH 7.2
CVE-2025-13645

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_fi…

Fix: 2.13.3+
Fix from $1,950 2025-12-03
Modula Image Gallery MEDIUM 5.4
CVE-2024-9416

The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (vers…

Fix: 2.10.2+
Fix from $1,600 2025-04-03
Modula Image Gallery HIGH 8.8
CVE-2024-12853

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functiona…

Fix: 2.11.11+
Fix from $1,950 2025-01-08
Passster HIGH 7.5
CVE-2024-11282

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc…

Fix: 4.2.11+
Fix from $1,950 2025-01-07
Htaccess File Editor HIGH 8.8
CVE-2024-49256

Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionality Not Properly Constrained b…

Fix: 1.0.19+
Fix from $1,950 2024-11-01
Strong Testimonials HIGH 8.8
CVE-2024-47362

Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testimonials: from n/a through <= 3…

Fix: 3.1.17+
Fix from $1,950 2024-11-01
Download Monitor HIGH 7.5
CVE-2022-4972

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related …

Fix: after 4.7.51
Fix from $1,950 2024-10-16
Optimize Images Alt Text \(alt Tag\) \& Names For Seo Using Ai MEDIUM 5.3
CVE-2024-6571

The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and…

Fix: 3.1.2+
Fix from $1,600 2024-07-24
Image Photo Gallery Final Tiles Grid MEDIUM 6.8
CVE-2024-3710

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputtin…

Fix: 3.6.0+
Fix from $1,600 2024-07-13
Passster MEDIUM 5.4
CVE-2024-2026

The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, an…

Fix: 4.2.6.5+
Fix from $1,600 2024-04-09
Download Monitor HIGH 7.2
CVE-2024-30501

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Dow…

Fix: 4.9.5+
Fix from $1,950 2024-03-29
Simple Restrict MEDIUM 5.3
CVE-2024-1083

The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.6 via the REST API…

Fix: 1.2.7+
Fix from $1,600 2024-03-13
Passster MEDIUM 5.3
CVE-2024-0616

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc…

Fix: 4.2.6.3+
Fix from $1,600 2024-02-29
Download Monitor HIGH 7.5
CVE-2022-45354EPSS 38%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a th…

Fix: after 4.7.60
Fix from $1,950 2024-01-08
Strong Testimonials HIGH 8.8
CVE-2023-52123

Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10.

Fix: after 3.1.10
Fix from $1,950 2024-01-05
Download Monitor HIGH 8.8
CVE-2023-34007

Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.

Fix: after 4.8.3
Fix from $1,950 2023-12-20
Cpo Shortcodes MEDIUM 5.4
CVE-2023-5704

The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including…

Fix: after 1.5.0
Fix from $1,600 2023-11-22
Brilliance MEDIUM 5.4
CVE-2023-28171

Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions.

Fix: after 1.3.1
Fix from $1,600 2023-06-22
Strong Testimonials MEDIUM 5.4
CVE-2023-26013

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 versions.

Fix: after 3.0.2
Fix from $1,600 2023-06-16
Mashshare MEDIUM 5.4
CVE-2022-4544

The MashShare WordPress plugin before 3.8.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, wh…

Fix: 3.8.7+
Fix from $1,600 2023-01-16
Customizable Wordpress Gallery Plugin Modula Image Gallery MEDIUM 5.3
CVE-2022-41135

Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.

Fix: 2.6.91+
Fix from $1,600 2022-11-18
Gallery Photoblocks MEDIUM 5.4
CVE-2022-37407

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.

Fix: after 1.2.6
Fix from $1,600 2022-09-09
Gallery Photoblocks HIGH 8.8
CVE-2022-36292

Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.

Fix: after 1.2.6
Fix from $1,950 2022-08-23
Check \& Log Email MEDIUM 6.1
CVE-2022-1547

The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back in an attribute in an admin pa…

Fix: 1.0.6+
Fix from $1,600 2022-05-23
Rsvp And Event Management MEDIUM 5.3
CVE-2022-1054

The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the exp…

Fix: 2.7.8+
Fix from $1,600 2022-04-18
Kb Support MEDIUM 6.1
CVE-2022-27852

Multiple Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilities in KB Support (WordPress plugin) <= 1.5.5 versions.

Fix: after 1.5.5
Fix from $1,600 2022-04-15
Remove Footer Credit MEDIUM 5.4
CVE-2021-24446

The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make…

Fix: 1.0.6+
Fix from $1,600 2022-02-14
Download Monitor MEDIUM 6.8
CVE-2021-31567

Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows a…

Fix: after 4.4.6
Fix from $1,600 2022-01-28
Download Monitor MEDIUM 5.4
CVE-2021-36920

Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).

Fix: after 4.4.6
Fix from $1,600 2022-01-14