Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.6 CVE-2025-13646 The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' fu… Modula Image Gallery 2.13.3+ Fix from $1,6002025-12-03 HIGH 7.2 CVE-2025-13645 The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_fi… Modula Image Gallery 2.13.3+ Fix from $1,9502025-12-03 MEDIUM 5.4 CVE-2024-9416 The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (vers… Modula Image Gallery 2.10.2+ Fix from $1,6002025-04-03 HIGH 8.8 CVE-2024-12853 The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functiona… Modula Image Gallery 2.11.11+ Fix from $1,9502025-01-08 HIGH 7.5 CVE-2024-11282 The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… Passster 4.2.11+ Fix from $1,9502025-01-07 HIGH 8.8 CVE-2024-49256 Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionality Not Properly Constrained b… Htaccess File Editor 1.0.19+ Fix from $1,9502024-11-01 HIGH 8.8 CVE-2024-47362 Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testimonials: from n/a through <= 3… Strong Testimonials 3.1.17+ Fix from $1,9502024-11-01 HIGH 7.5 CVE-2022-4972 The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related … Download Monitor after 4.7.51 Fix from $1,9502024-10-16 MEDIUM 5.3 CVE-2024-6571 The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and… Optimize Images Alt Text \(alt Tag\) \& Names For Seo Using Ai 3.1.2+ Fix from $1,6002024-07-24 MEDIUM 6.8 CVE-2024-3710 The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputtin… Image Photo Gallery Final Tiles Grid 3.6.0+ Fix from $1,6002024-07-13 MEDIUM 5.4 CVE-2024-2026 The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, an… Passster 4.2.6.5+ Fix from $1,6002024-04-09 HIGH 7.2 CVE-2024-30501 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Dow… Download Monitor 4.9.5+ Fix from $1,9502024-03-29 MEDIUM 5.3 CVE-2024-1083 The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.6 via the REST API… Simple Restrict 1.2.7+ Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-0616 The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… Passster 4.2.6.3+ Fix from $1,6002024-02-29 HIGH 7.5 CVE-2022-45354EPSS 38% Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a th… Download Monitor after 4.7.60 Fix from $1,9502024-01-08 HIGH 8.8 CVE-2023-52123 Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10. Strong Testimonials after 3.1.10 Fix from $1,9502024-01-05 HIGH 8.8 CVE-2023-34007 Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3. Download Monitor after 4.8.3 Fix from $1,9502023-12-20 MEDIUM 5.4 CVE-2023-5704 The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including… Cpo Shortcodes after 1.5.0 Fix from $1,6002023-11-22 MEDIUM 5.4 CVE-2023-28171 Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions. Brilliance after 1.3.1 Fix from $1,6002023-06-22 MEDIUM 5.4 CVE-2023-26013 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 versions. Strong Testimonials after 3.0.2 Fix from $1,6002023-06-16 MEDIUM 5.4 CVE-2022-4544 The MashShare WordPress plugin before 3.8.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, wh… Mashshare 3.8.7+ Fix from $1,6002023-01-16 MEDIUM 5.3 CVE-2022-41135 Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress. Customizable Wordpress Gallery Plugin Modula Image Gallery 2.6.91+ Fix from $1,6002022-11-18 MEDIUM 5.4 CVE-2022-37407 Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress. Gallery Photoblocks after 1.2.6 Fix from $1,6002022-09-09 HIGH 8.8 CVE-2022-36292 Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress. Gallery Photoblocks after 1.2.6 Fix from $1,9502022-08-23 MEDIUM 6.1 CVE-2022-1547 The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back in an attribute in an admin pa… Check \& Log Email 1.0.6+ Fix from $1,6002022-05-23 MEDIUM 5.3 CVE-2022-1054 The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the exp… Rsvp And Event Management 2.7.8+ Fix from $1,6002022-04-18 MEDIUM 6.1 CVE-2022-27852 Multiple Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilities in KB Support (WordPress plugin) <= 1.5.5 versions. Kb Support after 1.5.5 Fix from $1,6002022-04-15 MEDIUM 5.4 CVE-2021-24446 The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make… Remove Footer Credit 1.0.6+ Fix from $1,6002022-02-14 MEDIUM 6.8 CVE-2021-31567 Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows a… Download Monitor after 4.4.6 Fix from $1,6002022-01-28 MEDIUM 5.4 CVE-2021-36920 Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6). Download Monitor after 4.4.6 Fix from $1,6002022-01-14