Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Essential Blocks CRITICAL 9.8
CVE-2023-6623EPSS 51%

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templat…

Fix: 4.4.3+
Fix from $2,300 2024-01-15
Essential Blocks MEDIUM 5.4
CVE-2023-7071

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Fix: after 4.4.6
Fix from $1,600 2024-01-11
Essential Addons For Elementor MEDIUM 5.4
CVE-2023-7044

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cros…

Fix: after 5.9.2
Fix from $1,600 2024-01-04
Embedpress MEDIUM 5.4
CVE-2023-6986

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is…

Fix: 3.9.6+
Fix from $1,600 2024-01-03
Parallax Slider Block MEDIUM 5.4
CVE-2023-49184

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Parallax Slider Block allows Stored…

Fix: after 1.2.4
Fix from $1,600 2023-12-15
Embedpress MEDIUM 6.1
CVE-2023-5749

The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cr…

Fix: 3.9.2+
Fix from $1,600 2023-12-11
Embedpress MEDIUM 6.1
CVE-2023-5750

The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific con…

Fix: 3.9.2+
Fix from $1,600 2023-12-11
Essential Addons For Elementor HIGH 8.8
CVE-2023-32245

Cross-Site Request Forgery (CSRF) vulnerability in WPDeveloper Essential Addons for Elementor Pro.This issue affects Essential Addons for Elementor P…

Fix: after 5.4.8
Fix from $1,950 2023-11-18
Reviewx CRITICAL 9.8
CVE-2022-46809

Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This…

Fix: after 1.6.7
Fix from $2,300 2023-11-07
Essential Blocks HIGH 8.1
CVE-2023-4386

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrus…

Fix: after 4.2.0
Fix from $1,950 2023-10-20
Essential Blocks CRITICAL 9.8
CVE-2023-4402

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrus…

Fix: 1.1.1 / 4.2.1+
Fix from $2,300 2023-10-20
Essential Addons For Elementor MEDIUM 6.1
CVE-2023-32241

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPDeveloper Essential Addons for Elementor Pro plugin <= 5.4.8 versions.

Fix: after 5.4.8
Fix from $1,600 2023-08-29
Embedpress MEDIUM 5.4
CVE-2023-4283

The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and inclu…

Fix: after 3.8.2
Fix from $1,600 2023-08-10
Essential Addons For Elementor MEDIUM 5.3
CVE-2023-3779

The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 d…

Fix: after 5.8.1
Fix from $1,600 2023-07-20
Embedpress HIGH 7.5
CVE-2023-3371

The EmbedPress plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler…

Fix: after 3.7.3
Fix from $1,950 2023-06-27
Reviewx HIGH 8.8
CVE-2023-2833EPSS 17%

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on th…

Fix: after 1.6.13
Fix from $1,950 2023-06-06
Essential Addons For Elementor CRITICAL 9.8
CVE-2023-32243EPSS 76%

Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons …

Fix: 5.7.1+
Fix from $2,300 2023-05-12
Reviewx HIGH 8.8
CVE-2023-26325

The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and '…

Fix: 1.6.4+
Fix from $1,950 2023-02-23
Notificationx CRITICAL 9.8
CVE-2022-0349EPSS 34%

The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Un…

Fix: 2.3.9+
Fix from $2,300 2022-03-07
Essential Addons For Elementor MEDIUM 6.1
CVE-2022-0683

The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the s…

Fix: after 5.0.8
Fix from $1,600 2022-02-24
Essential Addons For Elementor CRITICAL 9.8
CVE-2022-0320

The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statemen…

Fix: 5.0.5+
Fix from $2,300 2022-02-01
Betterlinks MEDIUM 5.4
CVE-2021-24812

The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Script…

Fix: 1.2.6+
Fix from $1,600 2021-11-23
Simple 301 Redirects HIGH 8.8
CVE-2021-24352

The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possibl…

Fix: 2.0.4+
Fix from $1,950 2021-06-14
Simple 301 Redirects HIGH 8.8
CVE-2021-24353

The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possibl…

Fix: 2.0.4+
Fix from $1,950 2021-06-14
Simple 301 Redirects HIGH 8.8
CVE-2021-24354

A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4,…

Fix: 2.0.4+
Fix from $1,950 2021-06-14
Simple 301 Redirects HIGH 8.8
CVE-2021-24356

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action…

Fix: 2.0.4+
Fix from $1,950 2021-06-14
Essential Addons For Elementor MEDIUM 5.4
CVE-2021-24255

The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by low…

Fix: 4.5.4+
Fix from $1,600 2021-05-05
Twitter Cards Meta HIGH 8.8
CVE-2017-18504

The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.

Fix: 2.5.0+
Fix from $1,950 2019-08-12
Twitter Cards Meta MEDIUM 6.1
CVE-2017-18503

The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS.

Fix: 2.5.0+
Fix from $1,600 2019-08-12