Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Givewp Square MEDIUM 6.5
CVE-2024-13713

The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.…

Fix: 1.3.2+
Fix from $1,600 2025-02-21
Post Smtp MEDIUM 6.1
CVE-2025-0521

The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and includi…

Fix: 3.1.0+
Fix from $1,600 2025-02-18
Wp Multi Store Locator MEDIUM 6.1
CVE-2025-24680

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-loca…

Fix: 2.5.1+
Fix from $1,600 2025-01-27
Post Smtp HIGH 8.8
CVE-2025-22800

Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Fix: 2.9.12+
Fix from $1,950 2025-01-13
Wp Multi Store Locator MEDIUM 5.4
CVE-2024-12475

The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insuf…

Fix: 2.4.6+
Fix from $1,600 2025-01-04
Post Smtp HIGH 7.2
CVE-2024-52436

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post SMTP post-smtp allows Blind SQL…

Fix: after 2.9.9
Fix from $1,950 2024-11-18
Mycred MEDIUM 5.3
CVE-2024-43214

Missing Authorization vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

Fix: after 2.7.3
Fix from $1,600 2024-08-26
License Manager For Woocommerce MEDIUM 6.5
CVE-2024-1639

The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLi…

Fix: after 3.0.7
Fix from $1,600 2024-06-21
Post Smtp CRITICAL 9.8
CVE-2023-52233

Missing Authorization vulnerability in Post SMTP Post SMTP Mailer/Email Log.This issue affects Post SMTP Mailer/Email Log: from n/a through 2.8.6.

Fix: 2.8.7+
Fix from $2,300 2024-06-11
Post Smtp HIGH 7.2
CVE-2024-5207

The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to tim…

Fix: 2.9.4+
Fix from $1,950 2024-05-30
Wholesale For Woocommerce MEDIUM 5.3
CVE-2024-31297

Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.

Fix: after 2.3.0
Fix from $1,600 2024-04-10
Wholesale For Woocommerce MEDIUM 5.3
CVE-2024-30469

Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.

Fix: 2.3.1+
Fix from $1,600 2024-03-29
Post Smtp MEDIUM 6.1
CVE-2024-29128

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Post SMTP POST SMTP allows Reflected XSS.This i…

Fix: 2.8.7+
Fix from $1,600 2024-03-19
Wc Shop Sync MEDIUM 6.1
CVE-2024-27959

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpexpertsio WC Shop Sync – Integrate Square and…

Fix: 4.3+
Fix from $1,600 2024-03-17
Post Smtp HIGH 7.2
CVE-2023-6620EPSS 14%

The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, lead…

Fix: 2.8.7+
Fix from $1,950 2024-01-15
Post Smtp CRITICAL 9.8
CVE-2023-6875EPSS 90%

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized …

Fix: after 2.8.7
Fix from $2,300 2024-01-11
Post Smtp MEDIUM 6.1
CVE-2023-6621

The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflec…

Fix: 2.8.7+
Fix from $1,600 2024-01-03
Post Smtp MEDIUM 6.1
CVE-2023-6629

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cro…

Fix: 2.8.7+
Fix from $1,600 2024-01-03
Post Smtp MEDIUM 5.4
CVE-2023-7027

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-…

Fix: 2.8.8+
Fix from $1,600 2024-01-03
New User Approve HIGH 8.8
CVE-2023-50902

Cross-Site Request Forgery (CSRF) vulnerability in WPExpertsio New User Approve.This issue affects New User Approve: from n/a through 2.5.1.

Fix: after 2.5.1
Fix from $1,950 2023-12-29
Mycred MEDIUM 5.4
CVE-2023-47853

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred myCred – Points, Rewards, Gamification, …

Fix: after 2.6.1
Fix from $1,600 2023-11-30
License Manager For Woocommerce HIGH 7.2
CVE-2023-48742

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LicenseManager License Manager for WooCommerce …

Fix: 2.2.11+
Fix from $1,950 2023-11-30
Post Smtp MEDIUM 6.1
CVE-2023-5958

The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthentic…

Fix: 2.7.1+
Fix from $1,600 2023-11-27
Email Templates Customizer And Designer HIGH 8.8
CVE-2022-47181

Cross-Site Request Forgery (CSRF) vulnerability in wpexpertsio Email Templates Customizer and Designer for WordPress and WooCommerce email-templates …

Fix: after 1.4.2
Fix from $1,950 2023-11-07
User Avatar Reloaded MEDIUM 5.4
CVE-2023-4798

The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relativel…

Fix: 1.2.2+
Fix from $1,600 2023-10-16
All In One Login HIGH 7.5
CVE-2023-3604

The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protec…

Fix: 1.1.4+
Fix from $1,950 2023-08-21
Wp Pdf Generator HIGH 8.8
CVE-2023-35038

Cross-Site Request Forgery (CSRF) vulnerability in wpexperts.Io WP PDF Generator plugin <= 1.2.2 versions.

Fix: 1.2.3+
Fix from $1,950 2023-07-17
Mycred HIGH 8.8
CVE-2023-35096

Cross-Site Request Forgery (CSRF) vulnerability in myCred plugin <= 2.5 versions.

Fix: after 2.5.1
Fix from $1,950 2023-07-17
Post Smtp HIGH 8.8
CVE-2023-3179

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged …

Fix: 2.5.7+
Fix from $1,950 2023-07-17
Post Smtp MEDIUM 6.1
CVE-2023-3082

The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.5.7 due to ins…

Fix: 2.5.8+
Fix from $1,600 2023-07-12