Vulnerability index

Browse CVEs

56 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Elements Kit Elementor Addons MEDIUM 5.4
CVE-2024-2803

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, an…

Fix: 3.1.0+
Fix from $1,600 2024-04-04
Metform Elementor Contact Form Builder MEDIUM 5.4
CVE-2024-2791

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions…

Fix: 3.8.6+
Fix from $1,600 2024-04-02
Elements Kit Elementor Addons HIGH 8.8
CVE-2024-2047

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the rende…

Fix: 3.0.7+
Fix from $1,950 2024-03-30
Elements Kit Elementor Addons MEDIUM 5.4
CVE-2024-1238

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button ID parameter in all versions up to,…

Fix: 3.0.7+
Fix from $1,600 2024-03-30
Elements Kit Elementor Addons MEDIUM 5.4
CVE-2024-2042

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up …

Fix: 3.0.6+
Fix from $1,600 2024-03-16
Elements Kit Elementor Addons MEDIUM 5.4
CVE-2024-1239

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blog post read more button in all versions…

Fix: 3.0.5+
Fix from $1,600 2024-03-16
Wp Social Login And Register Social Counter MEDIUM 5.3
CVE-2024-1763

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c…

Fix: after 3.0.0
Fix from $1,600 2024-03-13
Metform Elementor Contact Form Builder MEDIUM 5.4
CVE-2024-1585

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all ver…

Fix: 3.8.4+
Fix from $1,600 2024-03-13
Wp Social Login And Register Social Counter MEDIUM 6.5
CVE-2022-47160

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp S…

Fix: 2.0.0+
Fix from $1,600 2024-01-19
Elements Kit Elementor Addons MEDIUM 5.3
CVE-2023-6582

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via…

Fix: 3.0.4+
Fix from $1,600 2024-01-11
Metform Elementor Contact Form Builder MEDIUM 5.4
CVE-2023-6788

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8…

Fix: after 3.8.1
Fix from $1,600 2024-01-09
Wp Ultimate Review HIGH 8.8
CVE-2023-28987

Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

Fix: after 2.0.3
Fix from $1,950 2023-11-12
Wp Ultimate Review HIGH 8.8
CVE-2023-46085

Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.

Fix: after 2.2.4
Fix from $1,950 2023-10-22
Metform Elementor Contact Form Builder MEDIUM 5.3
CVE-2023-1843

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update due to a missing capability …

Fix: after 3.3.0
Fix from $1,600 2023-06-09
Metform Elementor Contact Form Builder HIGH 7.8
CVE-2023-0721

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 3.3.0. This allows u…

Fix: after 3.3.0
Fix from $1,950 2023-06-09
Metform Elementor Contact Form Builder MEDIUM 5.4
CVE-2023-0710

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'fname' attribute of the 'mf_thankyou' sh…

Fix: after 3.3.0
Fix from $1,600 2023-06-09
Metform Elementor Contact Form Builder MEDIUM 5.4
CVE-2023-0695

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf' shortcode to echo unescaped form sub…

Fix: after 3.3.0
Fix from $1,600 2023-06-09
Metform Elementor Contact Form Builder MEDIUM 5.4
CVE-2023-0708

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_first_name' shortcode to echo unescap…

Fix: after 3.3.0
Fix from $1,600 2023-06-09
Metform Elementor Contact Form Builder MEDIUM 5.4
CVE-2023-0709

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_last_name' shortcode to echo unescape…

Fix: after 3.3.0
Fix from $1,600 2023-06-09
Metform Elementor Contact Form Builder MEDIUM 6.5
CVE-2023-0688

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' shortcode in versions up to, a…

Fix: after 3.3.1
Fix from $1,600 2023-06-09
Shopengine HIGH 8.8
CVE-2022-45371

Cross-Site Request Forgery (CSRF) vulnerability in Wpmet ShopEngine plugin <= 4.1.1 versions.

Fix: after 4.1.1
Fix from $1,950 2023-05-25
Metform Elementor Contact Form Builder MEDIUM 6.1
CVE-2023-0084EPSS 29%

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up t…

Fix: after 3.1.2
Fix from $1,600 2023-03-02
Metform Elementor Contact Form Builder MEDIUM 5.3
CVE-2023-0085

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass in versions up to, and including, 3.2.1. This is du…

Fix: after 3.2.1
Fix from $1,600 2023-03-02
Fundengine CRITICAL 9.8
CVE-2022-0788EPSS 8%

The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL…

Fix: 1.5.0+
Fix from $2,300 2022-06-08
Metform Elementor Contact Form Builder HIGH 7.5
CVE-2022-1442EPSS 9%

The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file whi…

Fix: 2.1.4+
Fix from $1,950 2022-05-10
Elements Kit Elementor Addons MEDIUM 5.4
CVE-2021-24258

The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting…

Fix: 2.2.0+
Fix from $1,600 2021-05-05