Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2017-20206 The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted … Appointments after 2.2.1 Fix from $2,3002025-10-18 MEDIUM 6.4 CVE-2025-5341 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id… Forminator Forms 1.44.2+ Fix from $1,6002025-06-05 MEDIUM 5.4 CVE-2025-3487 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘li… Forminator Forms 1.42.1+ Fix from $1,6002025-04-17 MEDIUM 5.3 CVE-2025-3479 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and… Forminator Forms 1.42.1+ Fix from $1,6002025-04-17 MEDIUM 5.4 CVE-2025-0469 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sli… Forminator Forms 1.39.3+ Fix from $1,6002025-02-27 MEDIUM 6.1 CVE-2025-0470 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … Forminator Forms 1.38.3+ Fix from $1,6002025-01-31 CRITICAL 9.8 CVE-2024-37444 Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Defender Security defender-security.This issue affects Defender … Defender 4.7.3+ Fix from $2,3002024-11-01 MEDIUM 5.3 CVE-2024-9700 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all… Forminator Forms 1.36.1+ Fix from $1,6002024-10-31 HIGH 8.8 CVE-2024-10402 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing ca… Forminator Forms 1.36.0+ Fix from $1,9502024-10-26 HIGH 8.8 CVE-2024-43117 Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affec… Hummingbird 3.9.2+ Fix from $1,9502024-08-26 MEDIUM 5.3 CVE-2024-6554 The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, an… Branda 3.4.19+ Fix from $1,6002024-07-11 MEDIUM 5.4 CVE-2024-5191 The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_type… Branda 3.4.18+ Fix from $1,6002024-06-21 CRITICAL 9.8 CVE-2023-47189 Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect… Defender 4.2.1+ Fix from $2,3002024-06-04 MEDIUM 5.3 CVE-2024-25595 Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from … Defender 4.4.2+ Fix from $1,6002024-05-17 CRITICAL 9.8 CVE-2022-44581 Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This … Defender 3.3.3+ Fix from $2,3002024-05-17 HIGH 8.6 CVE-2024-0368 The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… Hustle 7.8.4+ Fix from $1,9502024-03-13 HIGH 7.5 CVE-2023-51490 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.T… Defender Security after 4.1.0 Fix from $1,9502024-01-08 HIGH 7.5 CVE-2023-5949 The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts' content. Smartcrawl 3.8.3+ Fix from $1,9502023-12-18 MEDIUM 5.3 CVE-2023-5089 The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing a… Defender Security 4.1.0+ Fix from $1,6002023-10-16 MEDIUM 6.1 CVE-2015-10098 A vulnerability was found in Broken Link Checker Plugin up to 1.10.5 on WordPress. It has been rated as problematic. Affected by this issue is the fu… Broken Link Checker 1.10.6+ Fix from $1,6002023-04-08 MEDIUM 6.1 CVE-2022-1009 The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back in an admin page when upload… Smush Image Compression And Optimization 3.9.9+ Fix from $1,6002022-05-30 HIGH 8.8 CVE-2017-18510 The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions. Custom Sidebars 3.1.0+ Fix from $1,9502019-08-14 HIGH 8.8 CVE-2017-18511 The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF. Custom Sidebars 3.0.8.1+ Fix from $1,9502019-08-14 HIGH 7.5 CVE-2017-15079 The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal. Smush Image Compression And Optimization after 2.7.5 Fix from $1,9502017-10-06