Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Beaver Builder Addons MEDIUM 5.4
CVE-2024-30424

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Beaver Builder Addons by WPZOOM wpzoom-a…

Fix: 1.3.5+
Fix from $1,600 2024-11-19
Recipe Card Blocks For Gutenberg \& Elementor HIGH 8.8
CVE-2024-43293

Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor allows Exploiting Incorrectly Configured Access Control Se…

Fix: 3.3.2+
Fix from $1,950 2024-11-01
Wpzoom Shortcodes MEDIUM 5.4
CVE-2024-9027

The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and i…

Fix: after 1.0.5
Fix from $1,600 2024-09-25
Wpzoom Portfolio MEDIUM 5.4
CVE-2024-8276

The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute w…

Fix: 1.4.5+
Fix from $1,600 2024-08-31
Wpzoom Addons For Elementor MEDIUM 5.4
CVE-2024-5686

The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within…

Fix: 1.1.39+
Fix from $1,600 2024-06-20
Social Icons Widget HIGH 8.8
CVE-2024-30464

Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/…

Fix: 4.2.16+
Fix from $1,950 2024-06-09
Wpzoom Elementor Addons CRITICAL 9.8
CVE-2024-5147

The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,…

Fix: 1.1.38+
Fix from $2,300 2024-05-22
Social Icons Widget MEDIUM 6.1
CVE-2024-2189

The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow …

Fix: 4.2.18+
Fix from $1,600 2024-05-21
Wpzoom Elementor Addons MEDIUM 5.4
CVE-2024-4370

The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget Image …

Fix: 1.1.37+
Fix from $1,600 2024-05-15
Wpzoom Elementor Addons MEDIUM 5.4
CVE-2024-33539

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Addons for Elementor (Templates, …

Fix: 1.1.36+
Fix from $1,600 2024-04-29
Beaver Builder Addons MEDIUM 5.4
CVE-2024-2183

The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, a…

Fix: 1.3.5+
Fix from $1,600 2024-04-09
Beaver Builder Addons MEDIUM 5.4
CVE-2024-2185

The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget in all versions up to,…

Fix: 1.3.5+
Fix from $1,600 2024-04-09
Beaver Builder Addons MEDIUM 5.4
CVE-2024-2186

The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Members widget in all versions up …

Fix: 1.3.5+
Fix from $1,600 2024-04-09
Beaver Builder Addons MEDIUM 5.4
CVE-2024-2187

The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonials widget in all versions up …

Fix: 1.3.5+
Fix from $1,600 2024-04-09
Beaver Builder Addons MEDIUM 5.4
CVE-2024-2181

The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, an…

Fix: 1.3.5+
Fix from $1,600 2024-04-09
Wpzoom Shortcodes MEDIUM 6.1
CVE-2024-22162

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Shortcodes allows Reflected XSS.T…

Fix: after 1.0.1
Fix from $1,600 2024-01-31
Icon Widget MEDIUM 5.4
CVE-2022-4763

The Icon Widget WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, …

Fix: 1.3.0+
Fix from $1,600 2023-01-30
Wpzoom Portfolio MEDIUM 5.4
CVE-2022-4789

The WPZOOM Portfolio WordPress plugin before 1.2.2 does not validate and escape one of its shortcode attributes, which could allow users with a role …

Fix: 1.2.2+
Fix from $1,600 2023-01-23
Inspiro Pro MEDIUM 5.4
CVE-2022-2391

The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as low as Contributor to inject J…

Fix: 7.2.3+
Fix from $1,600 2022-08-08
Recipe Card Blocks For Gutenberg \& Elementor MEDIUM 6.1
CVE-2021-24632

The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard…

Fix: 2.8.1+
Fix from $1,600 2021-09-27
Recipe Card Blocks For Gutenberg \& Elementor MEDIUM 5.4
CVE-2021-24634

The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (…

Fix: 2.8.3+
Fix from $1,600 2021-09-27