Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Social Auto Poster HIGH 8.8
CVE-2023-26532

Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes Social Auto Poster plugin <= 2.1.4 versions.

Fix: after 2.1.4
Fix from $1,950 2023-11-22
Wp Tfeed HIGH 8.8
CVE-2023-26518

Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes WP TFeed plugin <= 1.6.9 versions.

Fix: after 1.6.9
Fix from $1,950 2023-11-13
Frontend Post Wordpress Plugin MEDIUM 5.4
CVE-2022-4946

The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users wit…

Fix: after 2.8.4
Fix from $1,600 2023-06-05
Wp Popup Banners HIGH 8.8
CVE-2023-28661

The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the …

No fix yet
Fix from $1,950 2023-03-22
Smart Logo Showcase Lite MEDIUM 5.4
CVE-2023-0175

The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before ou…

No fix yet
Fix from $1,600 2023-03-20
Access Demo Importer HIGH 8.1
CVE-2022-23976

Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media).

Fix: after 1.0.7
Fix from $1,950 2022-04-18
Access Demo Importer MEDIUM 6.5
CVE-2022-23975

Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin.

Fix: after 1.0.7
Fix from $1,600 2022-04-18
Ap Mega Menu MEDIUM 6.1
CVE-2022-0628

The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading t…

Fix: 3.0.8+
Fix from $1,600 2022-03-21
Ap Custom Testimonial HIGH 7.2
CVE-2022-23911

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when …

Fix: 1.4.7+
Fix from $1,950 2022-02-28
Ap Custom Testimonial MEDIUM 6.1
CVE-2022-23912

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribut…

Fix: 1.4.7+
Fix from $1,600 2022-02-28
Accessbuddy CRITICAL 9.8
CVE-2021-24867EPSS 19%

Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins …

No fix yet
Fix from $2,300 2022-02-21
Form Store To Db MEDIUM 6.1
CVE-2021-25107

The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back in the created entry, allowi…

Fix: 1.1.1+
Fix from $1,600 2022-02-14
Wp Cookie User Info HIGH 7.2
CVE-2021-24858

The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement,…

Fix: 1.0.9+
Fix from $1,950 2022-01-24
Access Demo Importer HIGH 8.8
CVE-2021-39317

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_insta…

Fix: 1.0.7+
Fix from $1,950 2021-10-11
Accesspress Social Icons HIGH 8.8
CVE-2021-24143

Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post p…

Fix: 1.8.1+
Fix from $1,950 2021-03-18
Wp Floating Menu MEDIUM 6.1
CVE-2020-25378

Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the id GET parameter.

No fix yet
Fix from $1,600 2020-09-14
Anonymous Post Pro CRITICAL 9.8
CVE-2017-16949EPSS 19%

An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the a…

Fix: after 3.1.9
Fix from $2,300 2017-12-19
Ultimate Form Builder Lite CRITICAL 9.8
CVE-2017-15919

The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.

Fix: after 1.3.6
Fix from $2,300 2017-10-26