Vulnerability index

Browse CVEs

71 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Smtp HIGH 7.2
CVE-2024-13908

The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' functi…

Fix: 1.2.0+
Fix from $1,950 2025-03-08
Contact Form To Db HIGH 8.8
CVE-2024-35678

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft.T…

Fix: 1.7.3+
Fix from $1,950 2024-06-08
Contact Form MEDIUM 6.1
CVE-2024-2200

The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_subject’ parameter in …

Fix: 4.2.9+
Fix from $1,600 2024-04-09
Captcha HIGH 7.1
CVE-2023-45771

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contact Form With Captcha allows Reflected XSS.…

Fix: after 1.6.8
Fix from $1,950 2024-03-26
Error Log Viewer MEDIUM 6.5
CVE-2023-6821

The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP l…

Fix: 1.1.3+
Fix from $1,600 2024-03-18
Like \& Share HIGH 7.5
CVE-2023-6250

The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag

Fix: 2.74+
Fix from $1,950 2023-12-26
Pluscaptcha MEDIUM 6.1
CVE-2015-10127

A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this issue is some unknown functi…

Fix: after 2.0.6
Fix from $1,600 2023-12-26
Portfolio MEDIUM 6.1
CVE-2014-125109

A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.27. It has been declared as problematic. This vulnerability affects the function bw…

Fix: 2.28+
Fix from $1,600 2023-12-26
Portfolio HIGH 8.8
CVE-2012-10017

A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.04 on WordPress. It has been classified as problematic. This affects an unknown par…

Fix: 2.06+
Fix from $1,950 2023-12-26
Contact Form To Db HIGH 8.8
CVE-2023-29096

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft –…

Fix: after 1.7.0
Fix from $1,950 2023-12-20
Post To Csv HIGH 8.8
CVE-2023-36527

Improper Neutralization of Formula Elements in a CSV File vulnerability in BestWebSoft Post to CSV by BestWebSoft.This issue affects Post to CSV by B…

Fix: after 1.4.0
Fix from $1,950 2023-11-07
Contact Form To Db CRITICAL 9.8
CVE-2023-36508

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft –…

Fix: after 1.7.1
Fix from $2,300 2023-10-31
Profile Extra Fields MEDIUM 5.3
CVE-2023-4469

The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the pr…

Fix: after 1.2.7
Fix from $1,600 2023-10-06
Twitter MEDIUM 6.1
CVE-2014-125103

A vulnerability was found in BestWebSoft Twitter Plugin up to 1.3.2 on WordPress. It has been declared as problematic. Affected by this vulnerability…

Fix: after 1.3.2
Fix from $1,600 2023-05-31
Twitter HIGH 8.8
CVE-2012-10015

A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. It has been classified as problematic. Affected is the function twtt…

Fix: 2.15+
Fix from $1,950 2023-05-31
Relevant HIGH 7.5
CVE-2014-125102

A vulnerability classified as problematic was found in Bestwebsoft Relevant Plugin up to 1.0.7 on WordPress. Affected by this vulnerability is an unk…

Fix: 1.0.8+
Fix from $1,950 2023-05-29
Job Board MEDIUM 6.1
CVE-2014-125100

A vulnerability classified as problematic was found in BestWebSoft Job Board Plugin 1.0.0 on WordPress. This vulnerability affects unknown code. The …

Patch available
Fix from $1,600 2023-05-02
Gallery HIGH 8.8
CVE-2023-0765

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulne…

Fix: 4.7.0+
Fix from $1,950 2023-04-17
Gallery MEDIUM 5.4
CVE-2023-0764

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site …

Fix: 4.7.0+
Fix from $1,600 2023-04-17
Facebook Button MEDIUM 6.1
CVE-2014-125097

A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected is the function fcbkbttn_set…

Fix: 2.34+
Fix from $1,600 2023-04-10
Facebook Button HIGH 8.8
CVE-2012-10012

A vulnerability has been found in BestWebSoft Facebook Like Button up to 2.13 and classified as problematic. Affected by this vulnerability is the fu…

Fix: after 2.13
Fix from $1,950 2023-04-10
Contact Form HIGH 8.8
CVE-2012-10010

A vulnerability was found in BestWebSoft Contact Form 3.21. It has been classified as problematic. This affects the function cntctfrm_settings_page o…

Patch available
Fix from $1,950 2023-04-09
Contact Form MEDIUM 6.1
CVE-2014-125095

A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected by this issue is the function…

Patch available
Fix from $1,600 2023-04-09
Contact Form MEDIUM 6.1
CVE-2013-10022

A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. Affected by this issue is …

Patch available
Fix from $1,600 2023-04-05
User Role HIGH 8.8
CVE-2023-0820

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrar…

Fix: 1.6.7+
Fix from $1,950 2023-04-03
Post To Csv CRITICAL 9.8
CVE-2022-3393

The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection

Fix: after 1.4.0
Fix from $2,300 2022-10-25
Rating MEDIUM 6.5
CVE-2021-25121

The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of long integer, causing a Denial o…

Fix: 1.6+
Fix from $1,600 2022-06-20
Contact Form MEDIUM 5.4
CVE-2017-20055

A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation lea…

No fix yet
Fix from $1,600 2022-06-16
Error Log Viewer MEDIUM 6.5
CVE-2021-24761

The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention,…

Fix: 1.1.2+
Fix from $1,600 2022-02-01
Visitors Online MEDIUM 6.1
CVE-2021-24350

The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The plugin would display…

Fix: after 0.3
Fix from $1,600 2021-06-14