Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Pricing Table MEDIUM 6.1
CVE-2024-13628

The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflec…

Fix: after 1.1
Fix from $1,600 2025-02-26
Wp Go Maps HIGH 8.8
CVE-2025-24742

Cross-Site Request Forgery (CSRF) vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.40.

Fix: 9.0.41+
Fix from $1,950 2025-01-27
Super Testimonials MEDIUM 5.4
CVE-2024-9127

The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter in all versions up to, and inc…

Fix: after 3.0.0
Fix from $1,600 2024-09-26
Wp Go Maps MEDIUM 5.4
CVE-2024-5994

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, an…

Fix: 9.0.39+
Fix from $1,600 2024-06-14
Wp Go Maps MEDIUM 5.4
CVE-2024-3557

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza shortcode in all v…

Fix: 9.0.37+
Fix from $1,600 2024-05-24
Wp Go Maps MEDIUM 6.5
CVE-2023-6777

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9…

Fix: 9.0.35+
Fix from $1,600 2024-04-09
Wp Go Maps MEDIUM 6.1
CVE-2024-29931

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue af…

Fix: 9.0.30+
Fix from $1,600 2024-03-27
Wp Go Maps MEDIUM 5.4
CVE-2024-1582

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all…

Fix: 9.0.33+
Fix from $1,600 2024-03-13
Wp Go Maps MEDIUM 6.1
CVE-2023-6627

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can ab…

Fix: 9.0.28+
Fix from $1,600 2024-01-08
Wp Go Maps MEDIUM 6.5
CVE-2022-47595

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15…

Fix: after 9.0.15
Fix from $1,600 2023-03-14
Wp Go Maps MEDIUM 5.4
CVE-2021-36870

Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable para…

Fix: after 8.1.12
Fix from $1,600 2021-09-09
Wp Go Maps MEDIUM 5.4
CVE-2021-36871

Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vul…

Fix: after 8.1.11
Fix from $1,600 2021-09-09
Wp Go Maps MEDIUM 5.4
CVE-2021-24383

The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboar…

Fix: 8.1.12+
Fix from $1,600 2021-06-21
Wp Go Maps MEDIUM 5.4
CVE-2019-14792

The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.

Fix: 7.11.35+
Fix from $1,600 2019-08-09
Wp Go Maps CRITICAL 9.8
CVE-2019-10692EPSS 79%

In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT …

Fix: 7.11.18+
Fix from $2,300 2019-04-02
Wp Go Maps MEDIUM 6.1
CVE-2019-9912

The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.

Fix: 7.10.43+
Fix from $1,600 2019-03-22