Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cryptocurrency Widgets CRITICAL 9.8
CVE-2023-36681

Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List allows Exploiting Incorrectly Configured Acces…

Fix: 2.6.3+
Fix from $2,300 2024-12-13
Cryptocurrency Widgets For Elementor CRITICAL 9.8
CVE-2024-53739

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency …

Fix: 1.6.5+
Fix from $2,300 2024-11-30
Web Stories Widgets For Elementor MEDIUM 5.4
CVE-2024-52354

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cool Plugins Web Stories Widgets For Elementor …

Fix: 1.1.1+
Fix from $1,600 2024-11-11
Cryptocurrency Widgets MEDIUM 6.1
CVE-2024-43304

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cool Plugins Cryptocurrency Widgets – Pr…

Fix: 2.8.1+
Fix from $1,600 2024-08-18
Timeline Widget For Elementor MEDIUM 5.4
CVE-2024-0977

The Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) plugin for WordPress is vulnerable to Stored Cross-Site Script…

Fix: 1.5.4+
Fix from $1,600 2024-02-07
Cryptocurrency Widgets HIGH 7.5
CVE-2024-0709

The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions …

Fix: after 2.6.5
Fix from $1,950 2024-02-05
Events Shortcodes For The Events Calendar HIGH 8.8
CVE-2023-52142

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events C…

Fix: after 2.3.1
Fix from $1,950 2024-01-08
Cool Timeline HIGH 8.8
CVE-2022-4950

Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execu…

Fix: 1.2 / 1.3+
Fix from $1,950 2023-06-07
Process Steps Template Designer HIGH 8.8
CVE-2021-4349

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This ma…

Fix: after 1.2.1
Fix from $1,950 2023-06-07