Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Essential Real Estate CRITICAL 9.8
CVE-2025-48126

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estat…

Fix: after 5.2.2
Fix from $2,300 2025-06-09
April HIGH 8.8
CVE-2024-13418

Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() func…

Fix: after 7.1
Fix from $1,950 2025-05-02
April MEDIUM 5.4
CVE-2024-13419

Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on…

Fix: after 7.1
Fix from $1,600 2025-05-02
Essential Real Estate CRITICAL 9.8
CVE-2025-30849

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estat…

Fix: 5.2.1+
Fix from $2,300 2025-04-01
Ultimate Bootstrap Elements For Elementor CRITICAL 9.8
CVE-2024-13545

The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. …

Fix: after 1.4.9
Fix from $2,300 2025-01-24
Ultimate Bootstrap Elements For Elementor HIGH 8.8
CVE-2024-43140

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor all…

Fix: 1.4.5+
Fix from $1,950 2024-08-13
Ultimate Bootstrap Elements For Elementor HIGH 8.8
CVE-2024-37462

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor all…

Fix: 1.4.3+
Fix from $1,950 2024-07-09
Essential Real Estate MEDIUM 5.4
CVE-2024-4273

The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ere_property_map' shortcode in all vers…

Fix: 4.4.3+
Fix from $1,600 2024-06-04
Ultimate Bootstrap Elements For Elementor MEDIUM 5.4
CVE-2024-2132

The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Widget in all versions …

Fix: 1.4.1+
Fix from $1,600 2024-04-06
Ultimate Bootstrap Elements For Elementor MEDIUM 6.4
CVE-2024-1398

The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_title_tag’ and ’head…

Fix: 1.3.7+
Fix from $1,600 2024-03-02
Ere Recently Viewed CRITICAL 9.8
CVE-2024-24797

Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed …

Fix: 2.0+
Fix from $2,300 2024-02-12
Essential Real Estate HIGH 8.8
CVE-2023-6140

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentaril…

Fix: 4.4.0+
Fix from $1,950 2024-01-08
Essential Real Estate MEDIUM 5.4
CVE-2023-6141

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow …

Fix: 4.4.0+
Fix from $1,600 2024-01-08
Essential Real Estate MEDIUM 6.5
CVE-2023-6139

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow …

Fix: 4.4.0+
Fix from $1,600 2024-01-08
Essential Real Estate HIGH 8.8
CVE-2023-6827

The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFon…

Fix: after 4.3.5
Fix from $1,950 2023-12-15