Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Backupbuddy HIGH 7.5
CVE-2022-31474EPSS 64%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue …

Fix: 8.7.5.0+
Fix from $1,950 2023-03-13
Backupbuddy MEDIUM 6.1
CVE-2022-4897

The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to …

Fix: 8.8.3+
Fix from $1,600 2023-02-21
Ithemes Security HIGH 7.5
CVE-2020-36176

The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing acco…

Fix: 7.7.0+
Fix from $1,950 2021-01-06
Paypal Pro CRITICAL 9.8
CVE-2020-14092EPSS 95%

The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

Fix: 1.1.65+
Fix from $2,300 2020-07-02
Membership MEDIUM 6.1
CVE-2015-9372

Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.3.0+
Fix from $1,600 2019-08-28
Stripe MEDIUM 6.1
CVE-2015-9374

Stripe Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.2.0+
Fix from $1,600 2019-08-28
Table Rate Shipping MEDIUM 6.1
CVE-2015-9375

Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.1.0+
Fix from $1,600 2019-08-28
Mobile MEDIUM 6.1
CVE-2015-9376

iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.2.8+
Fix from $1,600 2019-08-28
Builder Theme Depot MEDIUM 6.1
CVE-2015-9377

iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 5.0.30+
Fix from $1,600 2019-08-28
Builder Theme Market MEDIUM 6.1
CVE-2015-9378

iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 5.1.27+
Fix from $1,600 2019-08-28
Builder Style Manager MEDIUM 6.1
CVE-2015-9379

iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 0.7.7+
Fix from $1,600 2019-08-28
Easy Us Sales Taxes MEDIUM 6.1
CVE-2015-9369

Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.1.0+
Fix from $1,600 2019-08-28
Invoices MEDIUM 6.1
CVE-2015-9370

Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.4.0+
Fix from $1,600 2019-08-28
Manual Purchases MEDIUM 6.1
CVE-2015-9371

Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.1.0+
Fix from $1,600 2019-08-28
Exchange MEDIUM 6.1
CVE-2015-9363

iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.12.0+
Fix from $1,600 2019-08-28
Authorize.net MEDIUM 6.1
CVE-2015-9365

Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.1.0+
Fix from $1,600 2019-08-28
Custom Url Tracking MEDIUM 6.1
CVE-2015-9366

Custom URL Tracking Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.1.0+
Fix from $1,600 2019-08-28
Easy Canadian Sales Taxes MEDIUM 6.1
CVE-2015-9367

Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.1.0+
Fix from $1,600 2019-08-28
Easy Eu Value Added \(vat\) Taxes MEDIUM 6.1
CVE-2015-9368

Easy EU Value Added (VAT) Taxes Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

Fix: 1.2.0+
Fix from $1,600 2019-08-28
Security HIGH 7.2
CVE-2018-12636EPSS 30%

The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs pa…

Fix: 7.0.3+
Fix from $1,950 2018-06-22
Security HIGH 7.5
CVE-2018-7433

The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.

Fix: after 6.9.0
Fix from $1,950 2018-03-02
Backupbuddy HIGH 7.5
CVE-2013-2741

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, whic…

No fix yet
Fix from $1,950 2013-04-02
Backupbuddy HIGH 7.5
CVE-2013-2742

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a re…

No fix yet
Fix from $1,950 2013-04-02
Backupbuddy HIGH 7.5
CVE-2013-2743

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via …

No fix yet
Fix from $1,950 2013-04-02
Backupbuddy MEDIUM 5.0
CVE-2013-2744

importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpinfo actio…

No fix yet
Fix from $1,600 2013-04-02