Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mainwp Dashboard MEDIUM 6.1
CVE-2016-15041

The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripti…

Fix: after 3.1.2
Fix from $1,600 2024-10-16
Mainwp Child HIGH 8.8
CVE-2024-7492

The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to m…

Fix: 2.2.1+
Fix from $1,950 2024-08-08
Updraftplus Extension HIGH 8.8
CVE-2023-23640

Missing Authorization vulnerability in MainWP MainWP UpdraftPlus Extension.This issue affects MainWP UpdraftPlus Extension: from n/a through 4.0.6.

Fix: 4.0.7+
Fix from $1,950 2024-06-09
Staging Extension HIGH 8.8
CVE-2023-23639

Missing Authorization vulnerability in MainWP MainWP Staging Extension.This issue affects MainWP Staging Extension: from n/a through 4.0.3.

Fix: 4.0.4+
Fix from $1,950 2024-06-09
Code Snippets Extension CRITICAL 9.9
CVE-2023-23645

Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue aff…

Fix: 4.0.3+
Fix from $2,300 2024-05-17
Mainwp Child Reports MEDIUM 5.4
CVE-2024-33680

Cross-Site Request Forgery (CSRF) vulnerability in MainWP MainWP Child Reports.This issue affects MainWP Child Reports: from n/a through 2.1.1.

Fix: 2.2+
Fix from $1,600 2024-04-26
Mainwp Wordfence Extension MEDIUM 5.4
CVE-2023-22699

Missing Authorization vulnerability in MainWP MainWP Wordfence Extension.This issue affects MainWP Wordfence Extension: from n/a through 4.0.7.

Fix: 4.0.8+
Fix from $1,600 2024-03-25
Mainwp Google Analytics Extension HIGH 8.8
CVE-2023-23651

Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions.

Fix: after 4.0.4
Fix from $1,950 2023-10-12
Mainwp Maintenance Extension HIGH 8.8
CVE-2023-23660

Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP MainWP Maintenance Extension plugin <= 4.1.1 versions.

Fix: after 4.1.1
Fix from $1,950 2023-07-18
Mainwp Child HIGH 7.5
CVE-2023-3132

The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient c…

Fix: after 4.4.1.1
Fix from $1,950 2023-06-27
Code Snippets Extension MEDIUM 5.4
CVE-2023-23650

Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in MainWP MainWP Code Snippets Extension plugin <= 4.0.2 versions.

Fix: 4.0.3+
Fix from $1,600 2023-03-23
Motomo HIGH 8.8
CVE-2023-23659

Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension <= 4.0.4 versions.

Fix: 4.0.5+
Fix from $1,950 2023-02-23
Mainwp Child HIGH 7.2
CVE-2021-24877

The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an …

Fix: 4.1.8+
Fix from $1,950 2021-11-23
Mainwp Child Reports HIGH 7.2
CVE-2021-24754

The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the ad…

Fix: 2.0.8+
Fix from $1,950 2021-10-18