Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Theme Switcha MEDIUM 5.4
CVE-2025-46239

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme Switcha theme-switcha allows S…

Fix: 3.4.1+
Fix from $1,600 2025-04-22
Simple Download Counter MEDIUM 5.4
CVE-2025-46240

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter simple-downl…

Fix: 2.2.1+
Fix from $1,600 2025-04-22
Dashboard Widgets Suite MEDIUM 6.1
CVE-2024-0979

The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and i…

Fix: 3.4.4+
Fix from $1,600 2024-06-13
Simple Ajax Chat MEDIUM 5.4
CVE-2024-2470

The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could allow high privilege users such…

Fix: 20240412+
Fix from $1,600 2024-06-04
Simple Ajax Chat HIGH 7.1
CVE-2024-1983

The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflec…

Fix: 20240223+
Fix from $1,950 2024-03-20
User Submitted Posts CRITICAL 9.8
CVE-2023-45603

Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.Th…

Fix: after 20230902
Fix from $2,300 2023-12-20
Theme Switcha MEDIUM 5.4
CVE-2023-5614

The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list' shortcode in all versions u…

Fix: after 3.3
Fix from $1,600 2023-10-20
Simple Download Counter MEDIUM 5.4
CVE-2023-4838

The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and incl…

Fix: after 1.6
Fix from $1,600 2023-09-09
User Submitted Posts MEDIUM 5.4
CVE-2023-4779

The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery] shortcode in versions up to…

Fix: after 20230811
Fix from $1,600 2023-09-06
User Submitted Posts MEDIUM 5.4
CVE-2023-4308

The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up …

Fix: 20230811+
Fix from $1,600 2023-08-15
User Submitted Posts CRITICAL 9.8
CVE-2019-25138

The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images fun…

Fix: after 20190312
Fix from $2,300 2023-06-07
Simple Ajax Chat HIGH 7.5
CVE-2022-27849

Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115

Fix: after 20220115
Fix from $1,950 2022-04-15
Blackhole For Bad Bots CRITICAL 9.1
CVE-2022-1165

The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests…

Fix: 3.3.2+
Fix from $2,300 2022-04-04
Simple Ajax Chat MEDIUM 6.1
CVE-2022-25610

Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code. However, the attack…

Fix: 20220115+
Fix from $1,600 2022-03-25
Contact Form X MEDIUM 6.1
CVE-2022-25601

Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).

Fix: 2.4.1+
Fix from $1,600 2022-03-11
Prismatic MEDIUM 6.1
CVE-2021-24409

The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected C…

Fix: 2.8+
Fix from $1,600 2021-07-12
Prismatic MEDIUM 5.4
CVE-2021-24408

The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contri…

Fix: 2.8+
Fix from $1,600 2021-07-12
User Submitted Posts MEDIUM 6.1
CVE-2016-11001

The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.

Fix: 20160215+
Fix from $1,600 2019-09-20