Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Export All Posts\, Products\, Orders\, Refunds \& Users HIGH 7.5
CVE-2024-12315

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a…

Fix: 2.10+
Fix from $1,950 2025-02-12
Sendgrid CRITICAL 9.8
CVE-2024-43965

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGrid for WordPress allows SQL I…

Fix: after 1.4
Fix from $2,300 2024-08-29
Export All Posts\, Products\, Orders\, Refunds \& Users HIGH 7.5
CVE-2023-2487

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issu…

Fix: after 2.4.1
Fix from $1,950 2023-12-21
Export All Posts\, Products\, Orders\, Refunds \& Users HIGH 7.5
CVE-2023-45066

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issu…

Fix: after 2.4.1
Fix from $1,950 2023-11-30
Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv HIGH 8.8
CVE-2015-10125

A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The man…

Fix: 3.7.3+
Fix from $1,950 2023-10-05
Wp Ultimate Csv Importer HIGH 8.8
CVE-2023-4140

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient r…

Fix: after 7.9.8
Fix from $1,950 2023-08-04
Wp Ultimate Csv Importer HIGH 8.8
CVE-2023-4141

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' par…

Fix: after 7.9.8
Fix from $1,950 2023-08-04
Wp Ultimate Csv Importer HIGH 8.8
CVE-2023-4142

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' par…

Fix: after 7.9.8
Fix from $1,950 2023-08-04
Wp Ultimate Csv Importer HIGH 7.5
CVE-2023-4139

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction i…

Fix: after 7.9.8
Fix from $1,950 2023-08-04
Visual Email Designer For Woocommerce HIGH 8.8
CVE-2022-3860

The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL st…

Fix: 1.7.2+
Fix from $1,950 2023-01-02
Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv HIGH 7.2
CVE-2022-3243

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements…

Fix: 6.5.8+
Fix from $1,950 2022-10-17
Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv HIGH 7.2
CVE-2022-1977

The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL b…

Fix: 6.5.3+
Fix from $1,950 2022-06-27
Ultimate Exporter CRITICAL 9.8
CVE-2016-11000

The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

Fix: after 1.1
Fix from $2,300 2019-09-20
Echo Sign MEDIUM 6.1
CVE-2016-10984

The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.

Fix: 1.2+
Fix from $1,600 2019-09-17
Echo Sign MEDIUM 6.1
CVE-2016-10985

The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.

Fix: 1.2+
Fix from $1,600 2019-09-17
Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv HIGH 8.8
CVE-2018-20967

The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.

Fix: 5.6.1+
Fix from $1,950 2019-08-14
Ultimate Exporter HIGH 8.8
CVE-2018-20968

The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.

Fix: 1.4.2+
Fix from $1,950 2019-08-14
Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv MEDIUM 6.1
CVE-2015-9306

The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.

Fix: 3.8.1+
Fix from $1,600 2019-08-12
Wp Ultimate Email Marketer Plugin MEDIUM 6.4
CVE-2013-3264

The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2) campaig…

Fix: after 1.1.0
Fix from $1,600 2013-11-05