Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp All Export HIGH 7.2
CVE-2024-7425

The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper u…

Fix: 1.9.2+
Fix from $1,950 2025-02-07
Wp All Export HIGH 8.8
CVE-2024-7419

The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export f…

Fix: 1.9.2+
Fix from $1,950 2025-02-07
Wp All Import HIGH 7.2
CVE-2024-9664

The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of u…

Fix: 4.9.8+
Fix from $1,950 2025-02-07
Breakdance MEDIUM 5.4
CVE-2024-5330

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up…

Fix: 2.0+
Fix from $1,600 2024-08-01
Export Any Wordpress Data To Xml\/csv HIGH 7.2
CVE-2023-7082

The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly accessi…

Fix: 3.7.3+
Fix from $1,950 2024-01-22
Oxygen MEDIUM 5.4
CVE-2023-6938

The Oxygen Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom field in all versions up to, and including, 4.8 due…

Fix: 4.8.1+
Fix from $1,600 2024-01-11
Export Any Wordpress Data To Xml\/csv HIGH 8.8
CVE-2023-5882

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens e…

Fix: 1.4.1 / 1.8.6+
Fix from $1,950 2023-12-18
Export Any Wordpress Data To Xml\/csv HIGH 8.8
CVE-2023-5886

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens e…

Fix: 1.4.1 / 1.8.6+
Fix from $1,950 2023-12-18
Export Any Wordpress Data To Xml\/csv HIGH 7.2
CVE-2023-4724

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitis…

Fix: 1.4.0 / 1.8.6+
Fix from $1,950 2023-12-18
Oxygen HIGH 8.8
CVE-2022-46841

Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Oxygen Builder plugin <= 4.4 versions.

Fix: 4.4+
Fix from $1,950 2023-10-03
Wp All Import HIGH 7.2
CVE-2022-2711

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing hig…

Fix: 3.6.9+
Fix from $1,950 2022-11-07
Wp All Import HIGH 7.2
CVE-2022-3418

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the ser…

Fix: 3.6.9+
Fix from $1,950 2022-11-07
Wp All Export HIGH 8.8
CVE-2022-3395

The WP All Export Pro WordPress plugin before 1.7.9 uses the contents of the cc_sql POST parameter directly as a database query, allowing users which…

Fix: 1.7.9+
Fix from $1,950 2022-10-25
Wp All Export HIGH 7.2
CVE-2022-3394

The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allow…

Fix: 1.7.9+
Fix from $1,950 2022-10-25
Wp All Import HIGH 7.2
CVE-2022-36386

Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

Fix: after 3.6.7
Fix from $1,950 2022-09-21
Wp All Import HIGH 7.2
CVE-2022-2268

The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the …

Fix: 3.6.8+
Fix from $1,950 2022-07-04
Export Any Wordpress Data To Xml\/csv HIGH 7.2
CVE-2022-1800

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using…

Fix: 1.3.5+
Fix from $1,950 2022-06-13
Wp All Import MEDIUM 6.1
CVE-2018-20978

The wp-all-import plugin before 3.4.7 for WordPress has XSS.

Fix: 3.4.7+
Fix from $1,600 2019-08-20
Wp All Import CRITICAL 9.8
CVE-2015-9330

The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.

Fix: 3.2.5+
Fix from $2,300 2019-08-20
Wp All Import HIGH 7.5
CVE-2015-9331

The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.

Fix: 3.2.4+
Fix from $1,950 2019-08-20
Wp All Import MEDIUM 6.1
CVE-2015-9329

The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.

Fix: 3.2.5+
Fix from $1,600 2019-08-20
Wp All Import MEDIUM 6.1
CVE-2017-18567

The wp-all-import plugin before 3.4.6 for WordPress has XSS.

Fix: 3.2.6+
Fix from $1,600 2019-08-20
Wp All Import MEDIUM 6.1
CVE-2018-16257

There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vu…

Mitigation only
Fix from $1,600 2019-04-12
Wp All Import MEDIUM 6.1
CVE-2018-16258

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not…

Mitigation only
Fix from $1,600 2019-04-12
Wp All Import MEDIUM 6.1
CVE-2018-16259

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this…

Mitigation only
Fix from $1,600 2019-04-12
Wp All Import MEDIUM 6.1
CVE-2018-16254

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerabilit…

Mitigation only
Fix from $1,600 2019-04-12
Wp All Import MEDIUM 6.1
CVE-2018-16255

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerabili…

Mitigation only
Fix from $1,600 2019-04-12
Wp All Import MEDIUM 6.1
CVE-2018-16256

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is n…

No fix yet
Fix from $1,600 2019-04-12
Wp All Import MEDIUM 6.1
CVE-2018-0546

Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to inject arbitrary web script or …

Fix: 3.4.6+
Fix from $1,600 2018-03-09
Wp All Import MEDIUM 6.1
CVE-2018-0547

Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to inject arbitrary web script or …

Fix: after 3.4.6
Fix from $1,600 2018-03-09