Vulnerability index

Browse CVEs

63 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wordpress Simple Paypal Shopping Cart MEDIUM 6.5
CVE-2025-3874

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3…

Fix: 5.1.4+
Fix from $1,600 2025-05-01
Wordpress Simple Paypal Shopping Cart MEDIUM 5.4
CVE-2025-3890

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in a…

Fix: 5.1.4+
Fix from $1,600 2025-05-01
Wordpress Simple Paypal Shopping Cart MEDIUM 5.3
CVE-2025-3889

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3…

Fix: 5.1.4+
Fix from $1,600 2025-05-01
Wp Estore MEDIUM 6.5
CVE-2024-6133

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leadin…

Fix: 8.5.6+
Fix from $1,600 2024-08-12
Wp Estore MEDIUM 5.4
CVE-2024-6134

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leadin…

Fix: 8.5.6+
Fix from $1,600 2024-08-12
Wp Estore MEDIUM 5.4
CVE-2024-6136

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged i…

Fix: 8.5.6+
Fix from $1,600 2024-08-12
Wp Emember MEDIUM 6.1
CVE-2024-5081

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Fix: 10.7.0+
Fix from $1,600 2024-08-05
Wp Affiliate Platform MEDIUM 5.5
CVE-2024-5285

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to ma…

Fix: 6.5.2+
Fix from $1,600 2024-07-29
Wp Estore HIGH 8.8
CVE-2024-6075

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged i…

Fix: 8.5.5+
Fix from $1,950 2024-07-15
Wp Estore MEDIUM 6.1
CVE-2024-6072

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an …

Fix: 8.5.5+
Fix from $1,600 2024-07-15
Wp Estore MEDIUM 6.1
CVE-2024-6073

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leadin…

Fix: 8.5.5+
Fix from $1,600 2024-07-15
Wp Estore MEDIUM 6.1
CVE-2024-6074

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leadin…

Fix: 8.5.5+
Fix from $1,600 2024-07-15
Wp Estore MEDIUM 6.1
CVE-2024-6076

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leadin…

Fix: 8.5.5+
Fix from $1,600 2024-07-15
Wp Emember HIGH 7.1
CVE-2024-5715

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Fix: 10.6.7+
Fix from $1,950 2024-07-13
Wp Emember MEDIUM 6.8
CVE-2024-5744

The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which …

Fix: 10.6.7+
Fix from $1,600 2024-07-13
Wp Emember HIGH 8.8
CVE-2024-5080

The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP …

Fix: 10.6.6+
Fix from $1,950 2024-07-13
Wp Affiliate Platform HIGH 7.1
CVE-2024-5287

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to …

Fix: 6.5.1+
Fix from $1,950 2024-07-13
Wp Emember MEDIUM 6.8
CVE-2024-5077

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could a…

Fix: 10.6.6+
Fix from $1,600 2024-07-13
Wp Affiliate Platform MEDIUM 6.8
CVE-2024-5284

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi…

Fix: 6.5.1+
Fix from $1,600 2024-07-13
Wp Emember MEDIUM 6.1
CVE-2024-5079

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated use…

Fix: 10.6.7+
Fix from $1,600 2024-07-13
Wp Affiliate Platform MEDIUM 6.1
CVE-2024-5281

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Fix: 6.5.1+
Fix from $1,600 2024-07-13
Wp Affiliate Platform MEDIUM 6.1
CVE-2024-5282

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Fix: 6.5.1+
Fix from $1,600 2024-07-13
Wp Affiliate Platform MEDIUM 6.1
CVE-2024-5283

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Fix: 6.5.1+
Fix from $1,600 2024-07-13
Wp Emember HIGH 8.8
CVE-2024-5076

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform u…

Fix: 10.6.6+
Fix from $1,950 2024-07-13
Wp Emember MEDIUM 5.9
CVE-2024-5075

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Fix: 10.6.6+
Fix from $1,600 2024-07-13
Wp Emember MEDIUM 5.4
CVE-2024-5074

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Fix: 10.6.6+
Fix from $1,600 2024-07-13
Wp Emember HIGH 8.3
CVE-2024-4749

The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to …

Fix: 10.3.9+
Fix from $1,950 2024-06-04
Simple Photo Gallery CRITICAL 9.8
CVE-2022-47588

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Peter Petreski Simple Photo…

Fix: after 1.8.1
Fix from $2,300 2023-11-03
Category Specific Rss Feed Subscription HIGH 8.8
CVE-2023-22691

Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions.

Fix: 2.2+
Fix from $1,950 2023-05-03
Wordpress Simple Paypal Shopping Cart MEDIUM 5.3
CVE-2023-1431

The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the p…

Fix: after 4.6.3
Fix from $1,600 2023-03-16