Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Sms CRITICAL 9.8
CVE-2024-43331

Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.

Fix: 6.9.4+
Fix from $2,300 2024-08-22
Wp Sms HIGH 8.8
CVE-2024-30454

Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.

Fix: 6.6.3+
Fix from $1,950 2024-03-29
Wp Sms MEDIUM 5.4
CVE-2024-25920

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue …

Fix: 6.4+
Fix from $1,600 2024-03-27
Wp Sms MEDIUM 6.1
CVE-2024-24881

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS – Messaging & SMS Notificatio…

Fix: 6.5.3+
Fix from $1,600 2024-02-08
Wp Sms HIGH 7.5
CVE-2023-27447

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommer…

Fix: 6.0.4.1+
Fix from $1,950 2023-12-28
Wp Sms MEDIUM 6.1
CVE-2023-32742

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in VeronaLabs WP SMS plugin <= 6.1.4 versions.

Fix: after 6.1.4
Fix from $1,600 2023-08-30
Wp Statistics HIGH 8.8
CVE-2023-0955

The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. B…

Fix: 14.0+
Fix from $1,950 2023-03-27
Wp Statistics HIGH 8.8
CVE-2022-38074

SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.

Fix: 13.2.11+
Fix from $1,950 2023-03-13
Wp Statistics MEDIUM 6.5
CVE-2021-4333

The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing o…

Fix: after 13.1.1
Fix from $1,600 2023-03-07
Wp Statistics HIGH 8.8
CVE-2022-4230EPSS 36%

The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks.…

Fix: 13.2.9+
Fix from $1,950 2023-01-23
Wp Statistics MEDIUM 6.1
CVE-2022-27231

Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiti…

Fix: 13.2.0+
Fix from $1,600 2022-06-13
Wp Statistics MEDIUM 6.1
CVE-2022-1005

The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading …

Fix: 13.2.2+
Fix from $1,600 2022-06-08
Wp Statistics CRITICAL 9.8
CVE-2022-25148EPSS 81%

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter …

Fix: after 13.1.5
Fix from $2,300 2022-02-24
Wp Statistics HIGH 7.5
CVE-2022-25149EPSS 78%

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the …

Fix: after 13.1.5
Fix from $1,950 2022-02-24
Wp Statistics MEDIUM 6.1
CVE-2022-25305EPSS 79%

The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in t…

Fix: after 13.1.5
Fix from $1,600 2022-02-24
Wp Statistics MEDIUM 6.1
CVE-2022-25306

The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found…

Fix: after 13.1.5
Fix from $1,600 2022-02-24
Wp Statistics MEDIUM 6.1
CVE-2022-25307

The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter foun…

Fix: after 13.1.5
Fix from $1,600 2022-02-24
Wp Statistics HIGH 7.5
CVE-2022-0651EPSS 32%

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type paramete…

Fix: after 13.1.5
Fix from $1,950 2022-02-24
Wp Statistics HIGH 7.5
CVE-2022-0513EPSS 53%

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter…

Fix: after 13.1.4
Fix from $1,950 2022-02-16
Wp Sms MEDIUM 5.4
CVE-2021-24561

The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to …

Fix: 5.4.13+
Fix from $1,600 2021-08-23
Wp Statistics HIGH 7.5
CVE-2021-24340EPSS 30%

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not firs…

Fix: 13.0.8+
Fix from $1,950 2021-06-07
Wp Statistics CRITICAL 9.8
CVE-2017-18515

The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.

Fix: 12.0.8+
Fix from $2,300 2019-08-14
Wp Statistics CRITICAL 9.8
CVE-2019-13275

An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use…

Fix: after 12.6.6
Fix from $2,300 2019-07-04
Wp Statistics MEDIUM 5.4
CVE-2019-12566

The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with th…

Fix: after 12.6.5
Fix from $1,600 2019-06-03
Wp Statistics MEDIUM 6.1
CVE-2019-10864

The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer head…

Fix: after 12.6.2
Fix from $1,600 2019-04-23
Wp Statistics MEDIUM 6.1
CVE-2018-1000556

WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An…

Fix: 12.0.6+
Fix from $1,600 2018-06-26