Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Advanced Google Recaptcha MEDIUM 5.3
CVE-2025-1262

The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it possible fo…

Fix: 1.2.8+
Fix from $1,600 2025-02-25
Minimal Coming Soon \& Maintenance Mode MEDIUM 5.4
CVE-2024-5087

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Fix: 2.39+
Fix from $1,600 2024-06-08
Wp Reset MEDIUM 5.9
CVE-2023-6799

The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc…

Fix: 2.01+
Fix from $1,600 2024-04-09
Wp Login Lockdown MEDIUM 5.4
CVE-2024-1340

The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ge…

Fix: 2.09+
Fix from $1,600 2024-02-29
Minimal Coming Soon \& Maintenance Mode MEDIUM 5.3
CVE-2024-1075

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions u…

Fix: after 2.37
Fix from $1,600 2024-02-05
Wp Login Lockdown HIGH 7.2
CVE-2023-50837

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFactory Ltd Login Lockdown – Protect Login F…

Fix: after 2.06
Fix from $1,950 2023-12-29
Guest Author MEDIUM 5.4
CVE-2023-49747

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebFactory Ltd Guest Author allows Stored XSS.T…

Fix: after 2.3
Fix from $1,600 2023-12-15
External Links In New Window \/ New Tab MEDIUM 6.5
CVE-2022-1583

The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites a…

Fix: 1.43+
Fix from $1,600 2022-05-30
External Links In New Window \/ New Tab MEDIUM 6.1
CVE-2022-1582

The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, whic…

Fix: 1.43+
Fix from $1,600 2022-05-30
Wp Reset Pro HIGH 8.8
CVE-2021-36908

Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions.

Fix: 5.99+
Fix from $1,950 2021-11-18
Wp Reset Pro HIGH 8.1
CVE-2021-36909

Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the enti…

Fix: after 5.98
Fix from $1,950 2021-11-18
Wp Reset MEDIUM 5.4
CVE-2021-24424

The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a sn…

Fix: 1.90+
Fix from $1,600 2021-07-12
301 Redirects HIGH 7.2
CVE-2021-24142

Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column wh…

Fix: 2.51+
Fix from $1,950 2021-03-18
Wp Database Reset CRITICAL 9.1
CVE-2020-7048EPSS 23%

The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the …

Fix: after 3.1
Fix from $2,300 2020-01-16
Wp Database Reset HIGH 8.8
CVE-2020-7047

The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a …

Fix: after 3.1
Fix from $1,950 2020-01-16
Minimal Coming Soon \& Maintenance Mode HIGH 7.6
CVE-2020-6168

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disab…

Fix: after 2.10
Fix from $1,950 2020-01-09
Minimal Coming Soon \& Maintenance Mode MEDIUM 5.4
CVE-2020-6166

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings …

Fix: after 2.15
Fix from $1,600 2020-01-09
Minimal Coming Soon \& Maintenance Mode HIGH 8.8
CVE-2020-6167

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, mod…

Fix: after 2.10
Fix from $1,950 2020-01-09
301 Redirects CRITICAL 9.0
CVE-2019-19915

The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or i…

Fix: 2.45+
Fix from $2,300 2019-12-19