Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Modal Window MEDIUM 5.4
CVE-2025-0897

The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode…

Fix: 6.1.6+
Fix from $1,600 2025-02-20
Modal Window HIGH 8.8
CVE-2025-24717

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal W…

Fix: 6.1.5+
Fix from $1,950 2025-01-24
Counter Box MEDIUM 5.4
CVE-2025-24715

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Counter Box counter-box allows Cross Site Request Forgery.This issue affects Counter B…

Fix: 2.0.6+
Fix from $1,600 2025-01-24
Viral Signup CRITICAL 9.8
CVE-2024-6926

The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX actio…

Fix: after 2.1
Fix from $2,300 2024-09-04
Modal Window MEDIUM 5.4
CVE-2024-43346

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wow-Company Modal Window allows Stored X…

Fix: 6.0.4+
Fix from $1,600 2024-08-18
Easy Digital Downloads CRITICAL 9.8
CVE-2024-35629

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Dow…

Fix: after 1.0.2
Fix from $2,300 2024-06-04
Herd Effects MEDIUM 6.1
CVE-2024-3478

The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins …

Fix: 5.2.7+
Fix from $1,600 2024-05-02
Counter Box MEDIUM 5.2
CVE-2024-3481

The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins p…

Fix: 1.2.4+
Fix from $1,600 2024-05-02
Wow Skype Buttons HIGH 8.8
CVE-2024-3474

The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in adm…

Fix: 4.0.4+
Fix from $1,950 2024-05-02
Side Menu Lite HIGH 8.8
CVE-2024-3476

The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admin…

Fix: 4.2.1+
Fix from $1,950 2024-05-02
Sticky Buttons HIGH 7.5
CVE-2024-3475

The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admin…

Fix: 3.2.4+
Fix from $1,950 2024-05-02
Modal Window MEDIUM 5.9
CVE-2024-3472

The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a l…

Fix: 5.3.10+
Fix from $1,600 2024-05-02
Modal Window MEDIUM 5.4
CVE-2024-2457

The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all v…

Fix: 5.3.9+
Fix from $1,600 2024-04-09
Floating Button HIGH 8.8
CVE-2023-52149

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0.

Fix: after 6.0
Fix from $1,950 2024-01-05
Button Generator HIGH 8.8
CVE-2023-49155

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder.This issue affects Button Generator – easily …

Fix: after 2.3.8
Fix from $1,950 2023-12-18
Side Menu Lite HIGH 8.8
CVE-2023-27418

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite – add sticky fixed buttons plugin <= 4.0 versions.

Fix: after 4.0
Fix from $1,950 2023-11-12
Modal Window MEDIUM 5.4
CVE-2023-5161

The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 5.3.5 due to insu…

Fix: after 5.3.5
Fix from $1,600 2023-09-27
Button Generator MEDIUM 6.5
CVE-2023-25443

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.5 versions.

Fix: after 2.3.5
Fix from $1,600 2023-07-11
Bubble Menu MEDIUM 6.1
CVE-2023-2362

The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator B…

Fix: 1.2.2 / 1.5.1+
Fix from $1,600 2023-06-12
Bubble Menu MEDIUM 5.4
CVE-2023-23984

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu plugin <= 3.0.1 leading to form deletion.

Fix: 3.0.2+
Fix from $1,600 2023-03-01
Wp Coder MEDIUM 6.5
CVE-2022-2388

The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to…

Fix: 2.5.3+
Fix from $1,600 2022-08-22
Counter Box HIGH 8.8
CVE-2022-2245

The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a …

Fix: 1.2.1+
Fix from $1,950 2022-08-01
Hover Effects HIGH 7.2
CVE-2022-29447

Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.

Fix: after 2.1
Fix from $1,950 2022-05-20
Counter Box HIGH 7.2
CVE-2022-29446

Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.

Fix: after 1.1.1
Fix from $1,950 2022-05-19
Wow Countdowns HIGH 7.2
CVE-2021-25064

The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an…

Fix: after 3.1.2
Fix from $1,950 2022-03-28
Modal Window HIGH 8.8
CVE-2021-25051

The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well …

Fix: 5.2.2+
Fix from $1,950 2022-01-10
Button Generator HIGH 8.8
CVE-2021-25052

The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as w…

Fix: 2.3.3+
Fix from $1,950 2022-01-10
Wp Coder HIGH 8.8
CVE-2021-25053

The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as w…

Fix: 2.5.2+
Fix from $1,950 2022-01-10
Wpcalc HIGH 8.8
CVE-2021-25054

The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authentic…

Fix: after 2.1
Fix from $1,950 2022-01-10
Wow Forms HIGH 7.2
CVE-2021-24628

The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL statement, when deleting a fo…

Fix: after 3.1.3
Fix from $1,950 2021-11-08