Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Genesis Blocks MEDIUM 6.8
CVE-2024-3901

The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for u…

Fix: 3.1.4+
Fix from $1,600 2025-05-15
Advanced Custom Fields MEDIUM 6.1
CVE-2024-45429

Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earl…

Fix: after 6.3.5
Fix from $1,600 2024-09-04
Genesis Blocks MEDIUM 5.4
CVE-2024-3563

The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions up to, and includ…

Fix: 3.1.4+
Fix from $1,600 2024-07-09
Genesis Blocks MEDIUM 6.8
CVE-2024-2761

The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least con…

Fix: 3.1.3+
Fix from $1,600 2024-04-19
Better Search Replace HIGH 8.8
CVE-2023-6933EPSS 68%

The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization …

Fix: 1.4.5+
Fix from $1,950 2024-02-05
Wpgraphql MEDIUM 5.3
CVE-2022-1563

The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values…

Fix: after 0.12.3
Fix from $1,600 2024-01-16
Wpgraphql MEDIUM 6.5
CVE-2023-23684

Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.

Fix: after 1.14.5
Fix from $1,600 2023-11-13
Php Compatibility Checker HIGH 8.8
CVE-2023-24421

Cross-Site Request Forgery (CSRF) vulnerability in WP Engine PHP Compatibility Checker plugin <= 1.5.2 versions.

Fix: 1.6.0+
Fix from $1,950 2023-07-11
Wpgraphql CRITICAL 9.8
CVE-2019-9879EPSS 47%

The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are al…

No fix yet
Fix from $2,300 2019-06-10
Wpgraphql CRITICAL 9.1
CVE-2019-9880EPSS 35%

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attack…

No fix yet
Fix from $2,300 2019-06-10
Wpgraphql MEDIUM 5.3
CVE-2019-9881EPSS 19%

The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow…

No fix yet
Fix from $1,600 2019-06-10