Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Appointments CRITICAL 9.8
CVE-2017-20206

The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted …

Fix: after 2.2.1
Fix from $2,300 2025-10-18
Forminator Forms MEDIUM 6.4
CVE-2025-5341

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id…

Fix: 1.44.2+
Fix from $1,600 2025-06-05
Forminator Forms MEDIUM 5.4
CVE-2025-3487

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘li…

Fix: 1.42.1+
Fix from $1,600 2025-04-17
Forminator Forms MEDIUM 5.3
CVE-2025-3479

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and…

Fix: 1.42.1+
Fix from $1,600 2025-04-17
Forminator Forms MEDIUM 5.4
CVE-2025-0469

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sli…

Fix: 1.39.3+
Fix from $1,600 2025-02-27
Forminator Forms MEDIUM 6.1
CVE-2025-0470

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the …

Fix: 1.38.3+
Fix from $1,600 2025-01-31
Defender CRITICAL 9.8
CVE-2024-37444

Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Defender Security defender-security.This issue affects Defender …

Fix: 4.7.3+
Fix from $2,300 2024-11-01
Forminator Forms MEDIUM 5.3
CVE-2024-9700

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…

Fix: 1.36.1+
Fix from $1,600 2024-10-31
Forminator Forms HIGH 8.8
CVE-2024-10402

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing ca…

Fix: 1.36.0+
Fix from $1,950 2024-10-26
Hummingbird HIGH 8.8
CVE-2024-43117

Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affec…

Fix: 3.9.2+
Fix from $1,950 2024-08-26
Branda MEDIUM 5.3
CVE-2024-6554

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, an…

Fix: 3.4.19+
Fix from $1,600 2024-07-11
Branda MEDIUM 5.4
CVE-2024-5191

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_type…

Fix: 3.4.18+
Fix from $1,600 2024-06-21
Defender CRITICAL 9.8
CVE-2023-47189

Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect…

Fix: 4.2.1+
Fix from $2,300 2024-06-04
Defender MEDIUM 5.3
CVE-2024-25595

Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from …

Fix: 4.4.2+
Fix from $1,600 2024-05-17
Defender CRITICAL 9.8
CVE-2022-44581

Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This …

Fix: 3.3.3+
Fix from $2,300 2024-05-17
Hustle HIGH 8.6
CVE-2024-0368

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up…

Fix: 7.8.4+
Fix from $1,950 2024-03-13
Defender Security HIGH 7.5
CVE-2023-51490

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.T…

Fix: after 4.1.0
Fix from $1,950 2024-01-08
Smartcrawl HIGH 7.5
CVE-2023-5949

The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts' content.

Fix: 3.8.3+
Fix from $1,950 2023-12-18
Defender Security MEDIUM 5.3
CVE-2023-5089

The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing a…

Fix: 4.1.0+
Fix from $1,600 2023-10-16
Broken Link Checker MEDIUM 6.1
CVE-2015-10098

A vulnerability was found in Broken Link Checker Plugin up to 1.10.5 on WordPress. It has been rated as problematic. Affected by this issue is the fu…

Fix: 1.10.6+
Fix from $1,600 2023-04-08
Smush Image Compression And Optimization MEDIUM 6.1
CVE-2022-1009

The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back in an admin page when upload…

Fix: 3.9.9+
Fix from $1,600 2022-05-30
Custom Sidebars HIGH 8.8
CVE-2017-18510

The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.

Fix: 3.1.0+
Fix from $1,950 2019-08-14
Custom Sidebars HIGH 8.8
CVE-2017-18511

The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.

Fix: 3.0.8.1+
Fix from $1,950 2019-08-14
Smush Image Compression And Optimization HIGH 7.5
CVE-2017-15079

The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal.

Fix: after 2.7.5
Fix from $1,950 2017-10-06