Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Custom Product Tabs For Woocommerce HIGH 7.2
CVE-2024-11465

The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via de…

Fix: after 1.8.5
Fix from $1,950 2025-01-07
Easy Forms For Mailchimp MEDIUM 6.1
CVE-2023-23900

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in YIKES, Inc. Easy Forms for Mailchimp plugin <= 6.8.8 versions.

Fix: after 6.8.8
Fix from $1,600 2023-08-10
Easy Forms For Mailchimp MEDIUM 6.1
CVE-2023-2518

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the de…

Fix: after 6.8.8
Fix from $1,600 2023-05-30
Easy Forms For Mailchimp MEDIUM 6.1
CVE-2023-1324

The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, …

Fix: 6.8.8+
Fix from $1,600 2023-04-24
Easy Forms For Mailchimp MEDIUM 5.4
CVE-2023-1325

The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back …

Fix: 6.8.7+
Fix from $1,600 2023-04-17
Custom Product Tabs For Woocommerce MEDIUM 5.3
CVE-2022-28666

Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-togg…

Fix: after 1.7.7
Fix from $1,600 2022-07-21
Easy Forms For Mailchimp MEDIUM 6.1
CVE-2021-24985

The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting th…

Fix: 6.8.6+
Fix from $1,600 2022-01-24
Easy Forms For Mailchimp CRITICAL 9.8
CVE-2019-15318

The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.

Fix: 6.5.3+
Fix from $2,300 2019-08-22