Vulnerability Name |
CVE
CWE
|
CWE |
Severity |
WordPress Plugin WP Symposium Open Redirect (13.12)
|
CWE-601
|
CWE-601
|
High
|
WordPress Plugin WP Symposium Pro Social Network Cross-Site Scripting (16.01)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP Symposium Pro Social Network Multiple Vulnerabilities (15.12)
|
CWE-79
CWE-352
|
CWE-79
CWE-352
|
High
|
WordPress Plugin WP Symposium SQL Injection (15.1)
|
CVE-2015-3325
CWE-89
|
CWE-89
|
High
|
WordPress Plugin WP Symposium SQL Injection (15.5.1)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin WP Symposium Toolbar Unspecified Vulnerability (0.26.0)
|
|
|
High
|
WordPress Plugin WP Table Builder-WordPress Table Cross-Site Scripting (1.3.9)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP Table Builder-WordPress Table Cross-Site Scripting (1.4.6)
|
CVE-2022-46852
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP Table Builder-WordPress Table Security Bypass (1.3.15)
|
CWE-862
|
CWE-862
|
High
|
WordPress Plugin WP Taxonomy Import Cross-Site Scripting (1.0.4)
|
CVE-2022-2669
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP Telegram (Auto Post and Notifications) Unspecified Vulnerability (2.1.8)
|
|
|
High
|
WordPress Plugin wptf-image-gallery Arbitrary File Download (1.0.3)
|
CVE-2015-1000007
CWE-538
|
CWE-538
|
High
|
WordPress Plugin WP TFeed includes Backdoor [Only if downloaded via the vendor website] (1.6.7)
|
CVE-2021-24867
CWE-912
|
CWE-912
|
High
|
WordPress Plugin WP to Twitter Authorization Bypass (2.9.3)
|
CWE-264
|
CWE-264
|
High
|
WordPress Plugin WP to Twitter Cross-Site Request Forgery (3.2.9)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin WP to Twitter Cross-Site Scripting (3.0.5)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP to Twitter Security Bypass (3.2.19)
|
CWE-264
|
CWE-264
|
High
|
WordPress Plugin WPtouch 'wptouch_redirect' Parameter URI Redirection (1.9.32)
|
CWE-601
|
CWE-601
|
High
|
WordPress Plugin WPtouch 'wptouch_settings' Parameter Cross-Site Scripting (1.9.20)
|
CVE-2010-4779
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WPtouch Arbitrary File Upload (3.4.6)
|
CWE-20
|
CWE-20
|
High
|
WordPress Plugin WPtouch Backdoor (1.9.28)
|
CWE-95
|
CWE-95
|
High
|
WordPress Plugin WPtouch Cross-Site Request Forgery (1.9.31)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin WPtouch Cross-Site Scripting (3.7.5.3)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WPtouch Cross-Site Scripting (4.3.42)
|
CWE-79
|
CWE-79
|
High
|
WordPress plugin WPtouch insecure nonce generation
|
CWE-287
|
CWE-287
|
High
|
WordPress Plugin WPtouch Multiple Cross-Site Scripting Vulnerabilities (3.7.3)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WPtouch Open Redirect (3.4.9)
|
CWE-601
|
CWE-601
|
High
|
WordPress Plugin WPtouch Security Bypass (3.4.2)
|
CWE-264
|
CWE-264
|
High
|
WordPress Plugin WP Travel-Best Travel Booking, Tour Management Engine Cross-Site Request Forgery (4.4.6)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin WP TripAdvisor Review Slider Cross-Site Scripting (11.8)
|
CVE-2023-6037
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP TripAdvisor Review Slider SQL Injection (10.7)
|
CVE-2023-0261
CWE-89
|
CWE-89
|
High
|
WordPress Plugin WP TripAdvisor Review Slider SQL Injection (12.6)
|
CVE-2024-35630
CWE-89
|
CWE-89
|
High
|
WordPress Plugin WP ULike Cross-Site Scripting (3.1)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP ULike Multiple Vulnerabilities (3.1)
|
CWE-264
CWE-352
|
CWE-264
CWE-352
|
High
|
WordPress Plugin WP Ultimate Email Marketer Multiple Vulnerabilities (1.1.0)
|
CVE-2013-3263
CVE-2013-3264
CVE-2014-4600
CWE-79
CWE-264
|
CWE-79
CWE-264
|
High
|
WordPress Plugin WP Ultimate Exporter Cross-Site Scripting (1.0)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP Ultimate Exporter SQL Injection (1.1)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin WP Ultimate Recipe Cross-Site Scripting (3.12.6)
|
CVE-2019-15836
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP Unique Article Header Image Cross-Site Request Forgery (1.0)
|
CVE-2014-9400
CWE-352
|
CWE-352
|
High
|
WordPress Plugin WP Upload Restriction Multiple Vulnerabilities (2.2.3)
|
CVE-2021-34625
CVE-2021-34626
CVE-2021-34627
CWE-79
CWE-264
|
CWE-79
CWE-264
|
High
|
WordPress Plugin WPUpper Share Buttons Cross-Site Scripting (3.42)
|
CVE-2022-3838
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP User-Custom Registration Forms, Login and User Profile Multiple Vulnerabilities (7.0)
|
CVE-2022-4049
CVE-2022-4519
CWE-79
CWE-89
|
CWE-79
CWE-89
|
High
|
WordPress Plugin WP User Frontend-Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Arbitrary File Upload (2.3.10)
|
CWE-434
|
CWE-434
|
High
|
WordPress Plugin WP User Frontend-Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Supply Chain Attack [Polyfill.io] (4.0.7)
|
CWE-1372
|
CWE-1372
|
High
|
WordPress Plugin WP User Groups Cross-Site Request Forgery (2.0.0)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin WP User Manager-User Profile Builder & Membership Security Bypass (2.6.2)
|
CWE-639
|
CWE-639
|
High
|
WordPress Plugin WP Users Exporter CSV Injection (1.4.2)
|
CVE-2022-3026
CWE-1236
|
CWE-1236
|
High
|
WordPress Plugin WP User Switch Security Bypass (1.0.2)
|
CVE-2023-2546
CWE-287
|
CWE-287
|
High
|
WordPress Plugin WP Vault Local File Inclusion (0.8.6.6)
|
CWE-22
|
CWE-22
|
High
|
WordPress Plugin WP Video Lightbox Cross-Site Scripting (1.7.4)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP Video Lightbox Cross-Site Scripting (1.9.2)
|
CVE-2021-24665
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP Visitor Statistics (Real Time Traffic) Cross-Site Scripting (6.4)
|
CVE-2022-4656
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP Visitor Statistics (Real Time Traffic) Security Bypass (5.4)
|
CVE-2021-25042
CWE-862
|
CWE-862
|
High
|
WordPress Plugin WP Visitor Statistics (Real Time Traffic) SQL Injection (4.7)
|
CVE-2021-24750
CWE-89
|
CWE-89
|
High
|
WordPress Plugin WP Visitor Statistics (Real Time Traffic) SQL Injection (5.5)
|
CVE-2022-0410
CWE-89
|
CWE-89
|
High
|
WordPress Plugin WP Visitor Statistics (Real Time Traffic) SQL Injection (5.7)
|
CVE-2022-33965
CWE-89
|
CWE-89
|
High
|
WordPress Plugin WP Visitor Statistics (Real Time Traffic) SQL Injection (6.8.1)
|
CVE-2023-0600
CWE-89
|
CWE-89
|
High
|
WordPress Plugin WP Visitor Statistics (Real Time Traffic) Unspecified Vulnerability (4.8)
|
|
|
High
|
WordPress Plugin WP VR-360 Panorama and Virtual Tour Builder For WordPress Cross-Site Request Forgery (8.2.7)
|
CVE-2023-25708
CWE-352
|
CWE-352
|
High
|
WordPress Plugin WP VR-360 Panorama and Virtual Tour Builder For WordPress Cross-Site Scripting (8.2.6)
|
CVE-2023-0174
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP w3all phpBB Multiple Unspecified Vulnerabilities (1.6.3)
|
|
|
High
|
WordPress Plugin WP Web Scraper Unspecified Vulnerability (2.4)
|
|
|
High
|
WordPress Plugin WP Whois Domain Cross-Site Scripting (1.0.0)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP Widget Cache Cross-Site Scripting (0.26)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP with Spritz Local/Remote File Inclusion (1.0)
|
CWE-98
|
CWE-98
|
High
|
WordPress Plugin WP Yelp Review Slider SQL Injection (7.0)
|
CVE-2023-0263
CWE-89
|
CWE-89
|
High
|
WordPress Plugin WP YouTube Live Cross-Site Scripting (1.7.21)
|
CVE-2022-1187
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WP YouTube Live Cross-Site Scripting (1.8.2)
|
CVE-2022-1334
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WPZOOM Portfolio Cross-Site Scripting (1.2.1)
|
CVE-2022-4789
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Wrapper Link Elementor Malicious Code (1.0.3)
|
CVE-2024-6297
CWE-506
|
CWE-506
|
High
|
WordPress Plugin WR ContactForm SQL Injection (1.1.9)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin wSecure Lite Remote Code Execution (2.3)
|
CVE-2016-10960
CWE-94
|
CWE-94
|
High
|
WordPress Plugin WTI Like Post Cross-Site Scripting (1.4.4)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin WTI Like Post SQL Injection (1.4.2)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Wu-Rating Cross-Site Scripting (1.0 12319)
|
CVE-2014-4601
CWE-79
|
CWE-79
|
High
|