Vulnerability Name CVE Severity
WordPress Plugin Highlight Cross-Site Scripting (0.9.2) CVE-2021-24591
WordPress Plugin Highlight Search Terms Cross-Site Scripting (1.3)
WordPress Plugin History Collection Arbitrary File Download (1.1.1)
WordPress Plugin Hitasoft FLV Player 'id' Parameter SQL Injection (1.1)
WordPress Plugin HK Exif Tags Cross-Site Scripting (1.11) CVE-2014-100007
WordPress Plugin HM Multiple Roles Security Bypass (1.2) CVE-2021-24602
WordPress Plugin HMS Testimonials Multiple Cross-Site Scripting and Cross-Site Request Forgery Vulnerabilities (2.0.10) CVE-2013-4240 CVE-2013-4241
WordPress Plugin Homepage SlideShow 'upload.php' Arbitrary File Upload (2.0)
WordPress Plugin Homepage SlideShow Arbitrary File Upload (2.3)
WordPress Plugin Hostel Cross-Site Scripting (1.1.3) CVE-2019-12345
WordPress Plugin Hot Files:File Sharing and Download Manager Cross-Site Scripting (1.0.0) CVE-2014-4588
WordPress Plugin Hotjar Connecticator Cross-Site Scripting (1.1.1) CVE-2021-24301
WordPress Plugin Hover Effects Builder Free Cross-Site Scripting (1.0.3)
WordPress Plugin How to Create an App for Android iPhone Easytouch Arbitrary File Upload (3.0) CVE-2017-1002000
WordPress Plugin Htaccess by BestWebSoft Cross-Site Request Forgery (1.8.1) CVE-2020-8658
WordPress Plugin Htaccess by BestWebSoft Cross-Site Scripting (1.4)
WordPress Plugin Htaccess by BestWebSoft Cross-Site Scripting (1.7.5) CVE-2017-2171 CVE-2017-2171 CVE-2017-18496
WordPress Plugin HT Mega-Absolute Addons for Elementor Page Builder Multiple Cross-Site Scripting Vulnerabilities (1.5.5) CVE-2021-24261
WordPress Plugin Html5 Audio Player-Audio Player for WordPress Cross-Site Scripting (2.1.2) CVE-2021-24412
WordPress Plugin HTML5 AV Manager for WordPress 'custom.php' Arbitrary File Upload (0.2.7)
WordPress Plugin HTML5 jQuery Audio Player Multiple Cross-Site Scripting Vulnerabilities (2.3)
WordPress Plugin HTML5 Lyrics Karaoke Player Cross-Site Scripting (1.06)
WordPress Plugin HTML5 Maps Cross-Site Request Forgery (1.6.5.6) CVE-2019-5983
WordPress Plugin HTML5 MP3 Player with Playlist Free Information Disclosure (2.6) CVE-2014-9177
WordPress Plugin HTML5 Video Player-Best WordPress Video Player and Block Cross-Site Scripting (2.5.18) CVE-2023-6485
WordPress Plugin HTML5 Video Player-Best WordPress Video Player and Block SQL Injection (2.5.24) CVE-2024-1061
WordPress Plugin HTML5 Video Player-Best WordPress Video Player and Block SQL Injection (2.5.26) CVE-2024-5522
WordPress Plugin HTML5 Video Player with Playlist Multiple Cross-Site Scripting Vulnerabilities (2.40) CVE-2014-4534
WordPress Plugin HT Slider Range for Amazon affiliates Cross-Site Scripting (1.1.5) CVE-2021-30134
WordPress Plugin http:BL Multiple Vulnerabilities (1.9.1)
WordPress Plugin HTTP Headers Multiple Vulnerabilities (1.9.1)
WordPress Plugin HubSpot All-In-One Marketing-Forms, Popups, Live Chat Cross-Site Scripting (7.5.5)
WordPress Plugin Hueman Addons Cross-Site Scripting (2.3.3) CVE-2022-4784
WordPress Plugin Human Presence Cross-Site Scripting (2.0.8)
WordPress Plugin Hungred Post Thumbnail 'hpt_file_upload.php' Arbitrary File Upload (2.1.9)
WordPress Plugin Hunk External Links Cross-Site Scripting (3.0.5)
WordPress Plugin Hupso Share Buttons for Twitter, Facebook & Google+ Multiple Unspecified Vulnerabilities (4.0.3)
WordPress Plugin Husker Portfolio Cross-Site Request Forgery (0.3)
WordPress Plugin HUSKY-Products Filter Professional for WooCommerce Multiple Vulnerabilities (1.1.4.2)
WordPress Plugin HUSKY-Products Filter Professional for WooCommerce Multiple Vulnerabilities (1.1.9) CVE-2018-8710 CVE-2018-8711
WordPress Plugin HUSKY-Products Filter Professional for WooCommerce SQL Injection (1.3.6) CVE-2024-6457
WordPress Plugin HUSKY-Products Filter Professional for WooCommerce Unspecified Vulnerability (1.2.6)
WordPress Plugin HUSKY-Products Filter Professional for WooCommerce Unspecified Vulnerability (1.2.6.1)
WordPress Plugin HUSKY-Products Filter Professional for WooCommerce Unspecified Vulnerability (1.2.6.2)
WordPress Plugin Hustle-Pop-Ups, Slide-ins and Email Opt-ins Cross-Site Scripting (4.7.0.5)
WordPress Plugin Hustle-Pop-Ups, Slide-ins and Email Opt-ins CSV Injection (6.0.7) CVE-2019-11872
WordPress Plugin HyperComments Arbitrary File Deletion (1.2.2)
WordPress Plugin IBPS Online Exam Multiple Vulnerabilities (1.0)
WordPress Plugin IBS Mappro Arbitrary File Download (0.6) CVE-2015-5472
WordPress Plugin Ibtana-Ecommerce Product Addons Cross-Site Scripting (0.2.3)
WordPress Plugin Icons with Links Widget Cross-Site Scripting (1.2) CVE-2021-24435
WordPress Plugin Icon Widget Cross-Site Scripting (1.2.6) CVE-2022-4763
WordPress Plugin iCopyright Toolbar 'icopyright_xml.php' SQL Injection (1.1.4)
WordPress Plugin ICustomizer Cross-Site Scripting (1.4.13) CVE-2021-24435
WordPress Plugin If>So Dynamic Content Unspecified Vulnerability (1.4.1)
WordPress Plugin iFlyChat-WordPress Chat Cross-Site Scripting (4.6.4) CVE-2021-24343
WordPress Plugin iFrame Admin Pages 'url' Parameter Cross-Site Scripting (0.1)
WordPress Plugin iframe Cross-Site Scripting (3.0)
WordPress Plugin iframe Cross-Site Scripting (4.0)
WordPress Plugin iframe Cross-Site Scripting (4.4) CVE-2020-12696
WordPress Plugin IGIT Posts Slider Widget 'src' Parameter Cross-Site Scripting (1.0)
WordPress Plugin IGIT Posts Slider Widget TimThumb Arbitrary File Upload (1.1) CVE-2011-4106
WordPress Plugin IGIT Related Posts With Thumb Image After Posts TimThumb Arbitrary File Upload (3.9.7) CVE-2011-4106
WordPress Plugin IgniteUp-Coming Soon and Maintenance Mode Multiple Vulnerabilities (3.4) CVE-2019-17234 CVE-2019-17235 CVE-2019-17236 CVE-2019-17237
WordPress Plugin IgnitionDeck Security Bypass (1.1.6)
WordPress Plugin iLive-Intelligent WordPress Live Chat Support Cross-Site Scripting (1.0.4)
WordPress Plugin ImageBoss-Images Up To 60% Smaller & CDN Cross-Site Scripting (3.0.4) CVE-2021-24888
WordPress Plugin ImageDrop 'ImageDrop.php' Blind SQL Injection (1.1.2)
WordPress Plugin Image Export Arbitrary File Download (1.1.0) CVE-2015-5609
WordPress Plugin Image Gallery-Responsive Photo Gallery Cross-Site Scripting (1.4.0)
WordPress Plugin Image Gallery-Responsive Photo Gallery Cross-Site Scripting (1.5.1)
WordPress Plugin Image Gallery-Responsive Photo Gallery Cross-Site Scripting (1.7.0)
WordPress Plugin Image Gallery-Responsive Photo Gallery Cross-Site Scripting (2.0.5)
WordPress Plugin Image Gallery-Responsive Photo Gallery Multiple Unspecified Vulnerabilities (1.9.58)
WordPress Plugin Image Gallery-Responsive Photo Gallery SQL Injection (1.0.6) CVE-2014-7153