Vulnerability Name CVE Severity
WordPress Plugin Nooz Cross-Site Scripting (1.6.0) CVE-2023-25794
WordPress Plugin No Page Comment Multiple Vulnerabilities (1.1)
WordPress Plugin NOSpamPTI SQL Injection (2.1) CVE-2013-5917
WordPress Plugin Note Press SQL Injection (0.1.1)
WordPress Plugin Notices Ticker Cross-Site Request Forgery (5.0)
WordPress Plugin Notices Ticker Cross-Site Scripting (6.1) CVE-2021-38328
WordPress Plugin Notification-Custom Notifications and Alerts for WordPress Cross-Site Scripting (7.2.4) CVE-2021-39340
WordPress Plugin NotificationX-WooCommerce Sales Notification Popup, Custom & Live Sales Notification, FOMO, Social Proof, Announcement Banner & Sticky Notification Bar Cross-Site Request Forgery (1.8.2)
WordPress Plugin NotificationX-WooCommerce Sales Notification Popup, Custom & Live Sales Notification, FOMO, Social Proof, Announcement Banner & Sticky Notification Bar SQL Injection (2.3.8) CVE-2022-0349
WordPress Plugin NotificationX-WooCommerce Sales Notification Popup, Custom & Live Sales Notification, FOMO, Social Proof, Announcement Banner & Sticky Notification Bar SQL Injection (2.3.11)
WordPress Plugin NotificationX-WooCommerce Sales Notification Popup, Custom & Live Sales Notification, FOMO, Social Proof, Announcement Banner & Sticky Notification Bar SQL Injection (2.8.2) CVE-2024-1698
WordPress Plugin NS Utilities Unspecified Vulnerability (1.0)
WordPress Plugin Numbers generator and validator Multiple Unspecified Vulnerabilities (1.02)
WordPress Plugin O2Tweet Cross-Site Request Forgery (0.0.4) CVE-2014-9338
WordPress Plugin OAuth client Single Sign On for WordPress (OAuth 2.0 SSO) Security Bypass (3.0.3) CVE-2022-3119
WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) Cross-Site Scripting (6.20.2)
WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) Multiple Cross-Site Request Forgery Vulnerabilities (6.24.1) CVE-2023-1092 CVE-2023-1093
WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) Security Bypass (6.22.5) CVE-2022-2133
WordPress Plugin Occasions Cross-Site Request Forgery (1.0.4)
WordPress Plugin Ocean Extra Cross-Site Request Forgery (1.6.5)
WordPress Plugin Ocean Extra Cross-Site Scripting (1.9.4) CVE-2021-25104
WordPress Plugin Ocean Extra Cross-Site Scripting (2.1.1) CVE-2023-23891
WordPress Plugin Ocean Extra Multiple Vulnerabilities (2.1.2) CVE-2023-0749 CVE-2023-24399
WordPress Plugin Ocean Extra PHP Object Injection (2.0.4) CVE-2022-3374
WordPress Plugin Ocean Extra Security Bypass (1.5.8) CVE-2019-16250
WordPress Plugin OdiHost Newsletter 'openstat.php' SQL Injection (1.0)
WordPress Plugin Official MailerLite Sign Up Forms Cross-Site Request Forgery (1.4.4)
WordPress Plugin Official MailerLite Sign Up Forms SQL Injection (1.4.3)
WordPress Plugin OG Tags Cross-Site Request Forgery (2.0.1) CVE-2021-20831
WordPress Plugin Oi Yandex.Maps for WordPress Cross-Site Scripting (3.2.7) CVE-2023-22721
WordPress Plugin Oleggo LiveStream Cross-Site Scripting (0.2.6) CVE-2014-4540
WordPress Plugin Olevmedia Shortcodes Cross-Site Scripting (1.1.8)
WordPress Plugin Olevmedia Shortcodes Multiple Cross-Site Scripting Vulnerabilities (1.1.9) CVE-2023-0168 CVE-2023-25798
WordPress Plugin Olimometer SQL Injection (2.56)
WordPress Plugin OMFG Mobile Pro Cross-Site Scripting (1.1.26) CVE-2014-4541
WordPress Plugin OMGF-Host Google Fonts Locally Multiple Vulnerabilities (4.5.3) CVE-2021-24638 CVE-2021-24639
WordPress Plugin Omni Secure Files 'upload.php' Arbitrary File Upload (0.1.13)
WordPress Plugin Onclick show popup Cross-Site Scripting (6.5)
WordPress Plugin OneClick Chat to Order Cross-Site Scripting (1.0.4.1) CVE-2022-4760
WordPress Plugin One Click SSL Cross-Site Request Forgery (1.4.6) CVE-2019-15828
WordPress Plugin One Click Upsell Funnel for WooCommerce Unspecified Vulnerability (2.0.0)
WordPress Plugin OneLogin SAML SSO Security Bypass (2.2.0)
WordPress Plugin OneLogin SAML SSO Unspecified Vulnerability (2.1.8)
WordPress Plugin One page checkout and layouts for woocommerce Unspecified Vulnerability (2.7)
WordPress Plugin OnePress Social Locker Multiple Cross-Site Scripting Vulnerabilities (4.2.0)
WordPress Plugin OnePress Social Locker Multiple Unspecified Vulnerabilities (4.2.5)
WordPress Plugin OneSignal-Web Push Notifications Cross-Site Scripting (1.17.7) CVE-2019-15827
WordPress Plugin One User Avatar-User Profile Picture Multiple Vulnerabilities (2.3.6) CVE-2021-24672 CVE-2021-24675
WordPress Plugin One User Avatar-User Profile Picture Unspecified Vulnerability (2.3.8)
WordPress Plugin Online Hotel Booking System Pro Cross-Site Scripting (1.1) CVE-2020-15536
WordPress Plugin Online Hotel Booking System Pro SQL Injection (1.0)
WordPress Plugin Online Lesson Booking Multiple Vulnerabilities (0.8.6) CVE-2019-5972 CVE-2019-5973
WordPress Plugin On Page SEO + Social Live Chat (Formerly OPS) Cross-Site Scripting (1.0.1) CVE-2021-38332
WordPress Plugin Ooorl Cross-Site Scripting (1.0.0) CVE-2014-4542
WordPress Plugin Opal Estate Cross-Site Request Forgery (1.6.11)
WordPress Plugin open-flash-chart-core Remote Code Execution (0.4) CVE-2009-4140
WordPress Plugin Open Graph for Facebook, Google+ and Twitter Card Tags Cross-Site Scripting (2.2.4) CVE-2018-0579
WordPress Plugin Open Graph for Facebook, Google+ and Twitter Card Tags Unspecified Vulnerability (2.2.4.1)
WordPress Plugin OpenID Connect Generic Client Cross-Site Scripting (3.8.1) CVE-2021-24214
WordPress Plugin Opening Hours Cross-Site Scripting (2.3.0) CVE-2022-4752
WordPress Plugin OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) Cross-Site Scripting (1.1.1) CVE-2024-30450
WordPress Plugin OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) Supply Chain Attack [Polyfill.io] (1.1.2)
WordPress Plugin OPS Old Post Spinner 'ops_file' Parameter Local File Include (2.2.1)
WordPress Plugin Optimize images ALT Text (alt tag) & names for SEO using AI Cross-Site Request Forgery (2.0.7) CVE-2022-4548
WordPress Plugin OptionTree Cross-Site Scripting (2.5.3)
WordPress Plugin OptionTree Cross-Site Scripting (2.5.5)
WordPress Plugin OptionTree PHP Object Injection (2.6.0) CVE-2019-15319
WordPress Plugin OptionTree PHP Object Injection (2.7.2) CVE-2019-15320 CVE-2019-15321
WordPress Plugin oQey Gallery 'gal_id' Parameter SQL Injection (0.4.8)
WordPress Plugin oQey Gallery 'tbpv_domain' Parameter Cross-Site Scripting (0.2)
WordPress Plugin oQey Headers 'oqey_settings.php' SQL Injection (0.3)
WordPress Plugin Orbit Fox by ThemeIsle Multiple Vulnerabilities (2.10.2)
WordPress Plugin Order Export & Order Import for WooCommerce Cross-Site Request Forgery (1.6.0)
WordPress Plugin Order Export & Order Import for WooCommerce Information Disclosure (1.0.8)
WordPress Plugin Order XML File Export Import for WooCommerce Cross-Site Request Forgery (1.3.0)