Vulnerability Name |
CVE
CWE
|
CWE |
Severity |
WordPress Plugin Nooz Cross-Site Scripting (1.6.0)
|
CVE-2023-25794
CWE-79
|
CWE-79
|
High
|
WordPress Plugin No Page Comment Multiple Vulnerabilities (1.1)
|
CWE-79
CWE-352
|
CWE-79
CWE-352
|
High
|
WordPress Plugin NOSpamPTI SQL Injection (2.1)
|
CVE-2013-5917
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Note Press SQL Injection (0.1.1)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Notices Ticker Cross-Site Request Forgery (5.0)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin Notices Ticker Cross-Site Scripting (6.1)
|
CVE-2021-38328
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Notification-Custom Notifications and Alerts for WordPress Cross-Site Scripting (7.2.4)
|
CVE-2021-39340
CWE-79
|
CWE-79
|
High
|
WordPress Plugin NotificationX-WooCommerce Sales Notification Popup, Custom & Live Sales Notification, FOMO, Social Proof, Announcement Banner & Sticky Notification Bar Cross-Site Request Forgery (1.8.2)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin NotificationX-WooCommerce Sales Notification Popup, Custom & Live Sales Notification, FOMO, Social Proof, Announcement Banner & Sticky Notification Bar SQL Injection (2.3.8)
|
CVE-2022-0349
CWE-89
|
CWE-89
|
High
|
WordPress Plugin NotificationX-WooCommerce Sales Notification Popup, Custom & Live Sales Notification, FOMO, Social Proof, Announcement Banner & Sticky Notification Bar SQL Injection (2.3.11)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin NotificationX-WooCommerce Sales Notification Popup, Custom & Live Sales Notification, FOMO, Social Proof, Announcement Banner & Sticky Notification Bar SQL Injection (2.8.2)
|
CVE-2024-1698
CWE-89
|
CWE-89
|
High
|
WordPress Plugin NS Utilities Unspecified Vulnerability (1.0)
|
|
|
High
|
WordPress Plugin Numbers generator and validator Multiple Unspecified Vulnerabilities (1.02)
|
|
|
High
|
WordPress Plugin O2Tweet Cross-Site Request Forgery (0.0.4)
|
CVE-2014-9338
CWE-352
|
CWE-352
|
High
|
WordPress Plugin OAuth client Single Sign On for WordPress (OAuth 2.0 SSO) Security Bypass (3.0.3)
|
CVE-2022-3119
CWE-287
|
CWE-287
|
High
|
WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) Cross-Site Scripting (6.20.2)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) Multiple Cross-Site Request Forgery Vulnerabilities (6.24.1)
|
CVE-2023-1092
CVE-2023-1093
CWE-352
|
CWE-352
|
High
|
WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) Security Bypass (6.22.5)
|
CVE-2022-2133
CWE-287
|
CWE-287
|
High
|
WordPress Plugin Occasions Cross-Site Request Forgery (1.0.4)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin Ocean Extra Cross-Site Request Forgery (1.6.5)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin Ocean Extra Cross-Site Scripting (1.9.4)
|
CVE-2021-25104
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Ocean Extra Cross-Site Scripting (2.1.1)
|
CVE-2023-23891
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Ocean Extra Multiple Vulnerabilities (2.1.2)
|
CVE-2023-0749
CVE-2023-24399
CWE-79
CWE-639
|
CWE-79
CWE-639
|
High
|
WordPress Plugin Ocean Extra PHP Object Injection (2.0.4)
|
CVE-2022-3374
CWE-915
|
CWE-915
|
High
|
WordPress Plugin Ocean Extra Security Bypass (1.5.8)
|
CVE-2019-16250
CWE-264
|
CWE-264
|
High
|
WordPress Plugin OdiHost Newsletter 'openstat.php' SQL Injection (1.0)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Official MailerLite Sign Up Forms Cross-Site Request Forgery (1.4.4)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin Official MailerLite Sign Up Forms SQL Injection (1.4.3)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin OG Tags Cross-Site Request Forgery (2.0.1)
|
CVE-2021-20831
CWE-352
|
CWE-352
|
High
|
WordPress Plugin Oi Yandex.Maps for WordPress Cross-Site Scripting (3.2.7)
|
CVE-2023-22721
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Oleggo LiveStream Cross-Site Scripting (0.2.6)
|
CVE-2014-4540
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Olevmedia Shortcodes Cross-Site Scripting (1.1.8)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Olevmedia Shortcodes Multiple Cross-Site Scripting Vulnerabilities (1.1.9)
|
CVE-2023-0168
CVE-2023-25798
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Olimometer SQL Injection (2.56)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin OMFG Mobile Pro Cross-Site Scripting (1.1.26)
|
CVE-2014-4541
CWE-79
|
CWE-79
|
High
|
WordPress Plugin OMGF-Host Google Fonts Locally Multiple Vulnerabilities (4.5.3)
|
CVE-2021-24638
CVE-2021-24639
CWE-22
CWE-264
|
CWE-22
CWE-264
|
High
|
WordPress Plugin Omni Secure Files 'upload.php' Arbitrary File Upload (0.1.13)
|
CWE-434
|
CWE-434
|
High
|
WordPress Plugin Onclick show popup Cross-Site Scripting (6.5)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin OneClick Chat to Order Cross-Site Scripting (1.0.4.1)
|
CVE-2022-4760
CWE-79
|
CWE-79
|
High
|
WordPress Plugin One Click SSL Cross-Site Request Forgery (1.4.6)
|
CVE-2019-15828
CWE-352
|
CWE-352
|
High
|
WordPress Plugin One Click Upsell Funnel for WooCommerce Unspecified Vulnerability (2.0.0)
|
|
|
High
|
WordPress Plugin OneLogin SAML SSO Security Bypass (2.2.0)
|
CWE-287
|
CWE-287
|
High
|
WordPress Plugin OneLogin SAML SSO Unspecified Vulnerability (2.1.8)
|
|
|
High
|
WordPress Plugin One page checkout and layouts for woocommerce Unspecified Vulnerability (2.7)
|
|
|
High
|
WordPress Plugin OnePress Social Locker Multiple Cross-Site Scripting Vulnerabilities (4.2.0)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin OnePress Social Locker Multiple Unspecified Vulnerabilities (4.2.5)
|
|
|
High
|
WordPress Plugin OneSignal-Web Push Notifications Cross-Site Scripting (1.17.7)
|
CVE-2019-15827
CWE-79
|
CWE-79
|
High
|
WordPress Plugin One User Avatar-User Profile Picture Multiple Vulnerabilities (2.3.6)
|
CVE-2021-24672
CVE-2021-24675
CWE-79
CWE-352
|
CWE-79
CWE-352
|
High
|
WordPress Plugin One User Avatar-User Profile Picture Unspecified Vulnerability (2.3.8)
|
|
|
High
|
WordPress Plugin Online Hotel Booking System Pro Cross-Site Scripting (1.1)
|
CVE-2020-15536
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Online Hotel Booking System Pro SQL Injection (1.0)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Online Lesson Booking Multiple Vulnerabilities (0.8.6)
|
CVE-2019-5972
CVE-2019-5973
CWE-79
CWE-352
|
CWE-79
CWE-352
|
High
|
WordPress Plugin On Page SEO + Social Live Chat (Formerly OPS) Cross-Site Scripting (1.0.1)
|
CVE-2021-38332
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Ooorl Cross-Site Scripting (1.0.0)
|
CVE-2014-4542
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Opal Estate Cross-Site Request Forgery (1.6.11)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin open-flash-chart-core Remote Code Execution (0.4)
|
CVE-2009-4140
CWE-434
|
CWE-434
|
High
|
WordPress Plugin Open Graph for Facebook, Google+ and Twitter Card Tags Cross-Site Scripting (2.2.4)
|
CVE-2018-0579
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Open Graph for Facebook, Google+ and Twitter Card Tags Unspecified Vulnerability (2.2.4.1)
|
|
|
High
|
WordPress Plugin OpenID Connect Generic Client Cross-Site Scripting (3.8.1)
|
CVE-2021-24214
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Opening Hours Cross-Site Scripting (2.3.0)
|
CVE-2022-4752
CWE-79
|
CWE-79
|
High
|
WordPress Plugin OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) Cross-Site Scripting (1.1.1)
|
CVE-2024-30450
CWE-79
|
CWE-79
|
High
|
WordPress Plugin OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) Supply Chain Attack [Polyfill.io] (1.1.2)
|
CWE-1372
|
CWE-1372
|
High
|
WordPress Plugin OPS Old Post Spinner 'ops_file' Parameter Local File Include (2.2.1)
|
CWE-22
|
CWE-22
|
High
|
WordPress Plugin Optimize images ALT Text (alt tag) & names for SEO using AI Cross-Site Request Forgery (2.0.7)
|
CVE-2022-4548
CWE-352
|
CWE-352
|
High
|
WordPress Plugin OptionTree Cross-Site Scripting (2.5.3)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin OptionTree Cross-Site Scripting (2.5.5)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin OptionTree PHP Object Injection (2.6.0)
|
CVE-2019-15319
CWE-915
|
CWE-915
|
High
|
WordPress Plugin OptionTree PHP Object Injection (2.7.2)
|
CVE-2019-15320
CVE-2019-15321
CWE-915
|
CWE-915
|
High
|
WordPress Plugin oQey Gallery 'gal_id' Parameter SQL Injection (0.4.8)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin oQey Gallery 'tbpv_domain' Parameter Cross-Site Scripting (0.2)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin oQey Headers 'oqey_settings.php' SQL Injection (0.3)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Orbit Fox by ThemeIsle Multiple Vulnerabilities (2.10.2)
|
CWE-79
CWE-264
|
CWE-79
CWE-264
|
High
|
WordPress Plugin Order Export & Order Import for WooCommerce Cross-Site Request Forgery (1.6.0)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin Order Export & Order Import for WooCommerce Information Disclosure (1.0.8)
|
CWE-200
|
CWE-200
|
High
|
WordPress Plugin Order XML File Export Import for WooCommerce Cross-Site Request Forgery (1.3.0)
|
CWE-352
|
CWE-352
|
High
|