Vulnerability Name |
CVE
CWE
|
CWE |
Severity |
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership Security Bypass (1.3.75)
|
CWE-264
|
CWE-264
|
High
|
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership Security Bypass (1.3.83)
|
CWE-264
|
CWE-264
|
High
|
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership Security Bypass (2.1.2)
|
CVE-2020-6859
CWE-264
|
CWE-264
|
High
|
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership SQL Injection (2.8.2)
|
CVE-2024-1071
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership Unspecified Vulnerability (2.0.40)
|
|
|
High
|
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership Unspecified Vulnerability (2.1.3)
|
|
|
High
|
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership Unspecified Vulnerability (2.1.12)
|
CVE-2020-36170
|
|
High
|
WordPress Plugin Ultimate Membership Pro Cross-Site Request Forgery (8.6.1)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin Ultimate Membership Pro Cross-Site Request Forgery (8.6.2)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin Ultimate Membership Pro Security Bypass (8.6)
|
CWE-264
|
CWE-264
|
High
|
WordPress Plugin Ultimate Membership Pro SQL Injection (3.3)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Ultimate Membership Pro SQL Injection (6.4)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Ultimate Profile Builder By CMSHelpLive Multiple Vulnerabilities (2.3.3)
|
CWE-79
CWE-352
|
CWE-79
CWE-352
|
High
|
WordPress Plugin Ultimate Responsive Image Slider Unspecified Vulnerability (3.3.2)
|
|
|
High
|
WordPress Plugin Ultimate Reviews PHP Object Injection (2.0.18)
|
CWE-915
|
CWE-915
|
High
|
WordPress Plugin Ultimate Reviews PHP Object Injection (2.1.32)
|
CWE-915
|
CWE-915
|
High
|
WordPress Plugin Ultimate SMS Notifications for WooCommerce CSV Injection (1.4.1)
|
CVE-2022-2429
CWE-1236
|
CWE-1236
|
High
|
WordPress Plugin ULTIMATE TABLES SQL Injection (1.5)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Ultimate Tag Cloud Widget Unspecified Vulnerability (2.3)
|
|
|
High
|
WordPress Plugin Ultimate TinyMCE 'swfupload.swf' Cross-Site Scripting (3.5)
|
CVE-2012-3414
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Ultimate TinyMCE Multiple Unspecified Vulnerabilities (5.0)
|
|
|
High
|
WordPress Plugin ULTIMATE VIDEO GALLERY Cross-Site Scripting (1.4)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin UltimateWoo-The Ultimate WooCommerce with Unlimited Usage PHP Object Injection (0.1.10)
|
CWE-915
|
CWE-915
|
High
|
WordPress Plugin Ultimate WordPress Auction Cross-Site Request Forgery (1.0.0)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin Ultimate WordPress Auction Multiple Vulnerabilities (4.0.5)
|
CWE-79
CWE-352
|
CWE-79
CWE-352
|
High
|
WordPress Plugin Ultimate WP Query Search Filter Cross-Site Scripting (1.0.10)
|
CVE-2023-23832
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Ultimeter Security Bypass (1.9.2)
|
CWE-264
|
CWE-264
|
High
|
WordPress Plugin Uncanny Toolkit for LearnDash Cross-Site Request Forgery (3.6.3)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin Uncanny Toolkit for LearnDash Cross-Site Request Forgery (3.6.4.1)
|
CVE-2023-23714
CWE-352
|
CWE-352
|
High
|
WordPress Plugin Unconfirmed Cross-Site Scripting (1.2.3)
|
CVE-2014-100018
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Under Construction, Coming Soon & Maintenance Mode Multiple Vulnerabilities (1.1.1)
|
CWE-79
CWE-918
|
CWE-79
CWE-918
|
High
|
WordPress Plugin Under Construction/Maintenance Mode from Acurax Multiple Unspecified Vulnerabilities (2.5.2)
|
|
|
High
|
WordPress Plugin underConstruction Cross-Site Request Forgery (1.08)
|
CVE-2013-2699
CWE-352
|
CWE-352
|
High
|
WordPress Plugin underConstruction Cross-Site Scripting (1.18)
|
CVE-2021-39320
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Under Construction Open Redirect (3.20)
|
CWE-601
|
CWE-601
|
High
|
WordPress Plugin Under Construction Unspecified Vulnerability (3.25)
|
|
|
High
|
WordPress Plugin Under Construction Unspecified Vulnerability (3.85)
|
|
|
High
|
WordPress Plugin UnGallery 'search' Parameter Remote Arbitrary Command Execution (2.1.5)
|
CWE-95
|
CWE-95
|
High
|
WordPress Plugin UnGallery Local File Disclosure (1.5.8)
|
CWE-22
|
CWE-22
|
High
|
WordPress Plugin Unite Gallery Lite Multiple Vulnerabilities (1.4.6)
|
CWE-89
CWE-352
|
CWE-89
CWE-352
|
High
|
WordPress Plugin Universal Analytics Cross-Site Scripting (1.3.0)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Universal Post Manager Cross-Site Scripting and SQL Injection Vulnerabilities (1.0.9)
|
CWE-79
CWE-89
|
CWE-79
CWE-89
|
High
|
WordPress Plugin Universal Star Rating Unspecified Vulnerability (1.10.3)
|
|
|
High
|
WordPress Plugin Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Cross-Site Scripting (1.5.107)
|
CVE-2024-3190
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Remote Code Execution (1.5.89)
|
CVE-2023-6743
CWE-94
|
CWE-94
|
High
|
WordPress Plugin Unlimited Elements For Elementor (Free Widgets, Addons, Templates) SQL Injection (1.5.107)
|
CVE-2024-4779
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Unlimited Elements For Elementor (Free Widgets, Addons, Templates) SQL Injection (1.5.109)
|
CVE-2024-5329
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Unlimited Pop-Ups Multiple Cross-Site Scripting Vulnerabilities (1.4.3)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Unlimited PopUps SQL Injection (4.5.3)
|
CVE-2021-24631
CWE-89
|
CWE-89
|
High
|
WordPress Plugin Unyson Information Disclosure (2.7.18)
|
CWE-200
|
CWE-200
|
High
|
WordPress Plugin Updater by BestWebSoft Cross-Site Scripting (1.34)
|
CVE-2017-2171
CVE-2017-2171
CVE-2017-18565
CWE-79
|
CWE-79
|
High
|
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Request Forgery (1.22.24)
|
CWE-352
|
CWE-352
|
High
|
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Request Forgery (1.23.3)
|
CVE-2023-32960
CWE-352
|
CWE-352
|
High
|
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.9.63)
|
CVE-2015-9360
CWE-79
|
CWE-79
|
High
|
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.13.4)
|
CVE-2017-18593
CWE-79
|
CWE-79
|
High
|
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.16.65)
|
CVE-2021-25022
CWE-79
|
CWE-79
|
High
|
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.16.68)
|
CVE-2021-25089
CWE-79
|
CWE-79
|
High
|
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.22.8)
|
CVE-2022-0864
CWE-79
|
CWE-79
|
High
|
WordPress Plugin UpdraftPlus WordPress Backup Multiple Vulnerabilities (1.16.58)
|
CVE-2021-24423
CWE-22
CWE-79
|
CWE-22
CWE-79
|
High
|
WordPress Plugin UpdraftPlus WordPress Backup Privilege Escalation (1.23.2)
|
CWE-269
|
CWE-269
|
High
|
WordPress Plugin UpdraftPlus WordPress Backup Security Bypass (1.9.50)
|
CWE-264
|
CWE-264
|
High
|
WordPress Plugin UpdraftPlus WordPress Backup Security Bypass (1.22.1)
|
CVE-2022-0633
CWE-264
|
CWE-264
|
High
|
WordPress Plugin UpiCRM-Free WordPress CRM and Lead Management Information Disclosure (2.1.8.5)
|
CWE-538
|
CWE-538
|
High
|
WordPress Plugin Uploader 'num' Parameter Cross-Site Scripting (1.0.0)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Uploader 'uploadify.php' Arbitrary File Upload (1.0.4)
|
CWE-434
|
CWE-434
|
High
|
WordPress Plugin Uploader Cross-Site Scripting and Arbitrary File Upload Vulnerabilities (1.0.4)
|
CVE-2013-2287
CVE-2013-2288
CWE-79
CWE-434
|
CWE-79
CWE-434
|
High
|
WordPress Plugin Upload File Type Settings Cross-Site Scripting (1.1)
|
CVE-2023-25781
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Uploadify Integration Multiple Cross-Site Scripting Vulnerabilities (0.9.6)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Uploadify Remote File Upload (1.0)
|
CWE-20
|
CWE-20
|
High
|
WordPress Plugin UPM Polls 'PID' Parameter SQL Injection (1.0.4)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin UPM Polls 'qid' Parameter SQL Injection (1.0.3)
|
CWE-89
|
CWE-89
|
High
|
WordPress Plugin URL Cloak & Encrypt Cross-Site Scripting (2.0)
|
CVE-2014-4563
CWE-79
|
CWE-79
|
High
|
WordPress Plugin Use Any Font Unspecified Vulnerability (4.3.6)
|
|
|
High
|
WordPress Plugin User Access Manager Cross-Site Scripting (1.2.6.7)
|
CWE-79
|
CWE-79
|
High
|
WordPress Plugin User Access Manager Cross-Site Scripting (1.2.14)
|
CWE-79
|
CWE-79
|
High
|