Filtered by vendor Wordpress
Subscriptions
Total
5465 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-46467 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rahendra Putra K⢠RAphicon allows DOM-Based XSS. This issue affects RAphicon: from n/a through 2.1.2. | ||||
CVE-2024-12049 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 6.1 Medium |
The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd' parameters in all versions up to, and including, 1.17.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | ||||
CVE-2024-10783 | 2 Mainwp, Wordpress | 2 Mainwp Child, Wordpress | 2025-07-13 | 8.1 High |
The MainWP Child â Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due to a missing authorization checks on the register_site function in all versions up to, and including, 5.2 when a site is left in an unconfigured state. This makes it possible for unauthenticated attackers to log in as an administrator on instances where MainWP Child is not yet connected to the MainWP Dashboard. IMPORTANT: this only affects sites who have MainWP Child installed and have not yet connected to the MainWP Dashboard, and do not have the unique security ID feature enabled. Sites already connected to the MainWP Dashboard plugin and do not have the unique security ID feature enabled, are NOT affected and not required to upgrade. Please note 5.2.1 contains a partial patch, though we consider 5.3 to be the complete patch. | ||||
CVE-2023-47838 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 4.3 Medium |
Missing Authorization vulnerability in Jules Colle Conditional Fields for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conditional Fields for Contact Form 7: from n/a through 2.4.1. | ||||
CVE-2025-47665 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 5.9 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bistromatic N360 | Splash Screen allows Stored XSS. This issue affects N360 | Splash Screen: from n/a through 1.0.6. | ||||
CVE-2024-12518 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 6.4 Medium |
The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' shortcode in all versions up to, and including, 1.4.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
CVE-2025-30531 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in GBS Developer WP Ride Booking allows Cross Site Request Forgery. This issue affects WP Ride Booking: from n/a through 2.4. | ||||
CVE-2025-23433 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 7.1 High |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jnwry vcOS allows Reflected XSS. This issue affects vcOS: from n/a through 1.4.0. | ||||
CVE-2024-51660 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 4.3 Medium |
Missing Authorization vulnerability in Zakaria Binsaifullah Easy Accordion Gutenberg Block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Accordion Gutenberg Block: from n/a through 1.2.3. | ||||
CVE-2024-12495 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 6.4 Medium |
The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-bootstrap/column' block in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
CVE-2024-56049 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 8.5 High |
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue affects WPLMS: from n/a before 1.9.9.5.2. | ||||
CVE-2024-51634 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 7.1 High |
Cross-Site Request Forgery (CSRF) vulnerability in Webriti WordPress Themes & Plugins Shop Webriti Custom Login allows Reflected XSS.This issue affects Webriti Custom Login: from n/a through 0.3. | ||||
CVE-2025-23449 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 7.1 High |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Simple shortcode buttons allows Reflected XSS. This issue affects Simple shortcode buttons: from n/a through 1.3.2. | ||||
CVE-2025-23701 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 7.1 High |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew Blackford, LimeSquare Pty Ltd Lime Developer Login allows Reflected XSS. This issue affects Lime Developer Login: from n/a through 1.4.0. | ||||
CVE-2024-2500 | 2 Themegrill, Wordpress | 2 Colormag, Wordpress | 2025-07-13 | 6.4 Medium |
The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authentciated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
CVE-2024-25926 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 7.1 High |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IndiaNIC Widgets Controller allows Reflected XSS.This issue affects Widgets Controller: from n/a through 1.1. | ||||
CVE-2025-47522 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 5.9 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AWEOS GmbH AWEOS WP Lock allows Stored XSS. This issue affects AWEOS WP Lock: from n/a through 1.4.8. | ||||
CVE-2025-22633 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 5.8 Medium |
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Matt Cromwell Give â Divi Donation Modules allows Retrieve Embedded Sensitive Data. This issue affects Give â Divi Donation Modules: from n/a through 2.0.0. | ||||
CVE-2025-29013 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 5.4 Medium |
Missing Authorization vulnerability in faaiq Custom Category/Post Type Post order allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Custom Category/Post Type Post order: from n/a through 1.5.9. | ||||
CVE-2024-11779 | 1 Wordpress | 1 Wordpress | 2025-07-13 | 6.4 Medium |
The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocarousel_products_carousel' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |