Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 1.5 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2016-10762
The CampTix Event Ticketing plugin prior to 1.5 for WordPress allows CSV injection when the export tool is used.
Automattic Camptix Event Ticketing
7.5
CVSSv3
CVE-2017-1002004
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
Dtracker Project Dtracker 1.5
7.5
CVSSv3
CVE-2017-1002005
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.
Dtracker Project Dtracker 1.5
7.5
CVSSv3
CVE-2017-1002007
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
Dtracker Project Dtracker 1.5
7.5
CVSSv3
CVE-2017-1002006
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
Dtracker Project Dtracker 1.5
7.2
CVSSv3
CVE-2016-10939
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
Xtremelocator Xtremelocator 1.5
6.5
CVSSv3
CVE-2021-24820
The Cost Calculator WordPress plugin up to and including 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout
Bold-themes Cost Calculator
6.5
CVSSv3
CVE-2021-24795
The Filter Portfolio Gallery WordPress plugin up to and including 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow malicious users to make a logged in admin delete arbitrary Gallery.
Phoeniixx Filter Portfolio Gallery
6.5
CVSSv3
CVE-2015-9447
The unite-gallery-lite plugin prior to 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
Unitegallery Unite Gallery Lite
6.1
CVSSv3
CVE-2021-25044
The Cryptocurrency Pricing list and Ticker WordPress plugin up to and including 1.5 does not sanitise and escape the ccpw_setpage parameter before outputting it back in pages where its shortcode is embed, leading to a Reflected Cross-Site Scripting issue
Premium-themes Cryptocurrency Pricing List And Ticker
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »