Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wpdeveloper vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2023-2083
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level malicious users to save plugin settings. While ...
Wpdeveloper Essential Blocks
4.3
CVSSv3
CVE-2023-2084
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level malicious users to obtain plugin settings. While...
Wpdeveloper Essential Blocks
8.8
CVSSv3
CVE-2021-24356
In the Simple 301 Redirects by BetterLinks WordPress plugin prior to 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on v...
Wpdeveloper Simple 301 Redirects
1 Github repository
5.4
CVSSv3
CVE-2023-49184
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Parallax Slider Block allows Stored XSS.This issue affects Parallax Slider Block: from n/a up to and including 1.2.4.
Wpdeveloper Parallax Slider Block
6.1
CVSSv3
CVE-2017-18503
The twitter-cards-meta plugin prior to 2.5.0 for WordPress has XSS.
Wpdeveloper Twitter Cards Meta
8.8
CVSSv3
CVE-2017-18504
The twitter-cards-meta plugin prior to 2.5.0 for WordPress has CSRF.
Wpdeveloper Twitter Cards Meta
8.8
CVSSv3
CVE-2021-24352
The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin prior to 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects.
Wpdeveloper Simple 301 Redirects
8.8
CVSSv3
CVE-2021-24353
The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin prior to 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.
Wpdeveloper Simple 301 Redirects
8.8
CVSSv3
CVE-2021-24354
A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin prior to 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.
Wpdeveloper Simple 301 Redirects
4.3
CVSSv3
CVE-2021-24355
In the Simple 301 Redirects by BetterLinks WordPress plugin prior to 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to ret...
Wpdeveloper Simple 301 Redirects
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-40673
CVE-2024-36674
CVE-2024-27348
unspecified
CVE-2024-24919
CVE-2024-4870
malicious code
CVE-2024-2019
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »