Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
wordpress wordpress 3.1.1 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-2340
Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php....
Xcloner Xcloner
Xcloner Xcloner 2.1.2
Xcloner Xcloner 3.0
Xcloner Xcloner 3.0.3
Xcloner Xcloner 3.0.1
Xcloner Xcloner 3.0.6
Xcloner Xcloner 3.0.8
Xcloner Xcloner 3.0.7
Xcloner Xcloner 3.0.5
Xcloner Xcloner 3.0.2
Xcloner Xcloner 3.0.4
Xcloner Xcloner 2.2.1
Xcloner Xcloner 2.1
1 EDB exploit available
NA
CVE-2013-5962
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct...
Envato Complete Gallery Manager Plugin 3.3.2
Envato Complete Gallery Manager Plugin 3.3.1
Envato Complete Gallery Manager Plugin 3.2.2
Envato Complete Gallery Manager Plugin 3.2.1
Envato Complete Gallery Manager Plugin 2.0.2
Envato Complete Gallery Manager Plugin 2.0.1
Envato Complete Gallery Manager Plugin 3.2.6
Envato Complete Gallery Manager Plugin 3.2.5
Envato Complete Gallery Manager Plugin 3.1.0
Envato Complete Gallery Manager Plugin 3.0.1
Envato Complete Gallery Manager Plugin 1.0.1
Envato Complete Gallery Manager Plugin 1.0.0
Envato Complete Gallery Manager Plugin 3.3.0
Envato Complete Gallery Manager Plugin 3.2.8
Envato Complete Gallery Manager Plugin 3.2.7
Envato Complete Gallery Manager Plugin 3.2.0
Envato Complete Gallery Manager Plugin 3.1.1
Envato Complete Gallery Manager Plugin 2.0.0
Envato Complete Gallery Manager Plugin 1.0.2
Envato Complete Gallery Manager Plugin
Envato Complete Gallery Manager Plugin 3.2.4
Envato Complete Gallery Manager Plugin 3.2.3
Envato Complete Gallery Manager Plugin 3.0.0
Envato Complete Gallery Manager Plugin 2.0.3
1 EDB exploit available
NA
CVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3,...
Blair Williams Pretty Link Lite 1.6.0
Blair Williams Pretty Link Lite 1.6.1
Blair Williams Pretty Link Lite
Joobi Com Jnews 8.0.1
Civicrm Civicrm 4.3.1
Civicrm Civicrm 3.1.1
Civicrm Civicrm 3.1.2
Civicrm Civicrm 3.2.2
Civicrm Civicrm 3.2.3
Civicrm Civicrm 3.3.6
Civicrm Civicrm 3.4.0
Civicrm Civicrm 4.1.5
Civicrm Civicrm 4.1.6
Civicrm Civicrm 4.2.7
Civicrm Civicrm 4.2.8
Civicrm Civicrm 4.3.3
Civicrm Civicrm 3.1.0
Civicrm Civicrm 3.2.0
Civicrm Civicrm 3.2.1
Civicrm Civicrm 3.3.3
Civicrm Civicrm 3.3.5
Civicrm Civicrm 4.1.3
Civicrm Civicrm 4.1.4
Civicrm Civicrm 4.2.5
Civicrm Civicrm 4.2.6
Civicrm Civicrm 4.3.2
Civicrm Civicrm 3.1.5
Civicrm Civicrm 3.1.6
Civicrm Civicrm 3.3.0
Civicrm Civicrm 3.3.1
Civicrm Civicrm 3.3.2
Civicrm Civicrm 4.1.1
Civicrm Civicrm 4.1.2
Civicrm Civicrm 4.2.2
Civicrm Civicrm 4.2.4
Civicrm Civicrm 4.3.0
Civicrm Civicrm 3.1.3
Civicrm Civicrm 3.1.4
Civicrm Civicrm 3.2.4
Civicrm Civicrm 3.2.5
Civicrm Civicrm 4.0.5
Civicrm Civicrm 4.1.0
Civicrm Civicrm 4.2.0
Civicrm Civicrm 4.2.1
Civicrm Civicrm 4.2.9
1 EDB exploit available
4.8
CVE-2022-2635
The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite...
Autoptimize Autoptimize
6.1
CVSSv3
CVE-2021-24387
The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user...
Contempothemes Real Estate 7
1 Github repository available
NA
CVE-2014-7228
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professional 3.0.0 through 4.0.2; Backup Professional for WordPress 1.0.b1 through 1.1.3; Solo 1.0.b1 through 1.1.2; Admin Tools Core and...
Joomla Joomla\\! 2.5.4
Joomla Joomla\\! 2.5.11
Joomla Joomla\\! 2.5.13
Joomla Joomla\\! 2.5.18
Joomla Joomla\\! 2.5.21
Joomla Joomla\\! 3.0.2
Joomla Joomla\\! 3.0.4
Joomla Joomla\\! 3.1.6
Joomla Joomla\\! 3.2.1
Joomla Joomla\\! 3.3.0
Joomla Joomla\\! 3.3.2
Joomla Joomla\\! 2.5.5
Joomla Joomla\\! 2.5.6
Joomla Joomla\\! 2.5.7
Joomla Joomla\\! 2.5.8
Joomla Joomla\\! 2.5.9
Joomla Joomla\\! 2.5.23
Joomla Joomla\\! 2.5.24
Joomla Joomla\\! 2.5.25
Joomla Joomla\\! 3.0.0
Joomla Joomla\\! 3.2.2
Joomla Joomla\\! 3.2.3
Joomla Joomla\\! 3.2.4
Joomla Joomla\\! 3.2.5
Joomla Joomla\\! 2.5.10
Joomla Joomla\\! 2.5.12
Joomla Joomla\\! 2.5.20
Joomla Joomla\\! 2.5.22
Joomla Joomla\\! 3.0.1
Joomla Joomla\\! 3.0.3
Joomla Joomla\\! 3.1.5
Joomla Joomla\\! 3.2.0
Joomla Joomla\\! 3.3.1
Joomla Joomla\\! 3.3.3
Joomla Joomla\\! 2.5.14
Joomla Joomla\\! 2.5.15
Joomla Joomla\\! 2.5.16
Joomla Joomla\\! 2.5.17
Joomla Joomla\\! 3.1.0
Joomla Joomla\\! 3.1.1
Joomla Joomla\\! 3.1.2
Joomla Joomla\\! 3.1.3
Joomla Joomla\\! 3.1.4
Joomla Joomla\\! 3.3.4
Joomla Joomla\\! 2.5.19
1 EDB exploit available
1 Metasploit module available
NA
CVE-2013-1852
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the league_id parameter in the leaguemanager-export page to wp-admin/admin.php....
Kolja Schleich Leaguemanager
Kolja Schleich Leaguemanager 3.7
Kolja Schleich Leaguemanager 3.6.9
Kolja Schleich Leaguemanager 3.5.2
Kolja Schleich Leaguemanager 3.5.1
Kolja Schleich Leaguemanager 3.5
Kolja Schleich Leaguemanager 3.4.2
Kolja Schleich Leaguemanager 3.1.7
Kolja Schleich Leaguemanager 3.1.6
Kolja Schleich Leaguemanager 3.1.5
Kolja Schleich Leaguemanager 3.1.4
Kolja Schleich Leaguemanager 2.9
Kolja Schleich Leaguemanager 2.8
Kolja Schleich Leaguemanager 2.7.1
Kolja Schleich Leaguemanager 2.1
Kolja Schleich Leaguemanager 2.0
Kolja Schleich Leaguemanager 1.5
Kolja Schleich Leaguemanager 1.4.2
Kolja Schleich Leaguemanager 3.6.7
Kolja Schleich Leaguemanager 3.6.5
Kolja Schleich Leaguemanager 3.6
Kolja Schleich Leaguemanager 3.5.5
Kolja Schleich Leaguemanager 3.5.3
Kolja Schleich Leaguemanager 3.4.1
Kolja Schleich Leaguemanager 3.4
Kolja Schleich Leaguemanager 3.2
Kolja Schleich Leaguemanager 3.1.8
Kolja Schleich Leaguemanager 3.1.3
Kolja Schleich Leaguemanager 3.1.1
Kolja Schleich Leaguemanager 3.0.4
Kolja Schleich Leaguemanager 2.9.3
Kolja Schleich Leaguemanager 2.9.1
Kolja Schleich Leaguemanager 2.6.3
Kolja Schleich Leaguemanager 2.6.1
Kolja Schleich Leaguemanager 2.4.1
Kolja Schleich Leaguemanager 2.3.1
Kolja Schleich Leaguemanager 2.2
Kolja Schleich Leaguemanager 1.4.1
Kolja Schleich Leaguemanager 1.3
Kolja Schleich Leaguemanager 3.6.4
Kolja Schleich Leaguemanager 3.6.3
Kolja Schleich Leaguemanager 3.6.2
Kolja Schleich Leaguemanager 3.6.1
Kolja Schleich Leaguemanager 3.3.1
Kolja Schleich Leaguemanager 3.3
Kolja Schleich Leaguemanager 3.2.2
Kolja Schleich Leaguemanager 3.2.1
Kolja Schleich Leaguemanager 3.0.3
Kolja Schleich Leaguemanager 3.0.2
Kolja Schleich Leaguemanager 3.0.1
Kolja Schleich Leaguemanager 3.0
Kolja Schleich Leaguemanager 2.6
Kolja Schleich Leaguemanager 2.5.2
Kolja Schleich Leaguemanager 2.5.1
Kolja Schleich Leaguemanager 2.5
Kolja Schleich Leaguemanager 1.2.1
Kolja Schleich Leaguemanager 1.2
Kolja Schleich Leaguemanager 1.1
Kolja Schleich Leaguemanager 1.0
Kolja Schleich Leaguemanager 3.6.8
Kolja Schleich Leaguemanager 3.6.6
Kolja Schleich Leaguemanager 3.5.6
Kolja Schleich Leaguemanager 3.5.4
Kolja Schleich Leaguemanager 3.1.9
Kolja Schleich Leaguemanager 3.1.2
Kolja Schleich Leaguemanager 3.1
Kolja Schleich Leaguemanager 2.9.2
Kolja Schleich Leaguemanager 2.7
Kolja Schleich Leaguemanager 2.6.2
Kolja Schleich Leaguemanager 2.4
Kolja Schleich Leaguemanager 2.3
Kolja Schleich Leaguemanager 1.4
Kolja Schleich Leaguemanager 1.2.2
1 EDB exploit available
1 Github repository available
NA
CVE-2013-6342
Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin before 4.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tb_tab_index parameter to wp-admin/options-general.php....
Tweet-blender Tweet-blender
Tweet-blender Tweet-blender 4.0.0
Tweet-blender Tweet-blender 3.3.15
Tweet-blender Tweet-blender 3.3.14
Tweet-blender Tweet-blender 3.3.0
Tweet-blender Tweet-blender 3.2.4
Tweet-blender Tweet-blender 3.2.3
Tweet-blender Tweet-blender 3.2.2
Tweet-blender Tweet-blender 3.1.8
Tweet-blender Tweet-blender 3.1.7
Tweet-blender Tweet-blender 3.1.6
Tweet-blender Tweet-blender 3.1.5
Tweet-blender Tweet-blender 3.1.4
Tweet-blender Tweet-blender 3.0.0
Tweet-blender Tweet-blender 2.4.7
Tweet-blender Tweet-blender 2.4.6
Tweet-blender Tweet-blender 2.4.5
Tweet-blender Tweet-blender 2.0.4
Tweet-blender Tweet-blender 2.0.3
Tweet-blender Tweet-blender 2.0.2
Tweet-blender Tweet-blender 2.0.1
Tweet-blender Tweet-blender 3.3.9
Tweet-blender Tweet-blender 3.3.8
Tweet-blender Tweet-blender 3.3.7
Tweet-blender Tweet-blender 3.3.6
Tweet-blender Tweet-blender 3.3.5
Tweet-blender Tweet-blender 3.1.16
Tweet-blender Tweet-blender 3.1.15
Tweet-blender Tweet-blender 3.1.14
Tweet-blender Tweet-blender 3.1.13
Tweet-blender Tweet-blender 3.0.8
Tweet-blender Tweet-blender 3.0.7
Tweet-blender Tweet-blender 3.0.6
Tweet-blender Tweet-blender 3.0.5
Tweet-blender Tweet-blender 2.3.0
Tweet-blender Tweet-blender 2.2.3
Tweet-blender Tweet-blender 2.2.2
Tweet-blender Tweet-blender 3.3.13
Tweet-blender Tweet-blender 3.3.11
Tweet-blender Tweet-blender 3.3.4
Tweet-blender Tweet-blender 3.3.2
Tweet-blender Tweet-blender 3.2.0
Tweet-blender Tweet-blender 3.1.17
Tweet-blender Tweet-blender 3.1.12
Tweet-blender Tweet-blender 3.1.10
Tweet-blender Tweet-blender 3.1.3
Tweet-blender Tweet-blender 3.1.1
Tweet-blender Tweet-blender 3.0.3
Tweet-blender Tweet-blender 3.0.1
Tweet-blender Tweet-blender 2.4.4
Tweet-blender Tweet-blender 2.4.2
Tweet-blender Tweet-blender 2.4.0
Tweet-blender Tweet-blender 2.2.0
Tweet-blender Tweet-blender 2.1.0
Tweet-blender Tweet-blender 3.3.12
Tweet-blender Tweet-blender 3.3.10
Tweet-blender Tweet-blender 3.3.3
Tweet-blender Tweet-blender 3.3.1
Tweet-blender Tweet-blender 3.2.1
Tweet-blender Tweet-blender 3.1.18
Tweet-blender Tweet-blender 3.1.11
Tweet-blender Tweet-blender 3.1.9
Tweet-blender Tweet-blender 3.1.2
Tweet-blender Tweet-blender 3.1.0
Tweet-blender Tweet-blender 3.0.4
Tweet-blender Tweet-blender 3.0.2
Tweet-blender Tweet-blender 2.4.3
Tweet-blender Tweet-blender 2.4.1
Tweet-blender Tweet-blender 2.1.1
Tweet-blender Tweet-blender 2.0.5
Tweet-blender Tweet-blender 2.0.0
Tweet-blender Tweet-blender 2.2.1
8.8
CVE-2022-3240
The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1. This is due to missing nonce validation on the FollowMeIgniteSocialMedia_options_page() function. This makes it possible for unauthenticated...
Follow Me Plugin Project Follow Me Plugin
9.8
CVE-2020-36724
The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This is due to the use of a user supplied hashing algorithm passed to the hash_hmac() function and the use of a loose comparison on the hash which allows an attacker...
Wordable Wordable
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
XSS
CVE-2023-48314
CVE-2023-6376
CVE-2023-46384
arbitrary code
CVE-2023-42917
CVE-2023-48842
CVE-2023-42916
firewall
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6