Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 1.0 vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2021-24395
The editid GET parameter of the Embed Youtube Video WordPress plugin up to and including 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
Geekwebsolution Embed Youtube Video
6.5
CVSSv2
CVE-2021-24337
The id GET parameter of one of the Video Embed WordPress plugin up to and including 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injec...
Video-embed-box Project Video-embed-box
6.5
CVSSv2
CVE-2021-24224
The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin up to and including 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE.
6.5
CVSSv2
CVE-2016-10943
The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.
Zx-csv-upload Project Zx-csv-upload 1.0
6.5
CVSSv2
CVE-2016-10940
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
Zm-gallery Project Zm-gallery 1.0
6.5
CVSSv2
CVE-2017-18602
The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter.
Ibps Online Exam Project Ibps Online Exam 1.0
6.5
CVSSv2
CVE-2017-16955
SQL injection vulnerability in the InLinks plugin up to and including 1.1 for WordPress allows authenticated users to execute arbitrary SQL commands via the "keyword" parameter to /wp-admin/options-general.php?page=inlinks/inlinks.php.
Inlinks Project Inlinks 1.0
6.5
CVSSv2
CVE-2017-14848
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
Dasinfomedia Wphrm Human Resource Management System 1.0
1 EDB exploit
6.5
CVSSv2
CVE-2017-1002025
Vulnerability in wordpress plugin add-edit-delete-listing-for-member-module v1.0, The plugin author does not sanitize user supplied input via $act before passing it into an SQL statement.
Add-edit-delete-listing-for-member-module Project Add-edit-delete-listing-for-member-module 1.0
6.5
CVSSv2
CVE-2017-6570
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Parameter: id.
Mail-masta Project Mail-masta 1.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »