Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 2.1.1 vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2013-2701
Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote malicious users to hijack the authentication of administrators for requests that manipulate plugin settings via unknown vectors.
Linksalpha Social Sharing Toolkit Plugin 2.1.1
6.5
CVSSv2
CVE-2013-1408
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin prior to 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CS...
Wysija Newsletters Project Wysija Newsletters 2.1.4
Wysija Newsletters Project Wysija Newsletters 2.1.3
Wysija Newsletters Project Wysija Newsletters 2.0.7
Wysija Newsletters Project Wysija Newsletters 2.0.6
Wysija Newsletters Project Wysija Newsletters 2.1.8
Wysija Newsletters Project Wysija Newsletters 2.1.7
Wysija Newsletters Project Wysija Newsletters 2.1
Wysija Newsletters Project Wysija Newsletters 2.1.6
Wysija Newsletters Project Wysija Newsletters 2.1.5
Wysija Newsletters Project Wysija Newsletters 2.0.9
Wysija Newsletters Project Wysija Newsletters 2.0.8
Wysija Newsletters Project Wysija Newsletters 2.0
Wysija Newsletters Project Wysija Newsletters 2.0.9.5
Wysija Newsletters Project Wysija Newsletters 2.0.3
Wysija Newsletters Project Wysija Newsletters 2.0.2
Wysija Newsletters Project Wysija Newsletters 2.0.1
Wysija Newsletters Project Wysija Newsletters
Wysija Newsletters Project Wysija Newsletters 2.1.9
Wysija Newsletters Project Wysija Newsletters 2.1.2
Wysija Newsletters Project Wysija Newsletters 2.1.1
Wysija Newsletters Project Wysija Newsletters 2.0.5
Wysija Newsletters Project Wysija Newsletters 2.0.4
1 EDB exploit
4.3
CVSSv2
CVE-2011-3858
Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme prior to 2.1.6 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the s parameter.
Zespia Pixiv Custom
Zespia Pixiv Custom 1.0
Zespia Pixiv Custom 1.0.1
Zespia Pixiv Custom 1.0.2
Zespia Pixiv Custom 1.1
Zespia Pixiv Custom 1.1.1
Zespia Pixiv Custom 1.1.2
Zespia Pixiv Custom 1.1.3
Zespia Pixiv Custom 1.1.4
Zespia Pixiv Custom 1.1.5
Zespia Pixiv Custom 1.1.6
Zespia Pixiv Custom 1.1.7
Zespia Pixiv Custom 1.1.9
Zespia Pixiv Custom 1.1.10
Zespia Pixiv Custom 1.1.11
Zespia Pixiv Custom 1.1.12
Zespia Pixiv Custom 1.1.13
Zespia Pixiv Custom 1.1.14
Zespia Pixiv Custom 1.2.0
Zespia Pixiv Custom 1.2.1
Zespia Pixiv Custom 1.3.0
Zespia Pixiv Custom 1.3.1
1 EDB exploit
5
CVSSv2
CVE-2012-6112
classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon prior to 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x prior to 2.1.10, 2.2.x prior to 2.2.7, 2.3.x prior to 2.3.4, and 2.4.x prior to 2.4.1 and other products, does not properly handle control charact...
Tinymce Spellchecker Php 2.0
Tinymce Spellchecker Php 2.0.2
Tinymce Spellchecker Php 2.0.1
Tinymce Spellchecker Php 2.0.6
Tinymce Spellchecker Php 2.0.3
Moodle Moodle 2.1.0
Moodle Moodle 2.1.4
Moodle Moodle 2.1.7
Moodle Moodle 2.1.8
Moodle Moodle 2.1.9
Moodle Moodle 2.1.2
Moodle Moodle 2.1.1
Moodle Moodle 2.1.3
Moodle Moodle 2.1.5
Moodle Moodle 2.1.6
Moodle Moodle 2.2.3
Moodle Moodle 2.2.1
Moodle Moodle 2.2.4
Moodle Moodle 2.2.6
Moodle Moodle 2.2.5
Moodle Moodle 2.2.0
Moodle Moodle 2.2.2
6.8
CVSSv2
CVE-2014-4030
Cross-site request forgery (CSRF) vulnerability in the JW Player plugin prior to 2.1.4 for WordPress allows remote malicious users to hijack the authentication of administrators for requests that remove players via a delete action to wp-admin/admin.php.
Longtailvideo Jw Player For Flash \\& Html5 Video Plugin 2.0.4
Longtailvideo Jw Player For Flash \\& Html5 Video Plugin 2.0.3
Longtailvideo Jw Player For Flash \\& Html5 Video Plugin 2.0.2
Longtailvideo Jw Player For Flash \\& Html5 Video Plugin 2.0.1
Longtailvideo Jw Player For Flash \\& Html5 Video Plugin 2.1.1
Longtailvideo Jw Player For Flash \\& Html5 Video Plugin 2.0.5
Longtailvideo Jw Player For Flash \\& Html5 Video Plugin 2.0.0
Longtailvideo Jw Player For Flash \\& Html5 Video Plugin
Longtailvideo Jw Player For Flash \\& Html5 Video Plugin 2.1.2
Longtailvideo Jw Player For Flash \\& Html5 Video Plugin 2.1.0
1 EDB exploit
3.5
CVSSv2
CVE-2018-6194
A cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plugin (wp-splashing-images) prior to 2.1.1 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the search parameter to wp-admin/...
Splashing Images Project Splashing Images
6.5
CVSSv2
CVE-2018-6195
admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) prior to 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote malicious users to conduct PHP Object Injection attacks via crafted serialized data in the &...
Splashing Images Project Splashing Images
10
CVSSv2
CVE-2012-3576
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin prior to 2.5.30 for WordPress allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads...
Jquindlen Wpstorecart 2.5.24
Jquindlen Wpstorecart 2.5.23
Jquindlen Wpstorecart 2.5.15
Jquindlen Wpstorecart 2.5.14
Jquindlen Wpstorecart 2.5.7
Jquindlen Wpstorecart 2.5.5
Jquindlen Wpstorecart 2.4.14
Jquindlen Wpstorecart 2.4.13
Jquindlen Wpstorecart 2.4.5
Jquindlen Wpstorecart 2.4.4
Jquindlen Wpstorecart 2.3.15
Jquindlen Wpstorecart 2.3.14
Jquindlen Wpstorecart 2.3.7
Jquindlen Wpstorecart 2.3.6
Jquindlen Wpstorecart 2.2.8
Jquindlen Wpstorecart 2.2.7
Jquindlen Wpstorecart 2.2.0
Jquindlen Wpstorecart 2.1.8
Jquindlen Wpstorecart 2.1.1
Jquindlen Wpstorecart 2.1.0
Jquindlen Wpstorecart 2.0.6
Jquindlen Wpstorecart 2.0.5
1 EDB exploit
4.3
CVSSv2
CVE-2013-6342
Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin prior to 4.0.2 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the tb_tab_index parameter to wp-admin/options-general.php.
Tweet-blender Tweet-blender
Tweet-blender Tweet-blender 4.0.0
Tweet-blender Tweet-blender 3.3.15
Tweet-blender Tweet-blender 3.3.14
Tweet-blender Tweet-blender 3.3.0
Tweet-blender Tweet-blender 3.2.4
Tweet-blender Tweet-blender 3.2.3
Tweet-blender Tweet-blender 3.2.2
Tweet-blender Tweet-blender 3.1.8
Tweet-blender Tweet-blender 3.1.7
Tweet-blender Tweet-blender 3.1.6
Tweet-blender Tweet-blender 3.1.5
Tweet-blender Tweet-blender 3.1.4
Tweet-blender Tweet-blender 3.0.0
Tweet-blender Tweet-blender 2.4.7
Tweet-blender Tweet-blender 2.4.6
Tweet-blender Tweet-blender 2.4.5
Tweet-blender Tweet-blender 2.0.4
Tweet-blender Tweet-blender 2.0.3
Tweet-blender Tweet-blender 2.0.2
Tweet-blender Tweet-blender 2.0.1
Tweet-blender Tweet-blender 3.3.9
4.3
CVSSv2
CVE-2012-4283
Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin prior to 3.0.4.1 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the callback parameter.
Netweblogic Login With Ajax 3.0.1
Netweblogic Login With Ajax 2.21
Netweblogic Login With Ajax 2.1.1
Netweblogic Login With Ajax
Netweblogic Login With Ajax 3.0.3
Netweblogic Login With Ajax 3.0.2
Netweblogic Login With Ajax 2.2
Netweblogic Login With Ajax 2.1.5
Netweblogic Login With Ajax 2.1.4
Netweblogic Login With Ajax 2.1.3
Netweblogic Login With Ajax 2.1.2
Netweblogic Login With Ajax 3.0
Netweblogic Login With Ajax 3.0b
Netweblogic Login With Ajax 2.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2006-4304
CVE-2024-4240
arbitrary
CVE-2024-31601
XSS
CVE-2023-20198
CVE-2024-4256
CVE-2024-3342
encryption
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »