Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 1.5 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2021-24799
The Far Future Expiry Header WordPress plugin prior to 1.5 does not have CSRF check when saving its settings, which could allow malicious users to make a logged in admin change them via a CSRF attack.
Tipsandtricks-hq Far Future Expiry Header
4.3
CVSSv2
CVE-2015-9447
The unite-gallery-lite plugin prior to 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
Unitegallery Unite Gallery Lite
4.3
CVSSv2
CVE-2017-14751
The Intense WP "WP Jobs" plugin 1.5 for WordPress has XSS, related to the Job Qualification field.
Intensewp Wp Jobs 1.5
Intensewp Wp Jobs 1.1
Intensewp Wp Jobs 1.3
Intensewp Wp Jobs 1.0
Intensewp Wp Jobs 1.2
Intensewp Wp Jobs 1.4
4.3
CVSSv2
CVE-2014-8584
Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin prior to 1.5.2 for WordPress allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Web-dorado Web-dorado Spider Video Player 1.4.7
Web-dorado Web-dorado Spider Video Player 1.5.1
Web-dorado Web-dorado Spider Video Player 1.4.9
Web-dorado Web-dorado Spider Video Player 1.5
Web-dorado Web-dorado Spider Video Player 1.4.8
4.3
CVSSv2
CVE-2014-5344
Multiple cross-site scripting (XSS) vulnerabilities in the Mobiloud (mobiloud-mobile-app-plugin) plugin prior to 2.3.8 for WordPress allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third pa...
Mobiloud Mobiloud 2.3.1
Mobiloud Mobiloud 2.1
Mobiloud Mobiloud 1.8.11
Mobiloud Mobiloud 1.8.9
Mobiloud Mobiloud 1.8.2
Mobiloud Mobiloud 1.8.0
Mobiloud Mobiloud 1.6.2
Mobiloud Mobiloud 1.6
Mobiloud Mobiloud 1.4
Mobiloud Mobiloud 1.3.7
Mobiloud Mobiloud 1.2.5
Mobiloud Mobiloud 1.0
Mobiloud Mobiloud 1.8.8
Mobiloud Mobiloud 1.8.7
Mobiloud Mobiloud 1.8.6
Mobiloud Mobiloud 1.8.5
Mobiloud Mobiloud 1.5.3
Mobiloud Mobiloud 1.5.2
Mobiloud Mobiloud 1.5.1
Mobiloud Mobiloud 1.5
Mobiloud Mobiloud 1.9.0
Mobiloud Mobiloud 1.8.16
4.3
CVSSv2
CVE-2014-4855
Cross-site scripting (XSS) vulnerability in the Polylang plugin prior to 1.5.2 for WordPress allows remote malicious users to inject arbitrary web script or HTML via vectors related to a user description. NOTE: some of these details are obtained from third party information.
Polylang Plugin Project Polylang
Polylang Plugin Project Polylang 1.5
4.3
CVSSv2
CVE-2014-4554
Cross-site scripting (XSS) vulnerability in templates/download.php in the SS Downloads plugin prior to 1.5 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the title parameter.
Ss Downloads Project Ss Downloads
4.3
CVSSv2
CVE-2014-4579
Cross-site scripting (XSS) vulnerability in js/test.php in the Appointments Scheduler plugin 1.5 and previous versions for WordPress allows remote malicious users to inject arbitrary web script or HTML via the lang parameter.
Wp Appointments Schedules Project Wp Appointments Schedules
4.3
CVSSv2
CVE-2014-4596
Multiple cross-site scripting (XSS) vulnerabilities in js/button-snapapp.php in the SnapApp plugin 1.5 and previous versions for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) msg or (2) act parameter.
Snapapp Project Snapapp
4.3
CVSSv2
CVE-2012-2572
Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin prior to 1.16 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the Subject of an email.
Mindreantre Threewp Email Reflector 1.12
Mindreantre Threewp Email Reflector 1.11
Mindreantre Threewp Email Reflector 1.4
Mindreantre Threewp Email Reflector 1.3
Mindreantre Threewp Email Reflector 1.10
Mindreantre Threewp Email Reflector 1.9
Mindreantre Threewp Email Reflector 1.2
Mindreantre Threewp Email Reflector 1.1
Mindreantre Threewp Email Reflector
Mindreantre Threewp Email Reflector 1.8
Mindreantre Threewp Email Reflector 1.7
Mindreantre Threewp Email Reflector 1.0
Mindreantre Threewp Email Reflector 1.14
Mindreantre Threewp Email Reflector 1.13
Mindreantre Threewp Email Reflector 1.6
Mindreantre Threewp Email Reflector 1.5
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »