Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wpdeveloper vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2022-0349
The NotificationX WordPress plugin prior to 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection
Wpdeveloper Notificationx
1 Github repository
7.5
CVSSv2
CVE-2022-0320
The Essential Addons for Elementor WordPress plugin prior to 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated malicious users to perform Local File Inclusion attack and read arbitrary files on the serv...
Wpdeveloper Essential Addons For Elementor
1 Github repository
6.8
CVSSv2
CVE-2021-24352
The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin prior to 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects.
Wpdeveloper Simple 301 Redirects
6.8
CVSSv2
CVE-2021-24353
The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin prior to 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.
Wpdeveloper Simple 301 Redirects
6.8
CVSSv2
CVE-2017-18504
The twitter-cards-meta plugin prior to 2.5.0 for WordPress has CSRF.
Wpdeveloper Twitter Cards Meta
6.5
CVSSv2
CVE-2021-24354
A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin prior to 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.
Wpdeveloper Simple 301 Redirects
6.5
CVSSv2
CVE-2021-24356
In the Simple 301 Redirects by BetterLinks WordPress plugin prior to 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on v...
Wpdeveloper Simple 301 Redirects
1 Github repository
4.3
CVSSv2
CVE-2022-0683
The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the ~/includes/Traits/Helper.php file which allows malicious users to inject arbitrary web scripts onto ...
Wpdeveloper Essential Addons For Elementor
4.3
CVSSv2
CVE-2017-18503
The twitter-cards-meta plugin prior to 2.5.0 for WordPress has XSS.
Wpdeveloper Twitter Cards Meta
4
CVSSv2
CVE-2021-24633
The Countdown Block WordPress plugin prior to 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.
Wpdeveloper Countdown Block
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »