Search Results (20757 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2016-4825 1 Welcart 1 Welcart E-commerce 2025-04-12 5.6 Medium
The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serialized data.
CVE-2014-5460 1 Tribulant 1 Tibulant Slideshow Gallery 2025-04-12 N/A
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.
CVE-2013-2107 1 Mail On Update Project 1 Mail On Update 2025-04-12 N/A
Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change the "List of alternative recipients" via the mailonupdate_mailto parameter in the mail-on-update page to wp-admin/options-general.php. NOTE: a third party claims that 5.2.1 and 5.2.2 are also vulnerable, but the issue might require a separate CVE identifier since this might reflect an incomplete fix.
CVE-2015-4337 1 Xcloner 1 Xcloner 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.
CVE-2015-1000008 1 Mp3-jplayer Project 1 Mp3-jplayer 2025-04-12 N/A
Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2
CVE-2014-4723 1 Easy Banners Plugin Project 1 Easy Banners 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the Easy Banners plugin 1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the name parameter to wp-admin/options-general.php.
CVE-2013-2705 1 Tipsandtricks-hq 1 Wordpress Simple Paypal Shopping Cart 2025-04-12 N/A
Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings.
CVE-2014-8724 1 Boldgrid 1 W3 Total Cache 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the "Cache key" in the HTML-Comments, as demonstrated by the PATH_INFO to the default URI.
CVE-2013-1408 1 Wysija Newsletters Project 1 Wysija Newsletters 2025-04-12 N/A
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.
CVE-2016-1000154 1 Browserweb 1 Whizz 2025-04-12 N/A
Reflected XSS in wordpress plugin whizz v1.0.7
CVE-2016-1000138 1 Indexisto Project 1 Indexisto 2025-04-12 N/A
Reflected XSS in wordpress plugin indexisto v1.0.5
CVE-2013-2699 1 Underconstruction Project 1 Underconstruction 2025-04-12 N/A
Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote attackers to hijack the authentication of administrators for requests that deactivate a plugin via unspecified vectors.
CVE-2013-2694 1 Wpsymposiumpro 1 Wp Symposium 2025-04-12 N/A
Open redirect vulnerability in invite.php in the WP Symposium plugin 13.04 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the u parameter.
CVE-2015-1366 1 Pixabay Images Project 1 Pixabay Images 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the image_user parameter.
CVE-2015-5622 2 Debian, Wordpress 2 Debian Linux, Wordpress 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.
CVE-2012-2580 1 Postieplugin 1 Postie 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email.
CVE-2015-7386 1 Ghozylab 1 Gallery - Photo Albums - Portfolio 2025-04-12 N/A
Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio plugin 1.3.47 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) Media Title or (2) Media Subtitle fields.
CVE-2014-7182 1 Codecabin 1 Wp Go Maps 2025-04-12 N/A
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.
CVE-2016-1000139 1 Infusionsoft Project 1 Infusionsoft 2025-04-12 N/A
Reflected XSS in wordpress plugin infusionsoft v1.5.11
CVE-2016-1000217 1 Zotpress Project 1 Zotpress 2025-04-12 N/A
Zotpress plugin for WordPress SQLi in zp_get_account()