Search Results (20782 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-13642 1 Siteorigin 1 Page Builder 2024-11-21 8.8 High
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the victim's browser.
CVE-2020-13641 1 Infolific 1 Real-time Find And Replace 2024-11-21 8.8 High
An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser.
CVE-2020-13640 1 Gvectors 1 Wpdiscuz 2024-11-21 9.8 Critical
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)
CVE-2020-13487 1 Bbpress 1 Bbpress 2024-11-21 4.8 Medium
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.
CVE-2020-13426 1 Bdtask 1 Multi-scheduler 2024-11-21 6.5 Medium
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.
CVE-2020-13126 1 Elementor 1 Elementor Page Builder 2024-11-21 9.9 Critical
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
CVE-2020-13125 1 Brainstormforce 1 Ultimate Addons For Elementor 2024-11-21 6.5 Medium
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
CVE-2020-12832 1 Simplefilelist 1 Simple-file-list 2024-11-21 9.8 Critical
WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.
CVE-2020-12800 1 Codedropz 1 Drag And Drop Multiple File Upload - Contact Form 7 2024-11-21 9.8 Critical
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
CVE-2020-12742 1 Iubenda 1 Iubenda-cookie-law-solution 2024-11-21 6.1 Medium
The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols.
CVE-2020-12696 1 Iframe Project 1 Iframe 2024-11-21 6.1 Medium
The iframe plugin before 4.5 for WordPress does not sanitize a URL.
CVE-2020-12675 1 Mappresspro 1 Mappress 2024-11-21 8.8 High
The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an incomplete fix for CVE-2020-12077.
CVE-2020-12462 1 Ninjaforms 1 Ninja Forms 2024-11-21 6.1 Medium
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
CVE-2020-12104 1 Internet-formation 1 Wp-advanced-search 2024-11-21 8.8 High
The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
CVE-2020-12077 1 Mappresspro 1 Mappress 2024-11-21 8.8 High
The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution.
CVE-2020-12076 1 Supsystic 1 Data Tables Generator 2024-11-21 8.8 High
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
CVE-2020-12075 1 Supsystic 1 Data Tables Generator 2024-11-21 8.8 High
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
CVE-2020-12074 1 Webtoffee 1 Import Export Wordpress Users 2024-11-21 8.8 High
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
CVE-2020-12073 1 Cyberchimps 1 Gutenberg \& Elementor Templates Importer For Responsive 2024-11-21 8.8 High
The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests.
CVE-2020-12070 1 Advanced-woo-search 1 Advanced Woo Search 2024-11-21 7.5 High
The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to includes/class-aws-search.php.