Search Results (20782 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-15896 1 Lifterlms 1 Lifterlms 2024-11-21 9.8 Critical
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.
CVE-2019-15895 1 Search Exclude Project 1 Search Exclude 2024-11-21 7.5 High
search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.
CVE-2019-15873 1 Metagauss 1 Profilegrid 2024-11-21 N/A
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code.
CVE-2019-15872 1 Wpbrigade 1 Loginpress 2024-11-21 N/A
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
CVE-2019-15871 1 Wpbrigade 1 Loginpress 2024-11-21 N/A
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
CVE-2019-15869 1 Jobcareer Project 1 Jobcareer 2024-11-21 N/A
The JobCareer theme before 2.5.1 for WordPress has stored XSS.
CVE-2019-15868 1 Wpaffiliatemanager 1 Affiliates Manager 2024-11-21 N/A
The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.
CVE-2019-15867 1 Omaksolutions 1 Slick-popup 2024-11-21 N/A
The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.
CVE-2019-15866 1 Crelly Slider Project 1 Crelly Slider 2024-11-21 N/A
The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_ajax_crellyslider_importSlider.
CVE-2019-15865 1 Holest 1 Breadcrumbs By Menu 2024-11-21 N/A
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.
CVE-2019-15864 1 Holest 1 Breadcrumbs By Menu 2024-11-21 N/A
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS.
CVE-2019-15863 1 Convertplug 1 Convertplus 2024-11-21 N/A
The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request for variants.
CVE-2019-15858 1 Webcraftic 1 Woody Ad Snippets 2024-11-21 8.8 High
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
CVE-2019-15842 1 Easy Pdf Restaurant Menu Upload Project 1 Easy Pdf Restaurant Menu Upload 2024-11-21 N/A
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
CVE-2019-15841 1 Facebook 1 Facebook For Woocommerce 2024-11-21 N/A
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
CVE-2019-15840 1 Facebook 1 Facebook For Woocommerce 2024-11-21 N/A
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
CVE-2019-15838 1 Kunalnagar 1 Custom 404 Pro 2024-11-21 N/A
The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
CVE-2019-15837 1 Bitwise-it 1 Webp Express 2024-11-21 N/A
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
CVE-2019-15836 1 Bootstrapped 1 Wp Ultimate Recipe 2024-11-21 N/A
The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
CVE-2019-15835 1 Wp Better Permalinks Project 1 Wp Better Permalinks 2024-11-21 N/A
The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.