Search Results (20777 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-20971 1 Churchadminplugin 1 Church Admin 2024-11-21 N/A
The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.
CVE-2018-20970 1 Bestwebsoft 1 Pdf \& Print 2024-11-21 N/A
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.
CVE-2018-20968 1 Smackcoders 1 Ultimate Exporter 2024-11-21 N/A
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
CVE-2018-20967 1 Smackcoders 1 Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv 2024-11-21 N/A
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
CVE-2018-20966 1 Booster 1 Booster For Woocommerce 2024-11-21 N/A
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
CVE-2018-20965 1 Ultimatemember 1 Ultimate Member 2024-11-21 6.1 Medium
The ultimate-member plugin before 2.0.4 for WordPress has XSS.
CVE-2018-20964 1 Codepeople 1 Contact Form Email 2024-11-21 N/A
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
CVE-2018-20963 1 Codepeople 1 Contact Form Email 2024-11-21 N/A
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
CVE-2018-20853 1 Mailpoet 1 Mailpoet Newsletters 2024-11-21 5.3 Medium
An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks.
CVE-2018-20838 1 Magazine3 1 Amp For Wp 2024-11-21 N/A
ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.
CVE-2018-20714 1 Woocommerce 1 Woocommerce 2024-11-21 N/A
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.
CVE-2018-20556 1 Booking Calendar Project 1 Booking Calendar 2024-11-21 N/A
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
CVE-2018-20555 1 Designchemical 1 Social Network Tabs 2024-11-21 N/A
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.
CVE-2018-20463 1 Jsmol2wp Project 1 Jsmol2wp 2024-11-21 N/A
An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.
CVE-2018-20462 1 Jsmol2wp Project 1 Jsmol2wp 2024-11-21 N/A
An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter.
CVE-2018-20368 1 Averta 1 Master Slider 2024-11-21 N/A
The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.
CVE-2018-20231 1 Simbahosting 1 Two-factor-authentication 2024-11-21 N/A
Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation.
CVE-2018-20156 1 Designmodo 1 Wp Maintenance Mode 2024-11-21 N/A
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network.
CVE-2018-20155 1 Designmodo 1 Wp Maintenance Mode 2024-11-21 N/A
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings.
CVE-2018-20154 1 Designmodo 1 Wp Maintenance Mode 2024-11-21 N/A
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses.