U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): WordPress
  • Search Type: Search All
There are 4,985 matching records.
Displaying matches 1 through 20.
Vuln ID Summary CVSS Severity
CVE-2022-2268

The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE

Published: July 04, 2022; 9:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1967

The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwanted actions, such as create and delete arbitrary teams as well as update the plugin's settings. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

Published: July 04, 2022; 9:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1946

The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue

Published: July 04, 2022; 9:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1301

The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

Published: July 04, 2022; 9:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-0250

The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting

Published: July 04, 2022; 9:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2021-25066

The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Published: July 04, 2022; 9:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2021-25056

The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Published: July 04, 2022; 9:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2013-4144

There is an object injection vulnerability in swfupload plugin for wordpress.

Published: June 30, 2022; 2:15:08 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2017-20108

A vulnerability classified as problematic has been found in Easy Table Plugin 1.6. This affects an unknown part of the file /wordpress/wp-admin/options-general.php. The manipulation with the input "><script>alert(1)</script> leads to basic cross site scripting. It is possible to initiate the attack remotely.

Published: June 29, 2022; 3:15:06 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-2041

The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

Published: June 27, 2022; 5:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-2040

The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

Published: June 27, 2022; 5:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1995

The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

Published: June 27, 2022; 5:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1994

The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

Published: June 27, 2022; 5:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1990

The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

Published: June 27, 2022; 5:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1977

The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

Published: June 27, 2022; 5:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1971

The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

Published: June 27, 2022; 5:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1964

The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

Published: June 27, 2022; 5:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1960

The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

Published: June 27, 2022; 5:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1953

The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first

Published: June 27, 2022; 5:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-1916

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site Scripting

Published: June 27, 2022; 5:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)