Search Results (Refine Search)
- Keyword (text search): wordpress
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2016-10934 |
The check-email plugin before 0.5.2 for WordPress has XSS. Published: August 27, 2019; 8:15:11 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2015-9349 |
The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser. Published: August 27, 2019; 8:15:11 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2015-9347 |
The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors. Published: August 27, 2019; 8:15:11 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2015-9346 |
The cp-polls plugin before 1.0.5 for WordPress has XSS. Published: August 27, 2019; 8:15:11 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2015-9345 |
The link-log plugin before 2.0 for WordPress has HTTP Response Splitting. Published: August 27, 2019; 8:15:11 AM -0400 |
V4.0:(not available) V3.0: 7.5 HIGH V2.0: 5.0 MEDIUM |
CVE-2015-9344 |
The link-log plugin before 2.1 for WordPress has SQL injection. Published: August 27, 2019; 8:15:11 AM -0400 |
V4.0:(not available) V3.0: 9.8 CRITICAL V2.0: 7.5 HIGH |
CVE-2015-9343 |
The wp-rollback plugin before 1.2.3 for WordPress has CSRF. Published: August 27, 2019; 8:15:11 AM -0400 |
V4.0:(not available) V3.0: 8.8 HIGH V2.0: 6.8 MEDIUM |
CVE-2015-9342 |
The wp-rollback plugin before 1.2.3 for WordPress has XSS. Published: August 27, 2019; 8:15:11 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2014-10395 |
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list. Published: August 27, 2019; 8:15:11 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2019-15092 |
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class. Published: August 23, 2019; 5:15:11 PM -0400 |
V4.0:(not available) V3.0: 7.3 HIGH V2.0: 6.0 MEDIUM |
CVE-2019-15329 |
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. Published: August 22, 2019; 4:15:12 PM -0400 |
V4.0:(not available) V3.0: 8.8 HIGH V2.0: 6.8 MEDIUM |
CVE-2019-15328 |
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS. Published: August 22, 2019; 4:15:12 PM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2019-15327 |
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data. Published: August 22, 2019; 4:15:12 PM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2019-15326 |
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal. Published: August 22, 2019; 4:15:12 PM -0400 |
V4.0:(not available) V3.0: 7.5 HIGH V2.0: 5.0 MEDIUM |
CVE-2018-20987 |
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. Published: August 22, 2019; 4:15:11 PM -0400 |
V4.0:(not available) V3.0: 9.8 CRITICAL V2.0: 7.5 HIGH |
CVE-2018-20986 |
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors. Published: August 22, 2019; 4:15:11 PM -0400 |
V4.0:(not available) V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2017-18585 |
The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal. Published: August 22, 2019; 4:15:11 PM -0400 |
V4.0:(not available) V3.0: 8.1 HIGH V2.0: 5.5 MEDIUM |
CVE-2017-18579 |
The corner-ad plugin before 1.0.8 for WordPress has XSS. Published: August 22, 2019; 4:15:11 PM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2017-18578 |
The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS. Published: August 22, 2019; 4:15:11 PM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2016-10929 |
The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in. Published: August 22, 2019; 4:15:11 PM -0400 |
V4.0:(not available) V3.0: 5.3 MEDIUM V2.0: 5.0 MEDIUM |