The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achi…
The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that …
CVSS 3.1
The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that …
CVSS 3.1
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on…
CVSS 8.8
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 10.2.1 via deserialization of untrusted input . This makes…
CVSS 8.8
The Smart Popup by Supsystic plugin for WordPress is vulnerable to generic SQL Injection via the 'sidx' parameter in all versions up to, and including, 1.13.2 due to insufficient escaping on the user supplied parameter …
CVSS 4.9
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the ' ' parameter in all versions up to, and including, 3.6.6 due to insufficient input…
CVSS 4.7
The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions …
CVSS 6.4
The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[ ] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insuffic…
CVSS 5.4
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'not_found' parameter in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escapin…
CVSS 6.4
The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a Wor…
CVSS 9.1
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute in all versions up to, and including, 7.5.54.7212 due to insufficient input sanitiz…
CVSS 6.4