CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
WordPress amr personalise Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress amr personalise plugin, affecting versions through 2.10. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Post-to-Post Links Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Post-to-Post Links plugin, affecting versions through 4.2. This issue arises from improper input sanitization during web page generation, allowing malicious users to inject scripts that are executed when other users visit the affected page.
Nite Themes Nite Shortcodes Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Nite Shortcodes WordPress plugin, affecting versions through 1.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the site.
Jens Remus WP krpano Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress WP krpano plugin, affecting versions through 1.2.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Better Protected Pages Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Better Protected Pages plugin, affecting versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.
Anshi Solutions Category D3 Tree Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Anshi Solutions Category D3 Tree plugin for WordPress, affecting versions through 1.1. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
PayForm WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the PayForm WordPress plugin, affecting versions through 2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.
LSD Google Maps Embedder CSRF Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the LSD Google Maps Embedder WordPress plugin, affecting versions through 1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Copyright Safeguard Footer Notice Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Copyright Safeguard Footer Notice plugin, affecting versions through 3.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.
WordPress CJ Custom Content Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress CJ Custom Content plugin, specifically in versions through 2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts that are stored and executed later.
WordPress Chess Tempo Viewer Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Chess Tempo Viewer plugin, affecting versions through 0.9.5. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Winning Portfolio Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Winning Portfolio plugin, affecting versions through 1.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WP Code Snippets WCS QR Code Generator Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Code Snippets WCS QR Code Generator plugin, affecting versions through 1.0. This vulnerability allows for the injection of malicious scripts that are executed when users visit the affected site.
WordPress Rollover Tab Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Rollover Tab plugin, affecting versions through 1.3.2. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Contact Form 7 Anti Spambot Missing Authorization Vulnerability
A broken access control vulnerability has been identified in the WordPress Contact Form 7 Anti Spambot plugin, affecting versions through 1.0.1. This vulnerability arises from missing authorization checks, which can be exploited by users to perform actions that require higher privileges.
Katz Web Services Debt Calculator WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Katz Web Services Debt Calculator WordPress plugin, specifically in versions through 1.0.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Eyouth Charity-Thermometer Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Eyouth Charity-Thermometer WordPress plugin, affecting versions through 1.1.2. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Daily Proverb Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Daily Proverb plugin, affecting versions through 2.0.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Alessandro Staniscia Simple Vertical Timeline DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Simple Vertical Timeline plugin, affecting versions through 0.1. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
YesStreaming.com Shoutcast and Icecast Web Radio Player Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com, affecting versions through 3.3. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.
WordPress Hotspots Analytics Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Hotspots Analytics plugin, affecting versions through 4.0.12. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.
WordPress Custom Widget Classes Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Custom Widget Classes plugin, specifically in versions through 1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Nilesh Shiragave WordPress Gallery Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Gallery Plugin by Nilesh Shiragave, affecting versions through 1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Top Flash Embed Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Top Flash Embed plugin, specifically in versions through 0.3.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Links/Problem Reporter Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Links/Problem Reporter plugin, affecting versions through 2.6.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject harmful scripts that could be executed in the context of the user's browser.
WordPress Admin Cleanup Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Admin Cleanup plugin, specifically in versions through 1.0.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users with higher privileges.
WordPress QR Code Generator Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress QR Code Generator plugin, affecting versions through 1.2.6. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
Jobair JB Horizontal Scroller News Ticker DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the Jobair JB Horizontal Scroller News Ticker plugin for WordPress, affecting versions through 1.0. This vulnerability arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
WordPress Data Guard Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Data Guard plugin, affecting versions 8 and prior. This issue arises from improper input sanitization during web page generation, allowing malicious users to inject harmful scripts that are executed when the affected page is viewed.
Strx Magic Floating Sidebar Maker Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Strx Magic Floating Sidebar Maker plugin for WordPress, affecting versions through 1.4.1. This vulnerability arises from improper input neutralization during web page generation, allowing malicious users to inject harmful scripts that are executed when the affected page is viewed.
WordPress Stop Comment Spam Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Stop Comment Spam plugin, affecting versions through 0.5.3. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject harmful scripts that are executed when the affected page is viewed.
Alex Thorpe Easy Shortcode Buttons Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Easy Shortcode Buttons WordPress plugin, affecting versions through 1.2. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the affected site.
WordPress FontAwesome.io ShortCodes Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress FontAwesome.io ShortCodes plugin, specifically in versions through 1.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress CNZZ&51LA Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the CNZZ&51LA plugin for WordPress, affecting versions through 1.0.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Category Custom Fields Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Category Custom Fields plugin, affecting versions through 1.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP Cookies Alert Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WP Cookies Alert plugin, specifically in versions through 1.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Content Security Policy Pro Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Content Security Policy Pro plugin, affecting versions through 1.3.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress More Link Modifier Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress More Link Modifier plugin, specifically in versions through 1.0.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.
WordPress MHR-Custom-Anti-Copy Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress MHR-Custom-Anti-Copy plugin, affecting versions through 2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.
Metaphor Creations Metaphor Widgets Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Metaphor Widgets plugin for WordPress, affecting versions through 2.4. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WordPress Root Cookie Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Root Cookie plugin, affecting versions through 1.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Len Slider Plugin Cross-Site Request Forgery Vulnerability Allowing Reflected Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Len Slider plugin, specifically in versions through 2.0.11. This vulnerability allows for Reflected Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.
WordPress Custom List Table Example Plugin Cross-Site Request Forgery Vulnerability Allowing Reflected Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Custom List Table Example plugin, specifically in versions through 1.4.1. This vulnerability allows for Reflected Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not adequately protect against CSRF, potentially enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.
WordPress Spiderpowa Embed PDF Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Spiderpowa Embed PDF plugin, affecting versions through 1.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
SEOReseller WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the SEOReseller Partner WordPress plugin, specifically in versions through 1.3.15. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP Service Payment Form With Authorize.net Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Service Payment Form With Authorize.net plugin, affecting versions through 2.6.0. This vulnerability allows for Reflected Cross-Site Scripting (XSS) attacks.
WordPress WP-Revive Adserver Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress WP-Revive Adserver plugin, affecting versions through 2.2.1. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Style Admin Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Style Admin plugin, specifically in versions through 1.4.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.
David Hamilton OrangeBox WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the David Hamilton OrangeBox WordPress plugin, affecting versions through 3.0.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress WP Options Editor Plugin Cross-Site Request Forgery Vulnerability Allowing Privilege Escalation
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Options Editor plugin, specifically in versions through 1.1. This vulnerability allows for privilege escalation by enabling attackers to trick users with higher privileges into performing actions they did not intend to.
