Page last updated:

Type

Affected Software

Latest Version

Description

Severity

Date

  • Plugin

    WooCommerce

    <=

    11.2.0

    Privilege Escalation – A low-privilege user can become an admin and gain full control.

    7.2

    0 days ago

    Type

    Plugin

    7.2

    Affected Software

    Latest Version

    <=

    11.2.0

    Description

    pulse_description

    0 days ago

  • Plugin

    All In One SEO

    <=

    5.0.2.1

    Arbitrary Code Execution – Attackers can run their own code on your site’s server and take it over.

    5.3

    2 days ago

    Type

    Plugin

    5.3

    Affected Software

    Latest Version

    <=

    5.0.2.1

    Description

    pulse_description

    2 days ago

  • Plugin

    MainWP Child

    <=

    6.2.2

    Deserialization of untrusted data – Attackers can send crafted data that makes your server blindly trusts, to run commands or gain extra access.

    8.8

    2 days ago

    Type

    Plugin

    8.8

    Affected Software

    Latest Version

    <=

    6.2.2

    Description

    pulse_description

    2 days ago

  • Plugin

    Event Tickets

    <=

    5.30.0.1

    Broken Access Control – Users can access pages or perform actions they shouldn’t be allowed to, like viewing other people’s data.

    4.3

    3 days ago

    Type

    Plugin

    4.3

    Affected Software

    Latest Version

    <=

    5.30.0.1

    Description

    pulse_description

    3 days ago

  • Plugin

    Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

    <=

    3.7.12

    Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.

    7.1

    6 days ago

    Type

    Plugin

    7.1

    Affected Software

    Latest Version

    <=

    3.7.12

    Description

    pulse_description

    6 days ago

  • Plugin

    TranslatePress

    <=

    3.3.7

    Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.



    7.1

    6 days ago

    Type

    Plugin

    7.1

    Affected Software

    Latest Version

    <=

    3.3.7

    Description

    pulse_description

    6 days ago

  • Plugin

    CMB2

    <=

    2.13.2

    Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.



    7.1

    6 days ago

    Type

    Plugin

    7.1

    Affected Software

    Latest Version

    <=

    2.13.2

    Description

    pulse_description

    6 days ago

  • Plugin

    AltText.ai

    <=

    1.10.42

    Broken Access Control – Users can access pages or perform actions they shouldn’t be allowed to, like viewing other people’s data.



    4.3

    6 days ago

    Type

    Plugin

    4.3

    Affected Software

    Latest Version

    <=

    1.10.42

    Description

    pulse_description

    6 days ago

  • Plugin

    SEOPress

    <=

    10.3

    Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.

    4.9

    6 days ago

    Type

    Plugin

    4.9

    Affected Software

    Latest Version

    <=

    10.3

    Description

    pulse_description

    6 days ago

  • Plugin

    ElementsKit

    <=

    4.0.7

    Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.



    6.5

    7 days ago

    Type

    Plugin

    6.5

    Affected Software

    Latest Version

    <=

    4.0.7

    Description

    pulse_description

    7 days ago

  • Plugin

    Fluent Forms

    <=

    6.2.15

    Broken Access Control – Users can access pages or perform actions they shouldn’t be allowed to, like viewing other people’s data.

    5.3

    7 days ago

    Type

    Plugin

    5.3

    Affected Software

    Latest Version

    <=

    6.2.15

    Description

    pulse_description

    7 days ago

  • Plugin

    The Events Calendar

    <=

    6.17.5.1

    Broken Access Control – Users can access pages or perform actions they shouldn’t be allowed to, like viewing other people’s data.

    5.4

    8 days ago

    Type

    Plugin

    5.4

    Affected Software

    Latest Version

    <=

    6.17.5.1

    Description

    pulse_description

    8 days ago

  • Plugin

    Media Library Organizer

    <=

    2.1.4

    Broken Access Control – Users can access pages or perform actions they shouldn’t be allowed to, like viewing other people’s data.



    2.7

    8 days ago

    Type

    Plugin

    2.7

    Affected Software

    Latest Version

    <=

    2.1.4

    Description

    pulse_description

    8 days ago

  • Plugin

    Schema & Structured Data for WP & AMP

    <=

    1.67

    PHP Object Injection – Attackers can manipulate how the site processes data to run harmful actions on the server.



    8.8

    8 days ago

    Type

    Plugin

    8.8

    Affected Software

    Latest Version

    <=

    1.67

    Description

    pulse_description

    8 days ago

  • Plugin

    WP Popular Posts

    <=

    7.4.3

    Sensitive Data Exposure – Private information like passwords, emails, or payment details can be exposed and stolen by unauthorized parties.



    5.3

    8 days ago

    Type

    Plugin

    5.3

    Affected Software

    Latest Version

    <=

    7.4.3

    Description

    pulse_description

    8 days ago

  • Plugin

    Photo Gallery

    <=

    1.8.47

    PHP Object Injection – Attackers can manipulate how the site processes data to run harmful actions on the server.



    8.8

    8 days ago

    Type

    Plugin

    8.8

    Affected Software

    Latest Version

    <=

    1.8.47

    Description

    pulse_description

    8 days ago

  • Plugin

    MailChimp For WooCommerce

    <=

    6.3

    Insecure Direct Object References (IDOR) – Changing an ID in the URL can expose other people’s data.



    5.3

    10 days ago

    Type

    Plugin

    5.3

    Affected Software

    Latest Version

    <=

    6.3

    Description

    pulse_description

    10 days ago

  • Plugin

    Elementor

    <=

    4.3.2

    Cross Site Request Forgery (CSRF) – Logged-in users can be tricked into performing actions they didn’t intend, like changing passwords or making purchases.

    8.8

    13 days ago

    Type

    Plugin

    8.8

    Affected Software

    Latest Version

    <=

    4.3.2

    Description

    pulse_description

    13 days ago

  • Plugin

    ElementsKit Lite

    <=

    4.0.6

    Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.



    6.5

    15 days ago

    Type

    Plugin

    6.5

    Affected Software

    Latest Version

    <=

    4.0.6

    Description

    pulse_description

    15 days ago

  • Plugin

    Safe SVG

    <=

    2.5.1

    Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.

    6.5

    15 days ago

    Type

    Plugin

    6.5

    Affected Software

    Latest Version

    <=

    2.5.1

    Description

    pulse_description

    15 days ago