Page last updated:

Type

Affected Software

Latest Version

Description

Severity

Date

  • Plugin

    Code Embed

    <=

    2.5.1

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    6.5

    0 days ago

    Type

    Plugin

    6.5

    Affected Software

    Latest Version

    <=

    2.5.1

    Description

    pulse_description

    0 days ago

  • Plugin

    Post SMTP

    <=

    3.8.0

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    5.4

    0 days ago

    Type

    Plugin

    5.4

    Affected Software

    Latest Version

    <=

    3.8.0

    Description

    pulse_description

    0 days ago

  • Plugin

    Envira Photo Gallery

    <=

    1.12.3

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    5.9

    0 days ago

    Type

    Plugin

    5.9

    Affected Software

    Latest Version

    <=

    1.12.3

    Description

    pulse_description

    0 days ago

  • Plugin

    Google Analytics Dashboard for WordPress

    <=

    9.0.2

    Insecure Direct Object References (IDOR) – An insecure direct object reference vulnerability could allow a malicious actor to bypass authorization, authentication, access sensitive files/folders or interact with the database.

    8.8

    0 days ago

    Type

    Plugin

    8.8

    Affected Software

    Latest Version

    <=

    9.0.2

    Description

    pulse_description

    0 days ago

  • Plugin

    WPForms

    <=

    1.9.9.3

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    4.3

    0 days ago

    Type

    Plugin

    4.3

    Affected Software

    Latest Version

    <=

    1.9.9.3

    Description

    pulse_description

    0 days ago

  • Plugin

    The Events Calendar

    <=

    6.15.17

    Arbitrary File Download – This could allow a malicious actor to download any file from your website. This includes but is not limited to files that contain login credentials or backup files.

    7.5

    0 days ago

    Type

    Plugin

    7.5

    Affected Software

    Latest Version

    <=

    6.15.17

    Description

    pulse_description

    0 days ago

  • Plugin

    e2pdf

    <=

    1.28.15

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    0 days ago

    Type

    Plugin

    Affected Software

    Latest Version

    <=

    1.28.15

    Description

    pulse_description

    0 days ago

  • Plugin

    Calculated Fields Form

    <=

    5.4.5.0

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    6.5

    0 days ago

    Type

    Plugin

    6.5

    Affected Software

    Latest Version

    <=

    5.4.5.0

    Description

    pulse_description

    0 days ago

  • Plugin

    My Sticky Bar

    <=

    2.8.6

    SQL Injection – This could allow a malicious actor to directly interact with your database, including but not limited to stealing information.

    9.3

    0 days ago

    Type

    Plugin

    9.3

    Affected Software

    Latest Version

    <=

    2.8.6

    Description

    pulse_description

    0 days ago

  • Plugin

    WP Go Maps

    <=

    10.0.05

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    6.5

    0 days ago

    Type

    Plugin

    6.5

    Affected Software

    Latest Version

    <=

    10.0.05

    Description

    pulse_description

    0 days ago

  • Plugin

    Social Icons Widget & Block by WPZOOM

    <=

    4.5.8

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    4.3

    0 days ago

    Type

    Plugin

    4.3

    Affected Software

    Latest Version

    <=

    4.5.8

    Description

    pulse_description

    0 days ago

  • Plugin

    Widget Options

    <=

    4.1.3

    Remote Code Execution (RCE) – This could allow a malicious actor to execute commands on the target website. This can be used to gain backdoor access to then take full control of the website.

    9

    0 days ago

    Type

    Plugin

    9

    Affected Software

    Latest Version

    <=

    4.1.3

    Description

    pulse_description

    0 days ago

  • Plugin

    Yoast Dupliate Post

    <=

    4.5

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    5.4

    0 days ago

    Type

    Plugin

    5.4

    Affected Software

    Latest Version

    <=

    4.5

    Description

    pulse_description

    0 days ago

  • Plugin

    Ave Core

    <=

    2.9.1

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    6.3

    1 day ago

    Type

    Plugin

    6.3

    Affected Software

    Latest Version

    <=

    2.9.1

    Description

    pulse_description

    1 day ago

  • Plugin

    Formidable Forms

    <=

    6.28

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    7.5

    1 day ago

    Type

    Plugin

    7.5

    Affected Software

    Latest Version

    <=

    6.28

    Description

    pulse_description

    1 day ago

  • Plugin

    PDF Poster

    <=

    2.4.0

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    5.4

    1 day ago

    Type

    Plugin

    5.4

    Affected Software

    Latest Version

    <=

    2.4.0

    Description

    pulse_description

    1 day ago

  • Plugin

    Permalink Manager Lite

    <=

    2.5.2

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    5.3

    1 day ago

    Type

    Plugin

    5.3

    Affected Software

    Latest Version

    <=

    2.5.2

    Description

    pulse_description

    1 day ago

  • Plugin

    CMP – Coming Soon & Maintenance Plugin

    <=

    4.1.10

    Server Side Request Forgery (SSRF) – This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system.

    5.5

    2 days ago

    Type

    Plugin

    5.5

    Affected Software

    Latest Version

    <=

    4.1.10

    Description

    pulse_description

    2 days ago

  • Plugin

    Elementor

    <=

    3.35.5

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    6.5

    2 days ago

    Type

    Plugin

    6.5

    Affected Software

    Latest Version

    <=

    3.35.5

    Description

    pulse_description

    2 days ago

  • Plugin

    Really Simple SSL

    <=

    9.5.7

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    4.3

    2 days ago

    Type

    Plugin

    4.3

    Affected Software

    Latest Version

    <=

    9.5.7

    Description

    pulse_description

    2 days ago