Page last updated:

Type

Affected Software

Latest Version

Description

Severity

Date

  • Plugin

    Cookie Notice & Compliance for GDPR / CCPA

    <=

    2.5.9

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    5.5

    0 days ago

    Type

    Plugin

    5.5

    Affected Software

    Latest Version

    <=

    2.5.9

    Description

    pulse_description

    0 days ago

  • Plugin

    Ninja Tables

    <=

    5.0.19

    Server Side Request Forgery (SSRF) – This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system.

    7.2

    0 days ago

    Type

    Plugin

    7.2

    Affected Software

    Latest Version

    <=

    5.0.19

    Description

    pulse_description

    0 days ago

  • Plugin

    WP Maps

    <=

    4.8.7

    PHP Object Injection – This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present.

    6.6

    0 days ago

    Type

    Plugin

    6.6

    Affected Software

    Latest Version

    <=

    4.8.7

    Description

    pulse_description

    0 days ago

  • Plugin

    All-in-One WP Migration

    <=

    7.0

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    5.9

    0 days ago

    Type

    Plugin

    5.9

    Affected Software

    Latest Version

    <=

    7.0

    Description

    pulse_description

    0 days ago

  • Plugin

    Pixel Manager for WooCommerce

    <=

    1.53.0

    Sensitive Data Exposure – This could allow a malicious actor to view sensitive information that is normally not available to regular users. This can be used to exploit other weaknesses in the system.

    5.3

    1 day ago

    Type

    Plugin

    5.3

    Affected Software

    Latest Version

    <=

    1.53.0

    Description

    pulse_description

    1 day ago

  • Plugin

    Cookie Notice & Compliance for GDPR / CCPA

    <=

    2.5.9

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    5.9

    1 day ago

    Type

    Plugin

    5.9

    Affected Software

    Latest Version

    <=

    2.5.9

    Description

    pulse_description

    1 day ago

  • Plugin

    WooCommerce PDF Invoices & Packing Slips

    <=

    5.0.0

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    4.3

    1 day ago

    Type

    Plugin

    4.3

    Affected Software

    Latest Version

    <=

    5.0.0

    Description

    pulse_description

    1 day ago

  • Plugin

    ProfilePress

    <=

    4.16.8

    Content Injection – This could allow a malicious actor to inject their own content into pages and posts of your website. This could also be abused to inject phishing pages into your website.

    4.3

    1 day ago

    Type

    Plugin

    4.3

    Affected Software

    Latest Version

    <=

    4.16.8

    Description

    pulse_description

    1 day ago

  • Plugin

    Thim Elementor Kit

    <=

    1.3.4

    Insecure Direct Object References (IDOR) – An insecure direct object reference vulnerability could allow a malicious actor to bypass authorization, authentication, access sensitive files/folders or interact with the database.

    4.3

    1 day ago

    Type

    Plugin

    4.3

    Affected Software

    Latest Version

    <=

    1.3.4

    Description

    pulse_description

    1 day ago

  • Plugin

    Elementor Website Builder

    <=

    3.33.1

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    4.3

    1 day ago

    Type

    Plugin

    4.3

    Affected Software

    Latest Version

    <=

    3.33.1

    Description

    pulse_description

    1 day ago

  • Plugin

    FluentForm

    <=

    6.1.8

    Insecure Direct Object References (IDOR) – An insecure direct object reference vulnerability could allow a malicious actor to bypass authorization, authentication, access sensitive files/folders or interact with the database.

    6.5

    1 day ago

    Type

    Plugin

    6.5

    Affected Software

    Latest Version

    <=

    6.1.8

    Description

    pulse_description

    1 day ago

  • Plugin

    Widgets for Google Reviews

    <=

    13.2.5

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    7.1

    1 day ago

    Type

    Plugin

    7.1

    Affected Software

    Latest Version

    <=

    13.2.5

    Description

    pulse_description

    1 day ago

  • Plugin

    Post SMTP

    <=

    3.6.2

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    5.4

    5 days ago

    Type

    Plugin

    5.4

    Affected Software

    Latest Version

    <=

    3.6.2

    Description

    pulse_description

    5 days ago

  • Plugin

    Custom Post Type UI

    <=

    1.18.1

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    4.8

    5 days ago

    Type

    Plugin

    4.8

    Affected Software

    Latest Version

    <=

    1.18.1

    Description

    pulse_description

    5 days ago

  • Plugin

    Autoptimize

    <=

    3.1.14

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    6.5

    6 days ago

    Type

    Plugin

    6.5

    Affected Software

    Latest Version

    <=

    3.1.14

    Description

    pulse_description

    6 days ago

  • Plugin

    TaxoPress

    <=

    3.41.0

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    4.3

    7 days ago

    Type

    Plugin

    4.3

    Affected Software

    Latest Version

    <=

    3.41.0

    Description

    pulse_description

    7 days ago

  • Plugin

    Advanced Custom Fields: Extended

    <=

    0.9.2

    Remote Code Execution (RCE) – This could allow a malicious actor to execute commands on the target website. This can be used to gain backdoor access to then take full control of the website.

    10

    7 days ago

    Type

    Plugin

    10

    Affected Software

    Latest Version

    <=

    0.9.2

    Description

    pulse_description

    7 days ago

  • Plugin

    Modula Image Gallery

    <=

    2.13.3

    Arbitrary File Deletion – This could allow a malicious actor to delete files from your website. If core files are deleted from your website, it could cause your site to break and stop functioning.

    6.8

    7 days ago

    Type

    Plugin

    6.8

    Affected Software

    Latest Version

    <=

    2.13.3

    Description

    pulse_description

    7 days ago

  • Plugin

    Beaver Builder

    <=

    2.9.4.1

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    5.4

    8 days ago

    Type

    Plugin

    5.4

    Affected Software

    Latest Version

    <=

    2.9.4.1

    Description

    pulse_description

    8 days ago

  • Plugin

    PowerPress Podcasting

    <=

    11.15.3

    Arbitrary File Upload – This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website.

    9.9

    9 days ago

    Type

    Plugin

    9.9

    Affected Software

    Latest Version

    <=

    11.15.3

    Description

    pulse_description

    9 days ago