Page last updated:

Type

Affected Software

Latest Version

Description

Severity

Date

  • Plugin

    Ave Core

    <=

    2.9.1

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    6.3

    0 days ago

    Type

    Plugin

    6.3

    Affected Software

    Latest Version

    <=

    2.9.1

    Description

    pulse_description

    0 days ago

  • Plugin

    Formidable Forms

    <=

    6.28

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    7.5

    0 days ago

    Type

    Plugin

    7.5

    Affected Software

    Latest Version

    <=

    6.28

    Description

    pulse_description

    0 days ago

  • Plugin

    PDF Poster

    <=

    2.4.0

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    5.4

    0 days ago

    Type

    Plugin

    5.4

    Affected Software

    Latest Version

    <=

    2.4.0

    Description

    pulse_description

    0 days ago

  • Plugin

    Permalink Manager Lite

    <=

    2.5.2

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    5.3

    0 days ago

    Type

    Plugin

    5.3

    Affected Software

    Latest Version

    <=

    2.5.2

    Description

    pulse_description

    0 days ago

  • Plugin

    CMP – Coming Soon & Maintenance Plugin

    <=

    4.1.10

    Server Side Request Forgery (SSRF) – This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system.

    5.5

    0 days ago

    Type

    Plugin

    5.5

    Affected Software

    Latest Version

    <=

    4.1.10

    Description

    pulse_description

    0 days ago

  • Plugin

    Elementor

    <=

    3.35.5

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    6.5

    0 days ago

    Type

    Plugin

    6.5

    Affected Software

    Latest Version

    <=

    3.35.5

    Description

    pulse_description

    0 days ago

  • Plugin

    Really Simple SSL

    <=

    9.5.7

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    4.3

    0 days ago

    Type

    Plugin

    4.3

    Affected Software

    Latest Version

    <=

    9.5.7

    Description

    pulse_description

    0 days ago

  • Plugin

    WordPress Meta Box

    <=

    5.11.1

    Arbitrary File Deletion – This could allow a malicious actor to delete files from your website. If core files are deleted from your website, it could cause your site to break and stop functioning.

    7.2

    4 days ago

    Type

    Plugin

    7.2

    Affected Software

    WordPress Meta Box

    Latest Version

    <=

    5.11.1

    Description

    pulse_description

    4 days ago

  • Plugin

    WooCommerce

    <=

    10.5.3

    Cross Site Request Forgery (CSRF) – This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication.

    4.3

    4 days ago

    Type

    Plugin

    4.3

    Affected Software

    WooCommerce

    Latest Version

    <=

    10.5.3

    Description

    pulse_description

    4 days ago

  • Theme

    Astra WordPress Theme

    <=

    4.12.3

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    6.5

    4 days ago

    Type

    Theme

    6.5

    Affected Software

    Astra WordPress Theme

    Latest Version

    <=

    4.12.3

    Description

    pulse_description

    4 days ago

  • Plugin

    Happy Addons for Elementor

    <=

    3.21.0

    Insecure Direct Object References (IDOR) – An insecure direct object reference vulnerability could allow a malicious actor to bypass authorization, authentication, access sensitive files/folders or interact with the database.

    5.4

    4 days ago

    Type

    Plugin

    5.4

    Affected Software

    Happy Addons for Elementor

    Latest Version

    <=

    3.21.0

    Description

    pulse_description

    4 days ago

  • Plugin

    DearFlip

    <=

    2.4.20

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    5.9

    4 days ago

    Type

    Plugin

    5.9

    Affected Software

    DearFlip

    Latest Version

    <=

    2.4.20

    Description

    pulse_description

    4 days ago

  • Plugin

    MC4WP

    <=

    4.11.1

    Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.

    6.5

    4 days ago

    Type

    Plugin

    6.5

    Affected Software

    MC4WP

    Latest Version

    <=

    4.11.1

    Description

    pulse_description

    4 days ago

  • Plugin

    WP Maps

    <=

    4.9.1

    SQL Injection – This could allow a malicious actor to directly interact with your database, including but not limited to stealing information.

    9.3

    4 days ago

    Type

    Plugin

    9.3

    Affected Software

    WP Maps

    Latest Version

    <=

    4.9.1

    Description

    pulse_description

    4 days ago

  • Plugin

    WP Rocket

    <=

    3.19.4

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    5.9

    4 days ago

    Type

    Plugin

    5.9

    Affected Software

    WP Rocket

    Latest Version

    <=

    3.19.4

    Description

    pulse_description

    4 days ago

  • Plugin

    Yoast SEO

    <=

    26.8

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    6.5

    4 days ago

    Type

    Plugin

    6.5

    Affected Software

    Yoast SEO

    Latest Version

    <=

    26.8

    Description

    pulse_description

    4 days ago

  • Plugin

    WP RSS Aggregator

    <=

    5.0.11

    Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

    7.1

    4 days ago

    Type

    Plugin

    7.1

    Affected Software

    WordPress WP RSS Aggregator

    Latest Version

    <=

    5.0.11

    Description

    pulse_description

    4 days ago

  • Plugin

    The Events Calendar

    <=

    6.15.17

    Arbitrary File Download – This could allow a malicious actor to download any file from your website. This includes but is not limited to files that contain login credentials or backup files.

    7.5

    4 days ago

    Type

    Plugin

    7.5

    Affected Software

    The Events Calendar

    Latest Version

    <=

    6.15.17

    Description

    pulse_description

    4 days ago

  • Plugin

    ExactMetrics

    <=

    7.1.0-9.0.2

    Insecure Direct Object References (IDOR) – An insecure direct object reference vulnerability could allow a malicious actor to bypass authorization, authentication, access sensitive files/folders or interact with the database.

    8.8

    4 days ago

    Type

    Plugin

    8.8

    Affected Software

    ExactMetrics

    Latest Version

    <=

    7.1.0-9.0.2

    Description

    pulse_description

    4 days ago

  • Plugin

    My Sticky Bar

    <=

    2.8.6

    SQL Injection – This could allow a malicious actor to directly interact with your database, including but not limited to stealing information.

    9.3

    4 days ago

    Type

    Plugin

    9.3

    Affected Software

    My Sticky Bar

    Latest Version

    <=

    2.8.6

    Description

    pulse_description

    4 days ago