CVE-2019-15647
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.
All CVEs associated with "WordPress". Page 136/152 • 18152 CVEs.
Subscribe CVEs: RSS for “WordPress” · RSS (High+Critical only)
A curated feed of “WordPress”-related CVEs appears below. We currently track 18152 CVEs for this tag (all time). In the last 365 days, 4094 were published. Average CVSS is 6.3 (all time; 6.3 over 365d), and 27% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), CWE-862 - Missing Authorization, CWE-352 - Cross-Site Request Forgery (CSRF).
In our taxonomy this topic maps to a MODERATE impact class. CMS and plugins expand attack surface. Patch core, themes, and plugins, remove abandoned extensions, restrict admin access, enable WAF, and keep backups. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.
The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.
The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
The anycomment plugin before 0.0.33 for WordPress has XSS.
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.
The check-email plugin before 0.5.2 for WordPress has XSS.
The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.
The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors.
The cp-polls plugin before 1.0.5 for WordPress has XSS.
The link-log plugin before 2.0 for WordPress has HTTP Response Splitting.
The link-log plugin before 2.1 for WordPress has SQL injection.
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
The wp-rollback plugin before 1.2.3 for WordPress has XSS.
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported C…
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal.
The corner-ad plugin before 1.0.8 for WordPress has XSS.
The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.
The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in.
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
The email-newsletter plugin through 20.15 for WordPress has SQL injection.
The cforms2 plugin before 10.5 for WordPress has XSS.
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.
The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
The cforms2 plugin before 10.2 for WordPress has XSS.
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
The ad-inserter plugin before 2.4.20 for WordPress has path traversal.
The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion.
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.
The post-pay-counter plugin before 2.731 for WordPress has no permissions check for an update-settinga action.
The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.
The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues.
The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list.
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation.
The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.
The ebook-download plugin before 1.2 for WordPress has directory traversal.
The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.
The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.
The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.
The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.
The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
The tubepress plugin before 1.6.5 for WordPress has XSS.
The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens.
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.
The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
The gnucommerce plugin before 1.4.2 for WordPress has XSS.
The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316.
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.
The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a different vulnerability than CVE-2012-2633.
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
The clean-login plugin before 1.5.1 for WordPress has reflected XSS.
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.
The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page.
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.
The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.
The embed-comment-images plugin before 0.6 for WordPress has XSS.
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
The smokesignal plugin before 1.2.7 for WordPress has XSS.
The megamenu plugin before 2.4 for WordPress has XSS.
The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n.
The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.