CVE-2016-10891
The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.
All CVEs associated with "WordPress". Page 137/152 • 18152 CVEs.
Subscribe CVEs: RSS for “WordPress” · RSS (High+Critical only)
A curated feed of “WordPress”-related CVEs appears below. We currently track 18152 CVEs for this tag (all time). In the last 365 days, 4094 were published. Average CVSS is 6.3 (all time; 6.3 over 365d), and 27% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), CWE-862 - Missing Authorization, CWE-352 - Cross-Site Request Forgery (CSRF).
In our taxonomy this topic maps to a MODERATE impact class. CMS and plugins expand attack surface. Patch core, themes, and plugins, remove abandoned extensions, restrict admin access, enable WAF, and keep backups. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.
The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.
The duplicate-post plugin before 2.6 for WordPress has SQL injection.
The duplicate-post plugin before 2.6 for WordPress has XSS.
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
The sender plugin before 1.2.1 for WordPress has multiple XSS issues.
The rsvp plugin before 2.3.8 for WordPress has persistent XSS via the note field on the attendee-list screen.
The universal-analytics plugin before 1.3.1 for WordPress has XSS.
The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
The formbuilder plugin before 1.06 for WordPress has multiple XSS issues.
The profile-builder plugin before 2.2.5 for WordPress has XSS.
The flickr-justified-gallery plugin before 3.4.0 for WordPress has XSS.
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
The formbuilder plugin before 0.9.1 for WordPress has XSS via a Referer header.
The wp-slimstat plugin before 4.8.1 for WordPress has XSS.
The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue.
The wp-front-end-profile plugin before 0.2.2 for WordPress has XSS.
The updater plugin before 1.35 for WordPress has multiple XSS issues.
The content-audit plugin before 1.9.2 for WordPress has XSS.
The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues.
The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues.
The bws-google-analytics plugin before 1.7.1 for WordPress has multiple XSS issues.
The booking-sms plugin before 1.1.0 for WordPress has XSS.
The analytics-tracker plugin before 1.1.1 for WordPress has XSS via a search event.
The ad-buttons plugin before 2.3.2 for WordPress has XSS.
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.
The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
The uji-countdown plugin before 2.0.7 for WordPress has XSS.
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes.
The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.
The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes.
The visitors-online plugin before 1.0.0 for WordPress has multiple XSS issues.
The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.
The share-on-diaspora plugin before 0.7.2 for WordPress has reflected XSS in share URL parameters.
The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.
The total-security plugin before 3.4.1 for WordPress has XSS.
The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.
The seo-redirection plugin before 4.3 for WordPress has stored XSS.
The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
The user-role plugin before 1.5.6 for WordPress has multiple XSS issues.
The rimons-twitter-widget plugin before 1.3 for WordPress has XSS.
The realty plugin before 1.1.0 for WordPress has multiple XSS issues.
The raygun4wp plugin before 1.8.3 for WordPress has XSS in the settings, a different issue than CVE-2017-9288.
The rating-bws plugin before 0.2 for WordPress has multiple XSS issues.
The promobar plugin before 1.1.1 for WordPress has multiple XSS issues.
The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.
The pagination plugin before 1.0.7 for WordPress has multiple XSS issues.
The moreads-se plugin before 1.4.7 for WordPress has XSS.
The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.
The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.
The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book.
The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.
The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.
The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser.
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
The wp-all-import plugin before 3.4.6 for WordPress has XSS.
The democracy-poll plugin before 5.4 for WordPress has XSS via update_l10n in admin/class.DemAdminInit.php.
The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.
The wp-latest-posts plugin before 3.7.5 for WordPress has XSS.
The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=uninstall URI.
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.
The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
The user-access-manager plugin before 1.2 for WordPress has CSRF.
The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.
The js-jobs plugin before 1.0.7 for WordPress has CSRF.
The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion.
The companion-auto-update plugin before 3.2.1 for WordPress has CSRF.
The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.
The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input.
The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.
The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.
The xo-security plugin before 1.5.3 for WordPress has XSS.
The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
The note-press plugin before 0.1.2 for WordPress has SQL injection.
The olimometer plugin before 2.57 for WordPress has SQL injection.
The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection.
The visitors-online plugin before 0.4 for WordPress has SQL injection.
The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the s…
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQ…
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1…
The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=update_title_options isAutoSaveValveChecked or isDisableAllPagesValveChecked parame…
The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGalleryAjax&grsAction=shortcode task parameter,
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads…
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.
The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.
The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.