CVE-2016-10888
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
All CVEs associated with "WordPress". Page 138/152 • 18152 CVEs.
Subscribe CVEs: RSS for “WordPress” · RSS (High+Critical only)
A curated feed of “WordPress”-related CVEs appears below. We currently track 18152 CVEs for this tag (all time). In the last 365 days, 4094 were published. Average CVSS is 6.3 (all time; 6.3 over 365d), and 27% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), CWE-862 - Missing Authorization, CWE-352 - Cross-Site Request Forgery (CSRF).
In our taxonomy this topic maps to a MODERATE impact class. CMS and plugins expand attack surface. Patch core, themes, and plugins, remove abandoned extensions, restrict admin access, enable WAF, and keep backups. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.
The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.
The google-document-embedder plugin before 2.6.2 for WordPress has XSS.
The google-document-embedder plugin before 2.6.1 for WordPress has XSS.
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter.
The newstatpress plugin before 1.0.1 for WordPress has SQL injection.
The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.
The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.
The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.
The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues.
The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.
The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search.
The liveforms plugin before 3.4.0 for WordPress has XSS.
The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues.
The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.
The custom-search-plugin plugin before 1.36 for WordPress has multiple XSS issues.
The custom-admin-page plugin before 0.1.2 for WordPress has multiple XSS issues.
The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.
The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.
The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues.
The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS.
The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.
The google-language-translator plugin before 5.0.06 for WordPress has XSS.
The contact-form-plugin plugin before 4.0.2 for WordPress has XSS.
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.
The simple-fields plugin before 1.4.11 for WordPress has XSS.
The liveforms plugin before 3.2.0 for WordPress has SQL injection.
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
The events-manager plugin before 5.6 for WordPress has code injection.
The events-manager plugin before 5.6 for WordPress has XSS.
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
The contact-form-plugin plugin before 3.96 for WordPress has XSS.
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
The contact-form-plugin plugin before 3.52 for WordPress has XSS.
The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues.
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
The ultimate-member plugin before 2.0.4 for WordPress has XSS.
The twitter-plugin plugin before 2.55 for WordPress has XSS.
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS.
The subscriber plugin before 1.3.5 for WordPress has multiple XSS issues.
The social-login-bws plugin before 0.2 for WordPress has multiple XSS issues.
The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.
The simple-membership plugin before 3.5.7 for WordPress has XSS.
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS.
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
The wp-database-backup plugin before 5.1.2 for WordPress has XSS.
The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.
The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.
The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.
The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
The wp-database-backup plugin before 4.3.1 for WordPress has XSS.
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
The wp-database-backup plugin before 4.3.3 for WordPress has XSS.
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_lim…
The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders.
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file attachment_id parameter.
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id paramete…
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.
The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.
admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?page=acfbs_admin_page CSRF.
The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove=true CSRF.
The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF.
core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.
A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQ…
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQ…
A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings.
The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute a…
The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_postratings_clear_fastest_cache and rm_folder_recursively in wpFastestCache.php…
An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using th…
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.
GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthenticated/unzuthorized Attacker can upload executable file in website. The component is: gourl.php#L56…
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-…
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no s…
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitizati…