Vulnerabilities > Wpdeveloper

DATE CVE VULNERABILITY TITLE RISK
2023-08-29 CVE-2023-32241 Cross-site Scripting vulnerability in Wpdeveloper Essential Addons for Elementor 5.4.8
Unauth.
network
low complexity
wpdeveloper CWE-79
6.1
2023-08-10 CVE-2023-4282 Missing Authorization vulnerability in Wpdeveloper Embedpress
The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2.
network
low complexity
wpdeveloper CWE-862
4.3
2023-08-10 CVE-2023-4283 Cross-site Scripting vulnerability in Wpdeveloper Embedpress
The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpdeveloper CWE-79
5.4
2023-07-20 CVE-2023-3779 Information Exposure vulnerability in Wpdeveloper Essential Addons for Elementor
The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running the MailChimp block.
network
low complexity
wpdeveloper CWE-200
5.3
2023-07-01 CVE-2020-36744 Cross-Site Request Forgery (CSRF) vulnerability in Wpdeveloper Notificationx
The NotificationX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2.
network
low complexity
wpdeveloper CWE-352
4.3
2023-06-27 CVE-2023-3371 Use of Hard-coded Cryptographic Key vulnerability in Wpdeveloper Embedpress
The User Registration plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3.
network
low complexity
wpdeveloper CWE-321
7.5
2023-06-09 CVE-2023-2083 Missing Authorization vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6.
network
low complexity
wpdeveloper CWE-862
4.3
2023-06-09 CVE-2023-2084 Missing Authorization vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6.
network
low complexity
wpdeveloper CWE-862
4.3
2023-06-09 CVE-2023-2085 Missing Authorization vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6.
network
low complexity
wpdeveloper CWE-862
4.3
2023-06-09 CVE-2023-2086 Missing Authorization vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6.
network
low complexity
wpdeveloper CWE-862
4.3