Vulnerabilities > Wpdeveloper

DATE CVE VULNERABILITY TITLE RISK
2023-11-07 CVE-2022-46809 Improper Neutralization of Formula Elements in a CSV File vulnerability in Wpdeveloper Reviewx
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerce: from n/a through 1.6.7.
network
low complexity
wpdeveloper CWE-1236
critical
9.8
2023-10-20 CVE-2023-4386 Deserialization of Untrusted Data vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function.
network
high complexity
wpdeveloper CWE-502
8.1
2023-10-20 CVE-2023-4402 Deserialization of Untrusted Data vulnerability in Wpdeveloper Essential Blocks and Essential Blocks PRO
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function.
network
low complexity
wpdeveloper CWE-502
critical
9.8
2023-08-29 CVE-2023-32241 Cross-site Scripting vulnerability in Wpdeveloper Essential Addons for Elementor
Unauth.
network
low complexity
wpdeveloper CWE-79
6.1
2023-08-10 CVE-2023-4282 Missing Authorization vulnerability in Wpdeveloper Embedpress
The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2.
network
low complexity
wpdeveloper CWE-862
4.3
2023-08-10 CVE-2023-4283 Unspecified vulnerability in Wpdeveloper Embedpress
The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpdeveloper
5.4
2023-07-20 CVE-2023-3779 Unspecified vulnerability in Wpdeveloper Essential Addons for Elementor
The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running the MailChimp block.
network
low complexity
wpdeveloper
5.3
2023-07-01 CVE-2020-36744 Unspecified vulnerability in Wpdeveloper Notificationx
The NotificationX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2.
network
low complexity
wpdeveloper
4.3
2023-06-27 CVE-2023-3371 Unspecified vulnerability in Wpdeveloper Embedpress
The User Registration plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3.
network
low complexity
wpdeveloper
7.5
2023-06-09 CVE-2023-2083 Unspecified vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6.
network
low complexity
wpdeveloper
4.3