ABCDEFGHIJKLMNOPQRSTUVWXYZAAAB
1
NameVersion(s) AffectedFixed in VersionPlugin DirectoryVulnerabilityLink/Plugin StatusSuggested ActionPlugin/ThemeOther NotesSource
2
Form Maker by 10Web<=1.13.31.13.4form-makerSQL Injectionhttps://wordpress.org/plugins/form-maker/UpdatePlugin
Current version is 1.13.10
https://seclists.org/fulldisclosure/2019/May/8
3
Launcher : Coming Soon & Maintenance Mode<= 1.0.81.0.9launcherStored Cross-Site Scriptinghttps://mythemeshop.com/plugins/launcher/UpdateTheme
https://mythemeshop.com/changelog/?product=launcher
https://vuldb.com/?id.134654
4
Register IPs<=1.8.01.8.1register-ip-multisiteStored Cross-Site Scriptinghttps://wordpress.org/plugins/register-ip-multisite/UpdatePlugin
https://wpvulndb.com/vulnerabilities/9274
5
Ultimate Member<=2.0.452.0.46ultimate-memberArbitrary File Download / Sensitive Information Disclosurehttps://wordpress.org/plugins/ultimate-member/Update ImmediatelyPlugin
https://blog.sucuri.net/2019/05/multiple-vulnerabilities-in-the-wordpress-ultimate-member-plugin.html
6
Ultimate Member<=2.0.462.0.47ultimate-memberArbitrary File Deletionhttps://wordpress.org/plugins/ultimate-member/Update ImmediatelyPlugin
https://blog.sucuri.net/2019/05/multiple-vulnerabilities-in-the-wordpress-ultimate-member-plugin.html
7
Ultimate Member<=2.0.472.0.48ultimate-memberMultiple Cross-Site Scriptinghttps://wordpress.org/plugins/ultimate-member/Update ImmediatelyPlugin
https://blog.sucuri.net/2019/05/multiple-vulnerabilities-in-the-wordpress-ultimate-member-plugin.html
8
Photo Gallery by 10Web<= 1.5.241.5.25photo-galleryUnknown, see noteshttps://wordpress.org/plugins/photo-gallery/UpdatePlugin
Changelog states "Fixed: Security issue"
https://wordpress.org/plugins/photo-gallery/#developers
9
Photo Gallery by 10Webunknow, see notesunfixed, see notesphoto-galleryLocal File Inclusionhttps://wordpress.org/plugins/photo-gallery/Use with caution, see notesPlugin
"Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions. Unable to verify if issue has been fixed yet
https://www.pluginvulnerabilities.com/2019/05/14/authenticated-local-file-inclusion-lfi-vulnerability-in-photo-gallery-by-10web/
10
Give<=2.4.62.4.7giveStored Cross-Site Scriptinghttps://wordpress.org/plugins/give/UpdatePlugin
https://blog.sucuri.net/2019/05/wordpress-plugin-give-stored-xss-for-donors.html
11
WP LIve Chat Support<=8.0.268.0.27wp-live-chat-supportStored Cross-Site Scriptinghttps://wordpress.org/plugins/wp-live-chat-support/Remove, see notesPlugin
Plugin has been closed in public repo, so you'll be unable to update through the WordPress interface. Either remove or get the code from svn
https://blog.sucuri.net/2019/05/persistent-cross-site-scripting-in-wp-live-chat-support-plugin.html
12
WP LIve Chat Supportunknow, see notesunfixedwp-live-chat-supportSensitive Information Disclosurehttps://wordpress.org/plugins/wp-live-chat-support/Remove, see notesPlugin
"Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions. Plugin has been closed in the public repository
https://www.pluginvulnerabilities.com/2019/05/16/gdpr-functionality-in-wordpress-plugin-wp-live-chat-support-allows-anyone-to-download-contents-of-chats-handled-through-it/
13
PPPT<=1.0.11.0.2ppptUnknown, see noteshttps://wordpress.org/plugins/pppt/UpdatePlugin
Changelog states "Security Fix"
https://wordpress.org/plugins/pppt/#developers
14
SAML SP Single Sign On<=4.8.704.8.71, see notesminiorange-saml-20-single-sign-onCross-Site Request Forgeryhttps://wordpress.org/plugins/miniorange-saml-20-single-sign-on/Update, use caution, see notesPlugin
Fix was supposed to be released in v4.8.71, but trac shows 4.8.72 with "Security patch" and plugin is now closed in public repo
https://blog.nintechnet.com/wordpress-latest-security-fixes/
15
FB Messenger Live Chatassume all, see notesunfixedfb-messenger-live-chatStored Cross-Site Scriptinghttps://wordpress.org/plugins/fb-messenger-live-chat/RemovePlugin
"Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions. Issue does not appear to be fixed yet
https://www.pluginvulnerabilities.com/2019/05/16/this-persistent-cross-site-scripting-xss-vulnerability-seems-likely-to-be-what-hackers-would-be-interested-in-fb-messenger-live-chat-for/
16
Toggle The Titleassume all, see notesunfixedtoggle-the-titleAuthenticated Stored Cross-Site Scriptinghttps://wordpress.org/plugins/toggle-the-title/RemovePlugin
"Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions. Plugin has been closed in the public repository
https://www.pluginvulnerabilities.com/2019/05/16/is-this-authenticated-persistent-cross-site-scripting-xss-vulnerability-what-hackers-would-be-interested-in-toggle-the-title-for/
17
FV Flowplayer Video Player<=7.3.13.7277.3.14.727fv-wordpress-flowplayerCross-Site Scriptinghttps://wordpress.org/plugins/fv-wordpress-flowplayer/UpdatePlugin
Changelog states "Security – fix for XSS vulnerability in email subscription"
https://wordpress.org/plugins/fv-wordpress-flowplayer/#developers
18
FV Flowplayer Video Player<=7.3.14.7287.3.15.727fv-wordpress-flowplayerInformation Disclosurehttps://wordpress.org/plugins/fv-wordpress-flowplayer/UpdatePlugin
"Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions.
https://www.pluginvulnerabilities.com/2019/05/15/information-disclosure-vulnerability-in-fv-player-fv-flowplayer-video-player/
19
Woocommerce Products Price Bulk Editassume all, see notesunfixed
mq-woocommerce-products-price-bulk-edit
Authenticated Stored Cross-Site Scriptinghttps://wordpress.org/plugins/mq-woocommerce-products-price-bulk-edit/RemovePlugin
"Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions. Plugin has been closed in the public repository
https://www.pluginvulnerabilities.com/2019/05/16/is-this-authenticated-persistent-cross-site-scripting-xss-vulnerability-what-hackers-would-be-interested-in-woocommerce-products-price-bulk-edit-for/
20
Zoho Sales IQ<=1.0.8 1.0.9zoho-salesiqCross-Site Scripting, see noteshttps://wordpress.org/plugins/zoho-salesiq/UpdatePlugin
Commit states "Added security bug fix", looking at code indicates cross-site scripting fix
https://plugins.trac.wordpress.org/changeset/2084532/
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100