| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | AA | AB | ||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | Name | Version(s) Affected | Fixed in Version | Plugin Directory | Vulnerability | Link/Plugin Status | Suggested Action | Plugin/Theme | Other Notes | Source | |||||||||||||||||||
2 | Form Maker by 10Web | <=1.13.3 | 1.13.4 | form-maker | SQL Injection | https://wordpress.org/plugins/form-maker/ | Update | Plugin | Current version is 1.13.10 | https://seclists.org/fulldisclosure/2019/May/8 | |||||||||||||||||||
3 | Launcher : Coming Soon & Maintenance Mode | <= 1.0.8 | 1.0.9 | launcher | Stored Cross-Site Scripting | https://mythemeshop.com/plugins/launcher/ | Update | Theme | https://mythemeshop.com/changelog/?product=launcher | https://vuldb.com/?id.134654 | |||||||||||||||||||
4 | Register IPs | <=1.8.0 | 1.8.1 | register-ip-multisite | Stored Cross-Site Scripting | https://wordpress.org/plugins/register-ip-multisite/ | Update | Plugin | https://wpvulndb.com/vulnerabilities/9274 | ||||||||||||||||||||
5 | Ultimate Member | <=2.0.45 | 2.0.46 | ultimate-member | Arbitrary File Download / Sensitive Information Disclosure | https://wordpress.org/plugins/ultimate-member/ | Update Immediately | Plugin | https://blog.sucuri.net/2019/05/multiple-vulnerabilities-in-the-wordpress-ultimate-member-plugin.html | ||||||||||||||||||||
6 | Ultimate Member | <=2.0.46 | 2.0.47 | ultimate-member | Arbitrary File Deletion | https://wordpress.org/plugins/ultimate-member/ | Update Immediately | Plugin | https://blog.sucuri.net/2019/05/multiple-vulnerabilities-in-the-wordpress-ultimate-member-plugin.html | ||||||||||||||||||||
7 | Ultimate Member | <=2.0.47 | 2.0.48 | ultimate-member | Multiple Cross-Site Scripting | https://wordpress.org/plugins/ultimate-member/ | Update Immediately | Plugin | https://blog.sucuri.net/2019/05/multiple-vulnerabilities-in-the-wordpress-ultimate-member-plugin.html | ||||||||||||||||||||
8 | Photo Gallery by 10Web | <= 1.5.24 | 1.5.25 | photo-gallery | Unknown, see notes | https://wordpress.org/plugins/photo-gallery/ | Update | Plugin | Changelog states "Fixed: Security issue" | https://wordpress.org/plugins/photo-gallery/#developers | |||||||||||||||||||
9 | Photo Gallery by 10Web | unknow, see notes | unfixed, see notes | photo-gallery | Local File Inclusion | https://wordpress.org/plugins/photo-gallery/ | Use with caution, see notes | Plugin | "Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions. Unable to verify if issue has been fixed yet | https://www.pluginvulnerabilities.com/2019/05/14/authenticated-local-file-inclusion-lfi-vulnerability-in-photo-gallery-by-10web/ | |||||||||||||||||||
10 | Give | <=2.4.6 | 2.4.7 | give | Stored Cross-Site Scripting | https://wordpress.org/plugins/give/ | Update | Plugin | https://blog.sucuri.net/2019/05/wordpress-plugin-give-stored-xss-for-donors.html | ||||||||||||||||||||
11 | WP LIve Chat Support | <=8.0.26 | 8.0.27 | wp-live-chat-support | Stored Cross-Site Scripting | https://wordpress.org/plugins/wp-live-chat-support/ | Remove, see notes | Plugin | Plugin has been closed in public repo, so you'll be unable to update through the WordPress interface. Either remove or get the code from svn | https://blog.sucuri.net/2019/05/persistent-cross-site-scripting-in-wp-live-chat-support-plugin.html | |||||||||||||||||||
12 | WP LIve Chat Support | unknow, see notes | unfixed | wp-live-chat-support | Sensitive Information Disclosure | https://wordpress.org/plugins/wp-live-chat-support/ | Remove, see notes | Plugin | "Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions. Plugin has been closed in the public repository | https://www.pluginvulnerabilities.com/2019/05/16/gdpr-functionality-in-wordpress-plugin-wp-live-chat-support-allows-anyone-to-download-contents-of-chats-handled-through-it/ | |||||||||||||||||||
13 | PPPT | <=1.0.1 | 1.0.2 | pppt | Unknown, see notes | https://wordpress.org/plugins/pppt/ | Update | Plugin | Changelog states "Security Fix" | https://wordpress.org/plugins/pppt/#developers | |||||||||||||||||||
14 | SAML SP Single Sign On | <=4.8.70 | 4.8.71, see notes | miniorange-saml-20-single-sign-on | Cross-Site Request Forgery | https://wordpress.org/plugins/miniorange-saml-20-single-sign-on/ | Update, use caution, see notes | Plugin | Fix was supposed to be released in v4.8.71, but trac shows 4.8.72 with "Security patch" and plugin is now closed in public repo | https://blog.nintechnet.com/wordpress-latest-security-fixes/ | |||||||||||||||||||
15 | FB Messenger Live Chat | assume all, see notes | unfixed | fb-messenger-live-chat | Stored Cross-Site Scripting | https://wordpress.org/plugins/fb-messenger-live-chat/ | Remove | Plugin | "Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions. Issue does not appear to be fixed yet | https://www.pluginvulnerabilities.com/2019/05/16/this-persistent-cross-site-scripting-xss-vulnerability-seems-likely-to-be-what-hackers-would-be-interested-in-fb-messenger-live-chat-for/ | |||||||||||||||||||
16 | Toggle The Title | assume all, see notes | unfixed | toggle-the-title | Authenticated Stored Cross-Site Scripting | https://wordpress.org/plugins/toggle-the-title/ | Remove | Plugin | "Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions. Plugin has been closed in the public repository | https://www.pluginvulnerabilities.com/2019/05/16/is-this-authenticated-persistent-cross-site-scripting-xss-vulnerability-what-hackers-would-be-interested-in-toggle-the-title-for/ | |||||||||||||||||||
17 | FV Flowplayer Video Player | <=7.3.13.727 | 7.3.14.727 | fv-wordpress-flowplayer | Cross-Site Scripting | https://wordpress.org/plugins/fv-wordpress-flowplayer/ | Update | Plugin | Changelog states "Security – fix for XSS vulnerability in email subscription" | https://wordpress.org/plugins/fv-wordpress-flowplayer/#developers | |||||||||||||||||||
18 | FV Flowplayer Video Player | <=7.3.14.728 | 7.3.15.727 | fv-wordpress-flowplayer | Information Disclosure | https://wordpress.org/plugins/fv-wordpress-flowplayer/ | Update | Plugin | "Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions. | https://www.pluginvulnerabilities.com/2019/05/15/information-disclosure-vulnerability-in-fv-player-fv-flowplayer-video-player/ | |||||||||||||||||||
19 | Woocommerce Products Price Bulk Edit | assume all, see notes | unfixed | mq-woocommerce-products-price-bulk-edit | Authenticated Stored Cross-Site Scripting | https://wordpress.org/plugins/mq-woocommerce-products-price-bulk-edit/ | Remove | Plugin | "Researcher" doesn't state when the vulnerability was introduced to the code base. Assume all previous versions. Plugin has been closed in the public repository | https://www.pluginvulnerabilities.com/2019/05/16/is-this-authenticated-persistent-cross-site-scripting-xss-vulnerability-what-hackers-would-be-interested-in-woocommerce-products-price-bulk-edit-for/ | |||||||||||||||||||
20 | Zoho Sales IQ | <=1.0.8 | 1.0.9 | zoho-salesiq | Cross-Site Scripting, see notes | https://wordpress.org/plugins/zoho-salesiq/ | Update | Plugin | Commit states "Added security bug fix", looking at code indicates cross-site scripting fix | https://plugins.trac.wordpress.org/changeset/2084532/ | |||||||||||||||||||
21 | |||||||||||||||||||||||||||||
22 | |||||||||||||||||||||||||||||
23 | |||||||||||||||||||||||||||||
24 | |||||||||||||||||||||||||||||
25 | |||||||||||||||||||||||||||||
26 | |||||||||||||||||||||||||||||
27 | |||||||||||||||||||||||||||||
28 | |||||||||||||||||||||||||||||
29 | |||||||||||||||||||||||||||||
30 | |||||||||||||||||||||||||||||
31 | |||||||||||||||||||||||||||||
32 | |||||||||||||||||||||||||||||
33 | |||||||||||||||||||||||||||||
34 | |||||||||||||||||||||||||||||
35 | |||||||||||||||||||||||||||||
36 | |||||||||||||||||||||||||||||
37 | |||||||||||||||||||||||||||||
38 | |||||||||||||||||||||||||||||
39 | |||||||||||||||||||||||||||||
40 | |||||||||||||||||||||||||||||
41 | |||||||||||||||||||||||||||||
42 | |||||||||||||||||||||||||||||
43 | |||||||||||||||||||||||||||||
44 | |||||||||||||||||||||||||||||
45 | |||||||||||||||||||||||||||||
46 | |||||||||||||||||||||||||||||
47 | |||||||||||||||||||||||||||||
48 | |||||||||||||||||||||||||||||
49 | |||||||||||||||||||||||||||||
50 | |||||||||||||||||||||||||||||
51 | |||||||||||||||||||||||||||||
52 | |||||||||||||||||||||||||||||
53 | |||||||||||||||||||||||||||||
54 | |||||||||||||||||||||||||||||
55 | |||||||||||||||||||||||||||||
56 | |||||||||||||||||||||||||||||
57 | |||||||||||||||||||||||||||||
58 | |||||||||||||||||||||||||||||
59 | |||||||||||||||||||||||||||||
60 | |||||||||||||||||||||||||||||
61 | |||||||||||||||||||||||||||||
62 | |||||||||||||||||||||||||||||
63 | |||||||||||||||||||||||||||||
64 | |||||||||||||||||||||||||||||
65 | |||||||||||||||||||||||||||||
66 | |||||||||||||||||||||||||||||
67 | |||||||||||||||||||||||||||||
68 | |||||||||||||||||||||||||||||
69 | |||||||||||||||||||||||||||||
70 | |||||||||||||||||||||||||||||
71 | |||||||||||||||||||||||||||||
72 | |||||||||||||||||||||||||||||
73 | |||||||||||||||||||||||||||||
74 | |||||||||||||||||||||||||||||
75 | |||||||||||||||||||||||||||||
76 | |||||||||||||||||||||||||||||
77 | |||||||||||||||||||||||||||||
78 | |||||||||||||||||||||||||||||
79 | |||||||||||||||||||||||||||||
80 | |||||||||||||||||||||||||||||
81 | |||||||||||||||||||||||||||||
82 | |||||||||||||||||||||||||||||
83 | |||||||||||||||||||||||||||||
84 | |||||||||||||||||||||||||||||
85 | |||||||||||||||||||||||||||||
86 | |||||||||||||||||||||||||||||
87 | |||||||||||||||||||||||||||||
88 | |||||||||||||||||||||||||||||
89 | |||||||||||||||||||||||||||||
90 | |||||||||||||||||||||||||||||
91 | |||||||||||||||||||||||||||||
92 | |||||||||||||||||||||||||||||
93 | |||||||||||||||||||||||||||||
94 | |||||||||||||||||||||||||||||
95 | |||||||||||||||||||||||||||||
96 | |||||||||||||||||||||||||||||
97 | |||||||||||||||||||||||||||||
98 | |||||||||||||||||||||||||||||
99 | |||||||||||||||||||||||||||||
100 |