ABCDEFGHIJKLMNOPQRSTUVWXYZAAAB
1
NameVersion(s) AffectedFixed in VersionPlugin DirectoryVulnerabilityLink/Plugin StatusSuggested ActionPlugin/ThemeOther NotesSource
2
Contact Form by WD1.12.22 and earlier, see notes1.12.28contact-form-makerSQL Injectionhttps://wordpress.org/plugins/contact-form-maker/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all.
http://www.defensecode.com/advisories/DC-2018-05-004_WordPress_Contact_Form_Maker_Plugin_Advisory.pdf
3
Contact Form by WD1.12.22 and earlier, see notes1.12.28contact-form-makerCross-Site Scriptinghttps://wordpress.org/plugins/contact-form-maker/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all.
http://www.defensecode.com/advisories/DC-2018-05-004_WordPress_Contact_Form_Maker_Plugin_Advisory.pdf
4
Contact Form by WD1.12.22 and earlier, see notes1.12.28contact-form-makerCross-Site Request Forgeryhttps://wordpress.org/plugins/contact-form-maker/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all.
http://www.defensecode.com/advisories/DC-2018-05-004_WordPress_Contact_Form_Maker_Plugin_Advisory.pdf
5
Form Maker by WD1.12.27 and earlier, see notes1.12.28form-makerSQL Injectionhttps://wordpress.org/plugins/form-maker/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all.
http://www.defensecode.com/advisories/DC-2018-05-001_WordPress_Form_Maker_Plugin_Advisory.pdf
6
Form Maker by WD1.12.27 and earlier, see notes1.12.28form-makerCross-Site Scriptinghttps://wordpress.org/plugins/form-maker/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all.
http://www.defensecode.com/advisories/DC-2018-05-001_WordPress_Form_Maker_Plugin_Advisory.pdf
7
Form Maker by WD1.12.27 and earlier, see notes1.12.28form-makerCross-Site Request Forgeryhttps://wordpress.org/plugins/form-maker/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all.
http://www.defensecode.com/advisories/DC-2018-05-001_WordPress_Form_Maker_Plugin_Advisory.pdf
8
WooCommerce Category Banner Management1.1.0 and earlier, see notes1.1.1, see notesbanner-management-for-woocommerceUnauthenticated Settings Changehttps://wordpress.org/plugins/banner-management-for-woocommerce/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all. Developer indicates in changelog that the vulnerable code has been fixed and the WordPress plugin team has re-enabled the plugin in the public repository. HOWEVER, threatpress did not release the details of the vulnerability so there is no quick way to verify the code has been corrected adequately.
https://blog.threatpress.com/vulnerable-wordpress-plugins-multidots/
9
Add Social Share Messenger Buttons Whatsapp and Viberall, see notesunfixedadd-social-share-buttonsCross-Site Request Forgeryhttps://wordpress.org/plugins/add-social-share-buttons/RemovePlugin
Researcher doesn't indicate which specific versions are affected, assume all. Plugin is currently disabled in the public repository. Code was last updated on 20180606 so potentially might have a fix soon.
https://blog.threatpress.com/vulnerable-wordpress-plugins-multidots/
10
Advance Search for WooCommerce1.0.9 and earlier, see notes1.1, see noteswoo-advance-searchStored Cross-Site Scriptinghttps://wordpress.org/plugins/woo-advance-search/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all. Developer indicates in changelog that the vulnerable code has been fixed and the WordPress plugin team has re-enabled the plugin in the public repository. HOWEVER, threatpress did not release the details of the vulnerability so there is no quick way to verify the code has been corrected adequately.
https://blog.threatpress.com/vulnerable-wordpress-plugins-multidots/
11
EU Cookie Notice1.0.6 and earlier, see notes1.0.7, see noteseu-cookie-noticeCross-Site Request Forgeryhttps://wordpress.org/plugins/eu-cookie-notice/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all. Developer indicates in changelog that the vulnerable code has been fixed and the WordPress plugin team has re-enabled the plugin in the public repository. HOWEVER, threatpress did not release the details of the vulnerability so there is no quick way to verify the code has been corrected adequately.
https://blog.threatpress.com/vulnerable-wordpress-plugins-multidots/
12
Mass Pages Posts Creatorall, see notesunfixedmass-pagesposts-creatorAuthenticated Stored Cross-Site Scriptinghttps://wordpress.org/plugins/mass-pagesposts-creator/RemovePlugin
Researcher doesn't indicate which specific versions are affected, assume all. Plugin is currently disabled in the public repository. Code was last updated on 20180606 so potentially might have a fix soon.
https://blog.threatpress.com/vulnerable-wordpress-plugins-multidots/
13
Page Visit Counter4.2 and earlier, see notes4.3, see notespage-visit-counterSQL Injectionhttps://wordpress.org/plugins/page-visit-counter/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all. Developer indicates in changelog that the vulnerable code has been fixed and the WordPress plugin team has re-enabled the plugin in the public repository. HOWEVER, threatpress did not release the details of the vulnerability so there is no quick way to verify the code has been corrected adequately.
https://blog.threatpress.com/vulnerable-wordpress-plugins-multidots/
14
WooCommerce Checkout for Digital Goods2.1 and earlier, see notes2.2, see noteswoo-checkout-for-digital-goodsCross-Site Request Forgeryhttps://wordpress.org/plugins/woo-checkout-for-digital-goods/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all. Developer indicates in changelog that the vulnerable code has been fixed and the WordPress plugin team has re-enabled the plugin in the public repository. HOWEVER, threatpress did not release the details of the vulnerability so there is no quick way to verify the code has been corrected adequately.
https://blog.threatpress.com/vulnerable-wordpress-plugins-multidots/
15
WooCommerce Enhanced Ecommerce Analytics Integration with Conversion Tracking1.0.4 and earlier, see notes1.0.5, see notesecommerce-tracking-for-easy-digital-downloadCross-Site Request Forgeryhttps://wordpress.org/plugins/ecommerce-tracking-for-easy-digital-download/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all. Developer indicates in changelog that the vulnerable code has been fixed and the WordPress plugin team has re-enabled the plugin in the public repository. HOWEVER, threatpress did not release the details of the vulnerability so there is no quick way to verify the code has been corrected adequately.
https://blog.threatpress.com/vulnerable-wordpress-plugins-multidots/
16
WooCommerce Enhanced Ecommerce Analytics Integration with Conversion Tracking1.0.4 and earlier, see notes1.0.5, see notesecommerce-tracking-for-easy-digital-downloadStored Cross-Site Scriptinghttps://wordpress.org/plugins/ecommerce-tracking-for-easy-digital-download/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all. Developer indicates in changelog that the vulnerable code has been fixed and the WordPress plugin team has re-enabled the plugin in the public repository. HOWEVER, threatpress did not release the details of the vulnerability so there is no quick way to verify the code has been corrected adequately.
https://blog.threatpress.com/vulnerable-wordpress-plugins-multidots/
17
WooCommerce Product Attachmentall, see notesunfixedwoo-product-attachmentAuthenticated Stored Cross-Site Scriptinghttps://wordpress.org/plugins/woo-product-attachment/RemovePlugin
Researcher doesn't indicate which specific versions are affected, assume all. Plugin is currently disabled in the public repository. Code was last updated on 20180606 so potentially might have a fix soon.
https://blog.threatpress.com/vulnerable-wordpress-plugins-multidots/
18
Woo Quick Reports1.0.6 and earlier, see notes1.0.7, see noteswoo-quick-reportsStored Cross-Site Scriptinghttps://wordpress.org/plugins/woo-quick-reports/UpdatePlugin
Researcher doesn't indicate which specific versions are affected, assume all. Developer indicates in changelog that the vulnerable code has been fixed and the WordPress plugin team has re-enabled the plugin in the public repository. HOWEVER, threatpress did not release the details of the vulnerability so there is no quick way to verify the code has been corrected adequately.
https://blog.threatpress.com/vulnerable-wordpress-plugins-multidots/
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100