ABCDEFGHIJKLMNOPQRSTUVWXYZAAAB
1
NameVersion(s) AffectedFixed in VersionPlugin DirectoryVulnerabilityLink/Plugin StatusSuggested ActionPlugin/ThemeOther NotesSource
2
WooCommerce3.4.5 and earlier3.4.6woocommerceAuthenticated Code Injectionhttps://wordpress.org/plugins/woocommerce/UpdatePlugin
https://wpvulndb.com/vulnerabilities/9137
3
Tajerunsure, see notesunfixedtajerStored Cross-Site Scriptinghttps://wordpress.org/plugins/tajer/RemovePluginPlugin closed
http://www.vapidlabs.com/advisory.php?v=205
4
WordFence7.1.12 and earlier, see notes7.1.14wordfenceUsername Enumeration Prevention Bypasshttps://wordpress.org/plugins/wordfence/UpdatePlugin
https://packetstormsecurity.com/files/149845/waraxe-2010-SA109.txt
5
WordFence7.1.12 and earlier, see notes7.1.14wordfenceMultiple Cross-Site Scriptinghttps://wordpress.org/plugins/wordfence/UpdatePlugin
https://packetstormsecurity.com/files/149845/waraxe-2010-SA109.txt
6
WordFence7.1.12 and earlier, see notes7.1.14wordfencePath Disclosurehttps://wordpress.org/plugins/wordfence/UpdatePlugin
https://packetstormsecurity.com/files/149845/waraxe-2010-SA109.txt
7
csv2wpec-couponallunfixedcsv2wpec-couponFile Uploadhttps://wordpress.org/plugins/csv2wpec-coupon/Remove ImmediatelyPlugin
http://www.vapidlabs.com/advisory.php?v=153
8
WP Fastest Cache0.8.8.5 and earlier.8.8.6wp-fastest-cacheCross-Site Scriptinghttps://wordpress.org/plugins/wp-fastest-cache/UpdatePlugin
https://wordpress.org/plugins/wp-fastest-cache/#developers changelog and https://www.pluginvulnerabilities.com/2018/10/09/vulnerability-details-csrf-xss-vulnerability-in-wp-fastest-cache/
9
Sitepress Multilingual CMS3.6.3 and earlier4.0sitepress-multilingual-cmsStored Cross-Site Scriptinghttps://wpml.org/UpdatePlugin
https://seclists.org/bugtraq/2018/Oct/24
10
WP DSGVO Toolsall, see notesunfixedshapepress-dsgvoObject Injectionhttps://wordpress.org/plugins/shapepress-dsgvo/RemovePlugin
Researcher doesn't indicate when the vulnerability was introduced. Quick looks shows it's in at least the last two releases. Assume all.
https://www.pluginvulnerabilities.com/2018/10/05/the-continued-inappropriate-behavior-of-wordpress-has-lead-to-this-disclosure-of-an-exploitable-vulnerability-in-a-plugin-with-30000-active-installs/
11
VendorFuel1.3.0 and earlier1.3.1vendorfuelRestricted File Uploadhttps://wordpress.org/plugins/vendorfuel/UpdatePlugin
https://www.pluginvulnerabilities.com/2018/10/04/our-proactive-monitoring-caught-a-restricted-file-upload-vulnerability-in-vendorfuel/
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100