| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | AA | AB | ||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | Name | Version(s) Affected | Fixed in Version | Plugin Directory | Vulnerability | Link/Plugin Status | Suggested Action | Plugin/Theme | Other Notes | Source | |||||||||||||||||||
2 | MapSVGLite | All, see notes | unfixed | mapsvg-lite-interactive-vector-maps | Authenticated Arbitrary File Upload | https://wordpress.org/plugins/mapsvg-lite-interactive-vector-maps/ | Remove Immediately | Plugin | Authenticated user with role as low as subscriber can upload arbitrary file. Researcher doesn't indicate which version the vulnerability was introduced | https://www.pluginvulnerabilities.com/2018/07/18/our-proactive-monitoring-caught-an-authenticated-arbitrary-file-upload-vulnerability-in-mapsvg-lite/ | |||||||||||||||||||
3 | Geo Mashup | 1.10.3 and earlier | 1.10.4 | geo-mashup | Cross-Site Scripting | https://wordpress.org/plugins/geo-mashup/ | Update | Plugin | https://wpvulndb.com/vulnerabilities/9105 | ||||||||||||||||||||
4 | FV Flowplayer Video Player | 6.1.2 through 6.6.4 | 6.6.5 | fv-wordpress-flowplayer | Cross-Site Scripting | https://wordpress.org/plugins/fv-wordpress-flowplayer/ | Update | Plugin | https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000078.html | ||||||||||||||||||||
5 | WP Job Manager | 1.31.0 and earlier, see notes | 1.31.1 | wp-job-manager | Cross-Site Scripting | https://wordpress.org/plugins/wp-job-manager/ | Update | Plugin | exploit db mentions the plugin being at v4.1.0, but that appears to be a typo | https://www.exploit-db.com/exploits/45031/ | |||||||||||||||||||
6 | all-in-one-favicon | all, see notes | unfixed | all-in-one-favicon | Stored Cross-Site Scripting | https://wordpress.org/plugins/all-in-one-favicon/ | Remove | Plugin | Requires user with high enough priveledges to adjust plugin settings (usually administrator). Researcher doesn't indicate when the vulnerability was introduced. Plugin has been removed from public repository. | https://hackpuntes.com/cve-2018-13832-wordpress-plugin-all-in-one-favicon-4-6-autenticado-multiples-cross-site-scripting-persistentes/ via https://wpvulndb.com/vulnerabilities/9104 | |||||||||||||||||||
7 | File Away | all, see notes | unfixed | file-away | Arbitrary File Inclusion/Disclosure | https://wordpress.org/plugins/file-away/ | Remove | Plugin | Researcher doesn't indicate when the vulnerability was introduced. Plugin hasn't been updated in 3 years so it's probably time to find a replacement anyway | https://cxsecurity.com/issue/WLB-2018070089 | |||||||||||||||||||
8 | Advanced Advertising System | all, see notes | unfixed | advanced-advertising-system | Object Injection | https://wordpress.org/plugins/advanced-advertising-system/ | Remove | Plugin | Researcher doesn't indicate when the vulnerability was introduced. | https://www.pluginvulnerabilities.com/2018/07/09/our-proactive-monitoring-caught-a-php-object-injection-vulnerability-in-advanced-advertising-system/ | |||||||||||||||||||
9 | Giveaway Boost | all, see notes | unfixed | giveaway-boost | Object Injection | https://wordpress.org/plugins/giveaway-boost/ | Remove | Plugin | Researcher doesn't indicate when the vulnerability was introduced. | https://www.pluginvulnerabilities.com/2018/07/09/our-proactive-monitoring-caught-a-php-object-injection-vulnerability-in-giveaway-boost/ | |||||||||||||||||||
10 | |||||||||||||||||||||||||||||
11 | |||||||||||||||||||||||||||||
12 | |||||||||||||||||||||||||||||
13 | |||||||||||||||||||||||||||||
14 | |||||||||||||||||||||||||||||
15 | |||||||||||||||||||||||||||||
16 | |||||||||||||||||||||||||||||
17 | |||||||||||||||||||||||||||||
18 | |||||||||||||||||||||||||||||
19 | |||||||||||||||||||||||||||||
20 | |||||||||||||||||||||||||||||
21 | |||||||||||||||||||||||||||||
22 | |||||||||||||||||||||||||||||
23 | |||||||||||||||||||||||||||||
24 | |||||||||||||||||||||||||||||
25 | |||||||||||||||||||||||||||||
26 | |||||||||||||||||||||||||||||
27 | |||||||||||||||||||||||||||||
28 | |||||||||||||||||||||||||||||
29 | |||||||||||||||||||||||||||||
30 | |||||||||||||||||||||||||||||
31 | |||||||||||||||||||||||||||||
32 | |||||||||||||||||||||||||||||
33 | |||||||||||||||||||||||||||||
34 | |||||||||||||||||||||||||||||
35 | |||||||||||||||||||||||||||||
36 | |||||||||||||||||||||||||||||
37 | |||||||||||||||||||||||||||||
38 | |||||||||||||||||||||||||||||
39 | |||||||||||||||||||||||||||||
40 | |||||||||||||||||||||||||||||
41 | |||||||||||||||||||||||||||||
42 | |||||||||||||||||||||||||||||
43 | |||||||||||||||||||||||||||||
44 | |||||||||||||||||||||||||||||
45 | |||||||||||||||||||||||||||||
46 | |||||||||||||||||||||||||||||
47 | |||||||||||||||||||||||||||||
48 | |||||||||||||||||||||||||||||
49 | |||||||||||||||||||||||||||||
50 | |||||||||||||||||||||||||||||
51 | |||||||||||||||||||||||||||||
52 | |||||||||||||||||||||||||||||
53 | |||||||||||||||||||||||||||||
54 | |||||||||||||||||||||||||||||
55 | |||||||||||||||||||||||||||||
56 | |||||||||||||||||||||||||||||
57 | |||||||||||||||||||||||||||||
58 | |||||||||||||||||||||||||||||
59 | |||||||||||||||||||||||||||||
60 | |||||||||||||||||||||||||||||
61 | |||||||||||||||||||||||||||||
62 | |||||||||||||||||||||||||||||
63 | |||||||||||||||||||||||||||||
64 | |||||||||||||||||||||||||||||
65 | |||||||||||||||||||||||||||||
66 | |||||||||||||||||||||||||||||
67 | |||||||||||||||||||||||||||||
68 | |||||||||||||||||||||||||||||
69 | |||||||||||||||||||||||||||||
70 | |||||||||||||||||||||||||||||
71 | |||||||||||||||||||||||||||||
72 | |||||||||||||||||||||||||||||
73 | |||||||||||||||||||||||||||||
74 | |||||||||||||||||||||||||||||
75 | |||||||||||||||||||||||||||||
76 | |||||||||||||||||||||||||||||
77 | |||||||||||||||||||||||||||||
78 | |||||||||||||||||||||||||||||
79 | |||||||||||||||||||||||||||||
80 | |||||||||||||||||||||||||||||
81 | |||||||||||||||||||||||||||||
82 | |||||||||||||||||||||||||||||
83 | |||||||||||||||||||||||||||||
84 | |||||||||||||||||||||||||||||
85 | |||||||||||||||||||||||||||||
86 | |||||||||||||||||||||||||||||
87 | |||||||||||||||||||||||||||||
88 | |||||||||||||||||||||||||||||
89 | |||||||||||||||||||||||||||||
90 | |||||||||||||||||||||||||||||
91 | |||||||||||||||||||||||||||||
92 | |||||||||||||||||||||||||||||
93 | |||||||||||||||||||||||||||||
94 | |||||||||||||||||||||||||||||
95 | |||||||||||||||||||||||||||||
96 | |||||||||||||||||||||||||||||
97 | |||||||||||||||||||||||||||||
98 | |||||||||||||||||||||||||||||
99 | |||||||||||||||||||||||||||||
100 |