ABCDEFGHIJKLMNOPQRSTUVWXYZAAAB
1
NameVersion(s) AffectedFixed in VersionPlugin DirectoryVulnerabilityLink/Plugin StatusSuggested ActionPlugin/ThemeOther NotesSource
2
MapSVGLiteAll, see notesunfixedmapsvg-lite-interactive-vector-mapsAuthenticated Arbitrary File Uploadhttps://wordpress.org/plugins/mapsvg-lite-interactive-vector-maps/Remove ImmediatelyPlugin
Authenticated user with role as low as subscriber can upload arbitrary file. Researcher doesn't indicate which version the vulnerability was introduced
https://www.pluginvulnerabilities.com/2018/07/18/our-proactive-monitoring-caught-an-authenticated-arbitrary-file-upload-vulnerability-in-mapsvg-lite/
3
Geo Mashup1.10.3 and earlier1.10.4geo-mashupCross-Site Scriptinghttps://wordpress.org/plugins/geo-mashup/UpdatePlugin
https://wpvulndb.com/vulnerabilities/9105
4
FV Flowplayer Video Player6.1.2 through 6.6.46.6.5fv-wordpress-flowplayerCross-Site Scriptinghttps://wordpress.org/plugins/fv-wordpress-flowplayer/UpdatePlugin
https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000078.html
5
WP Job Manager1.31.0 and earlier, see notes1.31.1wp-job-managerCross-Site Scriptinghttps://wordpress.org/plugins/wp-job-manager/UpdatePlugin
exploit db mentions the plugin being at v4.1.0, but that appears to be a typo
https://www.exploit-db.com/exploits/45031/
6
all-in-one-faviconall, see notesunfixedall-in-one-faviconStored Cross-Site Scriptinghttps://wordpress.org/plugins/all-in-one-favicon/RemovePlugin
Requires user with high enough priveledges to adjust plugin settings (usually administrator). Researcher doesn't indicate when the vulnerability was introduced. Plugin has been removed from public repository.
https://hackpuntes.com/cve-2018-13832-wordpress-plugin-all-in-one-favicon-4-6-autenticado-multiples-cross-site-scripting-persistentes/ via https://wpvulndb.com/vulnerabilities/9104
7
File Awayall, see notesunfixedfile-awayArbitrary File Inclusion/Disclosurehttps://wordpress.org/plugins/file-away/RemovePlugin
Researcher doesn't indicate when the vulnerability was introduced. Plugin hasn't been updated in 3 years so it's probably time to find a replacement anyway
https://cxsecurity.com/issue/WLB-2018070089
8
Advanced Advertising Systemall, see notesunfixedadvanced-advertising-systemObject Injectionhttps://wordpress.org/plugins/advanced-advertising-system/RemovePlugin
Researcher doesn't indicate when the vulnerability was introduced.
https://www.pluginvulnerabilities.com/2018/07/09/our-proactive-monitoring-caught-a-php-object-injection-vulnerability-in-advanced-advertising-system/
9
Giveaway Boostall, see notesunfixedgiveaway-boostObject Injectionhttps://wordpress.org/plugins/giveaway-boost/RemovePlugin
Researcher doesn't indicate when the vulnerability was introduced.
https://www.pluginvulnerabilities.com/2018/07/09/our-proactive-monitoring-caught-a-php-object-injection-vulnerability-in-giveaway-boost/
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100