2D Tag Cloud |
Cross-Site Scripting (XSS) from add_query_arg Parameter |
Ads.txt & App-ads.txt Manager for WordPress |
Cross-Site Scripting (XSS) |
Advanced Category and Custom Taxonomy Image |
Cross-Site Scripting (XSS) from ad_tax_image Shortcode |
AI Image Generator for Your Content & Featured Images – AI Postpix |
Arbitrary File Upload (BAC) |
AMP for WP |
Cross-Site Request Forgery to Privilege Escalation (BAC) |
Auto Amazon Links |
Cross-Site Scripting (XSS) |
Auto Featured Image from Title |
Cross-Site Scripting (XSS) |
Back Link Tracker |
Cross-Site Request Forgery (CSRF) to SQL Injection (SQLi) |
Better Author Bio |
Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
Broken Link Checker |
Cross-Site Scripting (XSS) |
Bulk images optimizer |
Missing Authorization (BAC) to Plugin Options Update (BAC) |
Category and Taxonomy Image |
Cross-Site Scripting (XSS) |
Category and Taxonomy Meta Fields |
Cross-Site Scripting (XSS) |
Category and Taxonomy Meta Fields |
Cross-Site Scripting (XSS) |
Category and Taxonomy Meta Fields |
Cross-Site Request Forgery to Taxonomy Meta Add and Delete |
Duplicate Title Validate |
SQL Injection (SQLi) |
Easy Post Types |
Cross-Site Scripting (XSS) from Post Meta |
Easy Post Types |
Missing Authorization (BAC) from Multiple Functions |
Easy Post Types |
PHP Object Injection (BAC) |
Echo RSS Feed Post Generator Plugin for WordPress |
Unauthenticated Privilege Escalation (BAC) |
Endless Posts Navigation |
Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
External featured image from bing |
Remote Code Execution (RCE) |
G Meta Keywords |
Cross-Site Scripting (XSS) |
Google Language Translator |
Cross-Site Scripting (XSS) |
Google Map Locations |
Cross-Site Scripting (XSS) |
Hyperlink Group Block |
Cross-Site Scripting (XSS) |
Infinite-Scroll |
Cross-Site Request Forgery to Plugin Settings Update (BAC) |
Language Switcher |
Cross-Site Scripting (XSS) |
Linkz.ai |
Missing Authorization (BAC) to Plugin Settings Update (BAC) |
Linkz.ai |
Missing Authorization (BAC) to Unauthenticated Plugin Settings Update (BAC) |
Local Business Addons For Elementor |
Cross-Site Scripting (XSS) |
Marketing and SEO Booster |
Cross-Site Scripting (XSS) |
Most And Least Read Posts Widget |
Cross-Site Request Forgery (CSRF) |
Parallax Image |
Cross-Site Scripting (XSS) from dd-parallax Shortcode |
Premium SEO Pack |
SQL Injection (SQLi) |
Rank Math SEO |
PHP Object Injection (BAC) |
Rank Math SEO |
Missing Authorization (BAC) to Unauthenticated User and Term Metadata Insert, Update (BAC), and Delete |
Read more By Adam |
Missing Authorization (BAC) to Read More Button Deletion (BAC) |
RSS Feed Widget |
Cross-Site Scripting (XSS) from rfw-youtube-videos Shortcode |
Schema & Structured Data for WP & AMP |
Private Data Exposure |
SEO Manager |
Cross-Site Scripting (XSS) from Post Meta |
SEOPress |
Broken Access Control (BAC) |
SEOPress |
Broken Access Control (BAC) |
SEOPress |
Cross-Site Scripting (XSS) |
SEOPress |
Unauthenticated Broken Access Control (BAC) |
ShortPixel Image Optimizer |
Broken Access Control (BAC) |
ShortPixel Image Optimizer |
SQL Injection (SQLi) |
Simple Custom Post Order |
Broken Access Control (BAC) |
Smart Custom 404 Error Page |
Cross-Site Scripting (XSS) |
Social Auto Poster |
Cross-Site Request Forgery (CSRF) |
Table of Contents Plus |
Cross-Site Request Forgery (CSRF) |
W3SPEEDSTER |
Remote Code Execution (RCE) |
Woocommerce Custom Profile Picture |
Arbitrary File Upload (BAC) |
WordPress Image SEO |
Cross-Site Request Forgery (CSRF) |
WordPress Meta Data and Taxonomies Filter (MDTF) |
Bypass (BAC) |
WordPress Meta Data and Taxonomies Filter (MDTF) |
Cross-Site Scripting (XSS) |
WP-Advanced-Search |
Unauthenticated SQL Injection (SQLi) |
WP Post Author |
SQL Injection (SQLi) |
WP RSS Aggregator |
Missing Authorization (BAC) |
WP Search Analytics |
Cross-Site Scripting (XSS) |
WP show more |
Cross-Site Scripting (XSS) |
YML for Yandex Market |
Cross-Site Scripting (XSS) |