WordPress Plugin Vulnerabilities

0-9 - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
Name Added Title
ucan-post 2014-08-01 uCan Post <= 1.0.09 - Stored XSS
uji-countdown 2016-08-03 Uji Countdown <= 2.0.6 - Cross-Site Scripting (XSS)
uk-cookie 2014-08-01 uk-cookie - Cross-Site Scripting (XSS)
uk-cookie 2014-08-01 uk-cookie - Cross-Site Request Forgery (CSRF)
Ultimate_VC_Addons 2017-05-17 Ultimate Addons for Visual Composer <= 3.16.11 - Authenti...
ultimate-auction 2014-08-01 Ultimate Auction 1.0 - CSRF
ultimate-form-builder-lite 2017-04-20 Ultimate Form Builder Lite <= 1.3.2 - Authenticated Cross...
ultimate-member 2015-03-17 Ultimate Member <= 1.0.78 - Multiple Vulnerabilities
ultimate-member 2015-06-18 Ultimate Member 1.2.98-1.2.994 - Reflected Cross-Site Scr...
ultimate-member 2015-12-02 Ultimate Member <= 1.3.28 - Unauthenticated Reflected Cro...
ultimate-member 2016-07-10 Ultimate Member <= 1.3.64 - Local File Inclusion
ultimate-member 2016-12-08 Ultimate Member <= 1.3.75 - Unauthenticated Change Passwords
ultimate-product-catalog 2016-06-20 Product Catalog <= 3.8.1 - Privilege Escalation
ultimate-product-catalogue 2015-04-26 Ultimate Product Catalogue <= 3.1.1 - Unauthenticated Fil...
ultimate-product-catalogue 2015-04-27 Ultimate Product Catalogue <= 3.1.2 - Unauthenticated SQL...
ultimate-product-catalogue 2015-04-27 Ultimate Product Catalogue <= 3.1.2 - Unauthenticated SQL...
ultimate-product-catalogue 2015-05-05 Ultimate Product Catalogue <= 3.1.4 - Multiple Vulnerabil...
ultimate-product-catalogue 2016-07-29 Ultimate Product Catalogue <= 3.9.8 - Unauthenticated Bli...
ultimate-profile-builder 2015-05-06 Ultimate Profile Builder By CMSHelpLive <= 2.3.3 - CSRF/XSS
ultimate-social-media-icons 2015-11-13 Social Media & Share Icons <= 1.1.1.11 - Authenticated St...
ultimate-tinymce 2014-08-01 TinyMCE 3.5 - swfupload Cross-Site Scripting
unconfirmed 2014-08-01 Unconfirmed <= 1.2.4 - unconfirmed.php s Parameter Reflec...
underconstruction 2014-08-01 Under Construction 1.08 - Setting Manipulation CSRF
ungallery 2014-08-01 UnGallery <= 1.5.8 - Local File Disclosure
ungallery 2014-08-01 UnGallery - Arbitrary Comm& Execution
uninstall 2014-12-11 WordPress Uninstall <= 1.1 - WordPress Deletion via CSRF
unite-gallery-lite 2015-07-25 Unite Gallery Lite <= 1.4.6 - CSRF & Authenticated SQL In...
universal-analytics 2016-02-06 Universal Analytics <= 1.3.0 - Authenticated Cross-Site S...
unlimited-popups 2016-04-25 Unlimited Pop-Ups <= 1.4.3 - Cross-Site Scripting (XSS)
updater 2017-04-13 Multiple BestWebSoft Plugins - Authenticated Reflected GE...
updraft 2015-04-20 UpdraftPlus Backup & Restoration <= 1.9.6.3 - Cross-Site ...
updraftplus 2015-02-03 UpdraftPlus <= 1.9.50 - Privilege Escalation
uploader 2014-08-01 Uploader 1.0.4 - Shell Upload
uploader 2014-08-01 Uploader 1.0.4 - notify.php blog Parameter XSS
uploader 2014-08-01 Uploader 1.0.0 - wp-content/plugins/uploader/views/notify...
uploadify 2014-08-01 Uploadify 1.0 - Arbitrary File Upload
uploadify-integration 2014-08-01 Uploadify Integration 0.9.6 - Multiple Cross Site Scripti...
upm-polls 2014-08-01 UPM-POLLS 1.0.4 - BLIND SQL injection
url-cloak-encrypt 2014-08-01 Cloak & Encrypt < 2.0 - Cross-Site Scripting (XSS)
usc-e-shop 2014-08-01 Welcart e-Commerce 1.3.12 - DOM Cross-Site Scripting (XSS)
usc-e-shop 2014-08-01 Welcart e-Commerce 1.3.12 - purchase_limit Parameter DOM-...
usc-e-shop 2014-08-01 Welcart e-Commerce 1.3.12 - SQL Injection
usc-e-shop 2014-08-01 Welcart e-Commerce - SQL Injection
usc-e-shop 2014-08-01 Welcart e-Commerce - CSRF & XSS
usc-e-shop 2015-07-25 Welcart e-Commerce <= 1.4.17 - Multiple Vulnerabilities
usc-e-shop 2015-12-31 Welcart e-Commerce <= 1.5.2 - SQL Injection
usc-e-shop 2016-06-27 Welcart e-Commerce <= 1.8.2 - PHP Object Injection
usc-e-shop 2016-06-27 Welcart e-Commerce <= 1.8.2 - Cross-Site Scripting (XSS)
usc-e-shop 2016-06-27 Welcart e-Commerce <= 1.8.2 - Session Management
user-access-manager 2017-05-12 User Access Manager - Authenticated Reflected Cross-Site ...
user-avatar 2014-08-01 User Avatar 1.3.7 - shell upload