Pluginus CVE Vulnerabilities & CVE List (86)

Products (CPE): — CVEs: 86

Pluginus vulnerability overview

Aggregates CVE and security vulnerability intelligence across all Pluginus-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk csrf, vendor risk path handling, and vendor risk sql injection and related problems; some flaws may lead to vendor impact file overwrite and vendor impact data exposure.

Vulnerability distribution trend (last 24 months)

Showing 8186 of 86 CVEs
«« First « Prev Page 5 / 5 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-4063 The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers. [email protected] 9.8 9.52% 2022-12-19 2026-06-17
CVE-2022-1916 The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site Scripting [email protected] 6.1 1.87% 2022-06-27 2026-06-17
CVE-2022-0234 The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting [email protected] 6.1 1.80% 2022-02-21 2026-06-17
CVE-2021-25085 The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting [email protected] 6.1 1.70% 2022-02-01 2026-06-16
CVE-2021-25043 The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue [email protected] 6.1 0.88% 2022-01-10 2026-06-16
CVE-2021-20781 Cross-site request forgery (CSRF) vulnerability in WordPress Meta Data Filter & Taxonomies Filter versions prior to v.1.2.8 and versions prior to v.2.2.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors. [email protected] 8.8 0.85% 2021-07-13 2026-06-16
«« First « Prev Page 5 / 5 Next »
cvelogic Threat Intelligence