Filter
-Infinity
0

Paid Memberships ProWordPress Paid Member Subscriptions <= 2.14.3 - Cross Site Scripting (XSS) Vulnerability

EPSS
0.03%
First published (updated )

TranslatePressWordPress TranslatePress <= 2.9.6 - PHP Object Injection Vulnerability

7.2
EPSS
0.04%
First published (updated )

Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions WordPressPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_id

First published (updated )

Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions WordPressPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.4 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

First published (updated )

Paid Memberships ProPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.0 - Unauthenticated Arbitrary Shortcode Execution

7.3
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions WordPressPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.12.8 - Reflected Cross-Site Scripting

EPSS
0.05%
First published (updated )

Cozmoslabs User Profile PictureUser Profile Picture <= 2.6.1 - Authenticated (Author+) Insecure Direct Object Reference to Profile Picture Update

EPSS
0.05%
First published (updated )

Cozmoslabs TranslatePressWordPress Translate Multilingual sites – TranslatePress plugin <= 2.7.5 - Cross Site Request Forgery (CSRF) vulnerability

EPSS
0.04%
First published (updated )

Paid Memberships ProWordPress Paid Membership Subscriptions plugin <= 2.11.0 - Cross Site Request Forgery (CSRF) vulnerability

EPSS
0.04%
First published (updated )

Paid Memberships ProWordPress Paid Membership Subscriptions plugin <= 2.10.4 - Cross Site Request Forgery (CSRF) vulnerability

8.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions WordPressThe Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction…

First published (updated )

Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions WordPressThe Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction…

First published (updated )

Cozmoslabs Profile BuilderThe User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugi…

8.2
EPSS
0.07%
First published (updated )

Cozmoslabs Profile BuilderWordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Cross Site Request Forgery (CSRF)

8.8
EPSS
0.06%
First published (updated )

Cozmoslabs Profile BuilderWordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Sensitive Data Exposure

7.5
EPSS
0.09%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Cozmoslabs Profile BuilderWordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Cross Site Scripting (XSS)

7.1
EPSS
0.05%
First published (updated )

Cozmoslabs Profile BuilderThe User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugi…

EPSS
0.04%
First published (updated )

CVE-2023-47669WordPress Profile Builder Plugin <= 3.10.3 is vulnerable to Cross Site Request Forgery (CSRF)

8.8
First published (updated )

Cozmoslabs Profile BuilderProfile Builder < 3.9.8 - Unauthenticated Plugin's Pages Creation

First published (updated )

Cozmoslabs Profile BuilderSQL Injection

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Cozmoslabs Client PortalWordPress Client Portal – Private user pages and login Plugin <= 1.1.8 is vulnerable to Cross Site Request Forgery (CSRF)

8.8
First published (updated )

Cozmoslabs Profile BuilderInfoleak

First published (updated )

Cozmoslabs Custom Post Types And Custom Fields CreatorWCK < 2.3.3 - Admin+ Stored XSS

First published (updated )

Cozmoslabs Profile BuilderWordPress Profile Builder plugin <= 3.6.0 - Cross-Site Request Forgery (CSRF) vulnerability

First published (updated )

TranslatePressTranslatepress Multilinugal < 2.3.3 - Admin+ SQLi

8.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Cozmoslabs Profile BuilderProfile Builder < 3.6.8 - Admin+ Stored Cross-Site Scripting

First published (updated )

Cozmoslabs Profile BuilderProfile Builder – User Profile & User Registration Forms <= 3.6.1 Reflected Cross-Site Scripting

First published (updated )

TranslatePressTranslatePress < 2.0.9 - Authenticated Stored Cross-Site Scripting

First published (updated )

Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions WordPressPaid Member Subscriptions < 2.4.2 - Authenticated SQL Injection

8.8
First published (updated )

Cozmoslabs Profile BuilderProfile Builder < 3.4.9 - Admin Access via Password Reset

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203