plugin-planet records
22 published records for vendor plugin-planet.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 40.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-25138No exploit | User Submitted Posts <= 20190312 - Unauthenticated Arbitrary File Uploadplugin-planet · user submitted posts · CWE-434 | Critical9.8 | — | 2.3% | Jun 6, 2023 |
39Monitor | CVE-2023-45603No exploit | WordPress User Submitted Posts Plugin <= 20230902 is vulnerable to Arbitrary File Uploadplugin-planet · user submitted posts · CWE-434 | Critical9.8 | — | 0.9% | Dec 20, 2023 |
37Monitor | CVE-2022-1165No exploit | Blackhole for Bad Bots < 3.3.2 - Arbitrary IP Address Blocking via IP Spoofingplugin-planet · blackhole for bad bots · CWE-639 | Critical9.1 | — | 1.7% | Apr 4, 2022 |
31Monitor | CVE-2022-27849Proof of concept | WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerabilityplugin-planet · simple ajax chat · CWE-200 | High7.5 | — | 4.6% | Apr 15, 2022 |
28Monitor | CVE-2024-1983No exploit | Simple Ajax Chat < 20240223 - Unauthenticated Stored XSSplugin-planet · simple ajax chat · CWE-79 | High7.1 | — | 0.5% | Mar 20, 2024 |
25Monitor | CVE-2021-24409Proof of concept | Prismatic < 2.8 - Reflected Cross-Site Scripting (XSS)plugin-planet · prismatic · CWE-79 | Medium6.1 | — | 1.7% | Jul 12, 2021 |
24Monitor | CVE-2016-11001No exploit | The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.plugin-planet · user submitted posts · CWE-79 | Medium6.1 | — | 1.2% | Sep 20, 2019 |
24Monitor | CVE-2022-25601No exploit | WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerabilityplugin-planet · contact form x · CWE-79 | Medium6.1 | — | 1.0% | Mar 11, 2022 |
24Monitor | CVE-2022-25610No exploit | WordPress Simple Ajax Chat plugin <= 20220115 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilityplugin-planet · simple ajax chat · CWE-79 | Medium6.1 | — | 0.7% | Mar 25, 2022 |
24Monitor | CVE-2024-0979No exploit | Dashboard Widgets Suite <= 3.4.3 - Reflected Cross-Site Scriptingplugin-planet · dashboard widgets suite · CWE-79 | Medium6.1 | — | 0.4% | Jun 13, 2024 |
21Monitor | CVE-2021-24408No exploit | Prismatic < 2.8 - Contributor+ Stored XSSplugin-planet · prismatic · CWE-79 | Medium5.4 | — | 0.6% | Jul 12, 2021 |
21Monitor | CVE-2023-5614No exploit | Theme Switcha <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeplugin-planet · theme switcha · CWE-79 | Medium5.4 | — | 0.4% | Oct 20, 2023 |
21Monitor | CVE-2023-4308No exploit | User Submitted Posts <= 20230809 - Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content'plugin-planet · user submitted posts · CWE-79 | Medium5.4 | — | 0.4% | Aug 15, 2023 |
21Monitor | CVE-2023-4779No exploit | User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20230811 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeplugin-planet · user submitted posts · CWE-79 | Medium5.4 | — | 0.4% | Sep 6, 2023 |
21Monitor | CVE-2023-4838No exploit | The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to,plugin-planet · simple download counter · CWE-79 | Medium5.4 | — | 0.4% | Sep 8, 2023 |
21Monitor | CVE-2024-2470No exploit | Simple Ajax Chat < 20240412 - Admin+ Stored XSSplugin-planet · simple ajax chat · CWE-79 | Medium5.4 | — | 0.3% | Jun 4, 2024 |
21Monitor | CVE-2025-46240No exploit | WordPress Simple Download Counter plugin <= 2.2 - Cross Site Scripting (XSS) Vulnerabilityplugin-planet · simple download counter · CWE-79 | Medium5.4 | — | 0.2% | Apr 22, 2025 |
21Monitor | CVE-2025-46239No exploit | WordPress Theme Switcha plugin <= 3.4 - Cross Site Scripting (XSS) Vulnerabilityplugin-planet · theme switcha · CWE-79 | Medium5.4 | — | 0.2% | Apr 22, 2025 |
19Monitor | CVE-2024-5002No exploit | User Submitted Posts < 20240516 - Admin+ Stored XSSplugin-planet · user submitted posts · CWE-79 | Medium4.8 | — | 0.4% | Jul 13, 2024 |
19Monitor | CVE-2023-49743No exploit | WordPress Dashboard Widgets Suite Plugin <= 3.4.1 is vulnerable to Cross Site Scripting (XSS)plugin-planet · dashboard widget suite · CWE-79 | Medium4.8 | — | 0.4% | Dec 14, 2023 |
19Monitor | CVE-2023-26517No exploit | WordPress Dashboard Widgets Suite Plugin <= 3.2.1 is vulnerable to Cross Site Scripting (XSS)plugin-planet · dashboard widget suite · CWE-79 | Medium4.8 | — | 0.4% | May 6, 2023 |
17Monitor | CVE-2022-27850No exploit | WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilityplugin-planet · simple ajax chat · CWE-352 | Medium4.3 | — | 0.4% | Apr 15, 2022 |
- CVE-2019-2513840Plan
User Submitted Posts <= 20190312 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.8No exploitEPSS 2%plugin-planet · user submitted postsJun 6, 2023
- CVE-2023-4560339Monitor
WordPress User Submitted Posts Plugin <= 20230902 is vulnerable to Arbitrary File Upload
CriticalCVSS 9.8No exploitEPSS 1%plugin-planet · user submitted postsDec 20, 2023
- CVE-2022-116537Monitor
Blackhole for Bad Bots < 3.3.2 - Arbitrary IP Address Blocking via IP Spoofing
CriticalCVSS 9.1No exploitEPSS 2%plugin-planet · blackhole for bad botsApr 4, 2022
- CVE-2022-2784931Monitor
WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerability
HighCVSS 7.5Proof of conceptEPSS 5%plugin-planet · simple ajax chatApr 15, 2022
- CVE-2024-198328Monitor
Simple Ajax Chat < 20240223 - Unauthenticated Stored XSS
HighCVSS 7.1No exploitEPSS 0%plugin-planet · simple ajax chatMar 20, 2024
- CVE-2021-2440925Monitor
Prismatic < 2.8 - Reflected Cross-Site Scripting (XSS)
MediumCVSS 6.1Proof of conceptEPSS 2%plugin-planet · prismaticJul 12, 2021
- CVE-2016-1100124Monitor
The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.
MediumCVSS 6.1No exploitEPSS 1%plugin-planet · user submitted postsSep 20, 2019
- CVE-2022-2560124Monitor
WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 1%plugin-planet · contact form xMar 11, 2022
- CVE-2022-2561024Monitor
WordPress Simple Ajax Chat plugin <= 20220115 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 1%plugin-planet · simple ajax chatMar 25, 2022
- CVE-2024-097924Monitor
Dashboard Widgets Suite <= 3.4.3 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%plugin-planet · dashboard widgets suiteJun 13, 2024
- CVE-2021-2440821Monitor
Prismatic < 2.8 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%plugin-planet · prismaticJul 12, 2021
- CVE-2023-561421Monitor
Theme Switcha <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 0%plugin-planet · theme switchaOct 20, 2023
- CVE-2023-430821Monitor
User Submitted Posts <= 20230809 - Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content'
MediumCVSS 5.4No exploitEPSS 0%plugin-planet · user submitted postsAug 15, 2023
- CVE-2023-477921Monitor
User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20230811 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 0%plugin-planet · user submitted postsSep 6, 2023
- CVE-2023-483821Monitor
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to,
MediumCVSS 5.4No exploitEPSS 0%plugin-planet · simple download counterSep 8, 2023
- CVE-2024-247021Monitor
Simple Ajax Chat < 20240412 - Admin+ Stored XSS
MediumCVSS 5.4No exploitEPSS 0%plugin-planet · simple ajax chatJun 4, 2024
- CVE-2025-4624021Monitor
WordPress Simple Download Counter plugin <= 2.2 - Cross Site Scripting (XSS) Vulnerability
MediumCVSS 5.4No exploitEPSS 0%plugin-planet · simple download counterApr 22, 2025
- CVE-2025-4623921Monitor
WordPress Theme Switcha plugin <= 3.4 - Cross Site Scripting (XSS) Vulnerability
MediumCVSS 5.4No exploitEPSS 0%plugin-planet · theme switchaApr 22, 2025
- CVE-2024-500219Monitor
User Submitted Posts < 20240516 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%plugin-planet · user submitted postsJul 13, 2024
- CVE-2023-4974319Monitor
WordPress Dashboard Widgets Suite Plugin <= 3.4.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%plugin-planet · dashboard widget suiteDec 14, 2023
- CVE-2023-2651719Monitor
WordPress Dashboard Widgets Suite Plugin <= 3.2.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%plugin-planet · dashboard widget suiteMay 6, 2023
- CVE-2022-2785017Monitor
WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerability
MediumCVSS 4.3No exploitEPSS 0%plugin-planet · simple ajax chatApr 15, 2022