Vulnerabilities protected by our SQL Injection firewall rule

1,433,120
Attacks Blocked in Past 24 Hours

Showing 881-900 of 1,444 Vulnerabilities

Title CVE ID CVSS Vector Date
Yasr – Yet Another Stars Rating < 0.9.1 - Authenticated SQL Injection CVE-2015-9465 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H July 6, 2015
Simple Retail Menus <= 4.0.1 - SQL Injection CVE-2014-5183 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H May 28, 2015
GigPress <= 2.3.8 - SQL Injection CVE-2015-4066 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H May 26, 2015
NewStatPress <= 0.9.8 - Authenticated SQL Injection CVE-2015-4062 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H May 25, 2015
WordPress Landing Pages <= 1.8.4 - Authenticated SQL Injection CVE-2015-4064 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H May 25, 2015
Freshmail for WordPress <= 1.5.8 - SQL Injection CVE-2015-9496 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H May 6, 2015
Duplicator <= 0.5.14 - SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H April 10, 2015
Yoast SEO <= 1.7.3.3 - Blind SQL Injection CVE-2015-2292 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H March 11, 2015
Gallery Bank – WordPress Photo Gallery <= 3.0.101 - SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H February 21, 2015
WonderPlugin Audio Player <= 2.0 - Blind SQL Injection CVE-2015-2199 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H February 19, 2015
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin < 1.4.36 - SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H February 9, 2015
User Meta Manager < 3.4.7 - Authenticated Blind SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H February 4, 2015
Most Popular Posts Widget <= 0.8 - Authenticated (Admin+) SQL Injection CVE-2015-10124 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H February 2, 2015
Photo Gallery by 10Web <= 1.2.10 - Authenticated SQL Injection via asc_or_desc Parameter CVE-2015-1393 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H January 23, 2015
Cart66 Lite :: WordPress Ecommerce <= 1.5.3 - SQL Injection CVE-2014-9442 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H December 22, 2014
Cart66 Lite :: WordPress Ecommerce < 1.5.2 - SQL Injection CVE-2014-9305 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H December 3, 2014
Polls CP <= 1.0.1 - Authenticated SQL Injection CVE-2014-125091 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H November 23, 2014
BulletProof Security < .51.1 - SQL Injection CVE-2014-7959 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H October 7, 2014
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 3.1.0 - SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H September 29, 2014
I Recommend This <= 3.7.2 - Authenticated (Subscriber+) SQL Injection via Shortcode CVE-2014-125099 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H September 24, 2014

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation