Vulnerabilities protected by our SQL Injection firewall rule

1,483,524
Attacks Blocked in Past 24 Hours

Showing 941-960 of 1,444 Vulnerabilities

Title CVE ID CVSS Vector Date
User Activity Log <= 1.6.2 - Unauthenticated SQL Injection via username 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H July 14, 2023
Contest Gallery <= 19.1.4.1 - Unauthenticated SQL Injection via cg_Fields CVE-2022-4158 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H December 5, 2022
Contest Gallery <= 19.1.5 - Unauthenticated SQL Injection via user_id CVE-2022-4156 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H December 5, 2022
Meow Gallery (+ Gallery Block) <= 4.1.8 - SQL Injection CVE-2021-24465 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N September 2, 2021
RegistrationMagic - Custom Registration Forms, User Registration and User Login Plugin <= 4.6.0.2 - SQL Injection CVE-2020-8435 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H February 13, 2020
Custom Permalinks <= 1.1 - Authenticated SQL Injection 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N February 26, 2018
Kama Click Counter <= 3.4.9 - Blind SQL Injection CVE-2017-18614 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H February 27, 2017
Booking Calendar Contact Form <= 1.0.23 - Shortcode SQL Injection 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H February 8, 2016
Eventify - Simple Events <= 1.7.f - SQL Injection via eventid 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H September 7, 2011
WordPress Core < 6.0.2 - Authenticated SQL Injection 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H August 30, 2022
WordPress Core < 5.8.3 - SQL Injection via WP_Query CVE-2022-21661 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H January 6, 2021
Contact Form Widget – Contact Query, Contact Page, Form Maker, Query Table <= 1.3.8 - Authenticated (Admin+) SQL Injection CVE-2019-17072 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H October 10, 2019
Podlove Podcast Publisher <= 2.5.3 - Authenticated SQL Injection CVE-2017-12949 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H August 7, 2017
Paid Memberships Pro <= 2.9.11 - Authenticated (Subscriber+) SQL Injection via Shortcodes CVE-2023-0631 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N February 28, 2023
Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filter CVE-2024-10400 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N November 20, 2024
Blogger 301 Redirect <= 2.5.3 - Unauthenticated SQL Injection via br CVE-2024-10645 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N November 15, 2024
WordPress Video Robot - The Ultimate Video Importer <= 1.20.0 - Unauthenticated SQL Injection CVE-2024-52431 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N November 15, 2024
Woocommerce Quote Calculator <= 1.1 - Unauthenticated SQL Injection CVE-2024-50479 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N October 25, 2024
RSVP ME <= 1.9.9 - Unauthenticated SQL Injection CVE-2024-50491 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N October 25, 2024
WP Sessions Time Monitoring Full Automatic <= 1.0.9 - Unauthenticated SQL Injection CVE-2024-49681 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N October 21, 2024

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation