Vulnerabilities protected by our SQL Injection firewall rule

1,621,168
Attacks Blocked in Past 24 Hours

Showing 1121-1140 of 1,444 Vulnerabilities

Title CVE ID CVSS Vector Date
FireStorm Shopping Cart eCommerce Plugin <= 2.07.02 - SQL Injection CVE-2016-10951 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H November 10, 2016
Zotpress < 6.1.3 - SQL Injection CVE-2016-1000217 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H October 6, 2016
MailPoet Newsletters <= 2.7.2 - SQL Injection 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L September 11, 2016
WordPress Zero Spam <= 2.1.1 - SQL Injection 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 24, 2016
Ninja Forms Contact Form <= 2.9.55.1 - Authenticated SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H August 16, 2016
WP Multiple Meta Box <= 1.0.0 - SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H August 4, 2016
Booking Calendar <= 6.2 - Authenticated (Editor+) SQL Injection 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H August 1, 2016
SpiderVPlayer < 1.5.18 - Multiple Blind Authenticated SQL Injections 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H July 19, 2016
Photo Gallery by Ays – Responsive Image Gallery < 1.0.1 - SQL Injection CVE-2016-10921 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 11, 2016
FormBuilder < 1.08 - SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H July 1, 2016
Search Everything <= 8.1.5 - SQL Injection CVE-2016-10917 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H June 10, 2016
Double Opt-In for Download <= 2.0.9 - SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H June 6, 2016
WP-EMail < 2.67.2 - SQL Injection 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H May 14, 2016
Huge-IT gallery-images <= 1.8.9 - SQL Injection CVE-2016-11018 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H May 10, 2016
Event Registration <= 6.02.02 - SQL Injection 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H May 9, 2016
All In One WP Security & Firewall <= 4.0.6 - SQL Injection CVE-2016-10888 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 6, 2016
SP Projects & Document Manager <= 2.5.9.5 - SQL Injection 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H March 7, 2016
Export WordPress Data with Advanced Filters < 1.2 - SQL Injection CVE-2016-11000 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H February 25, 2016
Booking Calendar Contact Form < 1.0.24 - Blind SQL Injection CVE-2016-10909 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H February 8, 2016
Booking Calendar Contact Form <= 1.0.23 - Shortcode SQL Injection 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H February 8, 2016

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation