Wpchill
46 known vulnerabilities
Top Products
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val
The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled Fanc
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure i
Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionali
Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testim
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosu
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcod
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capab
The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields befor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPChill Remove Foo
The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortc
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download M
The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure i
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects
Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: f
Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Mo
The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all
Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions.
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 vers
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions.
The MashShare WordPress plugin before 3.8.7 does not validate and escape some of its shortcode attributes before outputt
Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.
The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog fold
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CPO Shortcodes plugin <= 1.5.0 at WordPress.
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6
Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog fold
The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back i
The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting
Multiple Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilities in KB Support (WordPress plugin) <= 1.5.5 ver
The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege use
The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plug
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versio
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter bef
The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attr
The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameter
A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious
Frequently Asked Questions
How many CVEs affect Wpchill?
Wpchill has 46 CVE records in our database, including 1 critical and 7 high severity vulnerabilities.
What are the most severe Wpchill vulnerabilities?
Wpchill has 1 critical severity (CVSS 9.0+) and 7 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Wpchill vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Wpchill products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Wpchill Vulnerabilities
CyberStrike scans your infrastructure for Wpchill vulnerabilities and provides real-time remediation guidance.
Get Started