🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
/ Information Disclosure
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.3.2229
Information Disclosure
This page lists
612 vulnerabilities
in this category.
Critical: 3
High: 393
Medium: 134
Low: 72
Information: 10
Vulnerability Name
CVE
CWE
Severity
WordPress Plugin ACF to REST API Information Disclosure (3.2.0)
CVE-2020-13700
CWE-200
High
WordPress Plugin Gravity Forms Information Disclosure (2.4.8)
CVE-2020-13764
CWE-200
High
WordPress Plugin File Manager Information Disclosure (6.4)
CVE-2020-24312
CWE-200
High
WordPress Plugin Product Input Fields for WooCommerce Arbitrary File Download (1.2.6)
-
CWE-538
High
WordPress Plugin Total Upkeep-WordPress Backup plus Restore & Migrate by BoldGrid Information Disclosure (1.14.9)
-
CWE-200
High
WordPress Plugin Doneren met Mollie Information Disclosure (2.8.4)
-
CWE-200
High
WordPress Plugin Paid Memberships Pro-Restrict Member Access to Content, Courses, Communities-Free or Paid Subscriptions Information Disclosure (2.5.2)
-
CWE-200
High
WordPress Plugin Font Awesome Information Disclosure (4.0.0-rc16)
-
CWE-200
High
WordPress Plugin Theme Editor Arbitrary File Download (2.5)
CVE-2021-24154
CWE-538
High
WordPress Plugin User Profile Picture Information Disclosure (2.4.0)
CVE-2021-24170
CWE-200
High
WordPress Plugin AccessAlly Information Disclosure (3.5.6)
CVE-2021-24226
CWE-200
High
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Information Disclosure (9.7.1)
CVE-2021-24374
CWE-200
High
WordPress Plugin Welcart e-Commerce Information Disclosure (2.2.7)
-
CWE-200
High
WordPress Plugin BulletProof Security Information Disclosure (5.1)
CVE-2021-39327
CWE-200
High
WordPress Plugin Advanced Woo Search Information Disclosure (1.99)
CVE-2020-12070
CWE-200
High
WordPress Plugin BuddyPress Information Disclosure (5.1.1)
CVE-2020-5244
CWE-200
High
WordPress Plugin Timetable and Event Schedule by MotoPress Information Disclosure (2.3.19)
CVE-2021-24585
CWE-200
High
WordPress Plugin Fast Velocity Minify Information Disclosure (2.7.6)
CVE-2019-19983
CWE-200
High
WordPress Plugin W3 Total Cache Arbitrary File Disclosure (0.9.3)
CVE-2019-6715
CWE-538
High
WordPress Plugin WP-Live Chat by 3CX Information Disclosure (8.0.28)
-
CWE-200
High
WordPress Plugin Advanced Contact form 7 DB Information Disclosure (1.6.2)
-
CWE-200
High
WordPress Plugin All-in-One WP Migration Information Disclosure (7.0)
-
CWE-200
High
WordPress Plugin MapSVG Lite Arbitrary File Disclosure (4.2.3.1)
-
CWE-538
High
WordPress Plugin Groundhogg-Marketing Automation & CRM for WordPress Arbitrary File Disclosure (2.0.9.4)
-
CWE-538
High
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more Information Disclosure (1.8.11)
CVE-2019-17574
CWE-200
High
WordPress Plugin Duplicator-WordPress Migration Arbitrary File Download (1.3.26)
CVE-2020-11738
CWE-538
High
WordPress Plugin Product Subtitle For WooCommerce Arbitrary File Disclosure (4.1)
-
CWE-538
High
WordPress Plugin Quick Buy For Woocommerce Arbitrary File Disclosure (2.0)
-
CWE-538
High
WordPress Plugin SKU Shortlink For WooCommerce Arbitrary File Disclosure (1.3.4)
-
CWE-538
High
WordPress Plugin TRADIES Information Disclosure (2.2.6)
-
CWE-200
High
WordPress Plugin Slack-Chat Information Disclosure (1.5.5)
CVE-2019-14367
CWE-200
High
WordPress Plugin WP Intercom-Slack for WordPress Information Disclosure (1.2.1)
CVE-2019-14365
CWE-200
High
WordPress Plugin WP SlackSync Information Disclosure (1.8.5)
CVE-2019-14366
CWE-200
High
WordPress Plugin Credova_Financial Information Disclosure (1.4.8)
CVE-2021-39342
CWE-200
High
WordPress Plugin Find My Blocks Information Disclosure (3.3.2)
CVE-2021-24677
CWE-200
High
WordPress Plugin A2 Optimized WP Information Disclosure (2.0.10.8)
-
CWE-200
High
WordPress Plugin Backup Migration Information Disclosure (1.2.8)
-
CWE-200
High
WordPress Plugin Advanced Custom Fields (ACF) Information Disclosure (6.0.2)
CVE-2022-40696
CWE-200
High
WordPress Plugin Advanced Custom Fields PRO Information Disclosure (6.0.2)
CVE-2022-40696
CWE-200
High
WordPress Plugin YaySMTP-Simple WP SMTP Mail Information Disclosure (2.2)
CVE-2022-2369
CWE-862
High
WordPress Plugin AI ChatBot Information Disclosure (4.8.9)
CVE-2023-5254
CWE-200
High
WordPress Plugin Backup Migration Arbitrary File Download (1.3.6)
CVE-2023-6266
CWE-200
High
WordPress Plugin Backup Migration Information Disclosure (1.3.5)
CVE-2023-6271
CWE-200
High
WordPress Plugin Clone Information Disclosure (2.4.2)
CVE-2023-6750
CWE-200
High
WordPress Plugin Video Conferencing with Zoom Information Disclosure (3.8.16)
CVE-2022-0384
CWE-200
High
WordPress Plugin Debug Log Manager Information Disclosure (2.2.2)
CVE-2023-6383
CWE-200
High
WordPress Plugin LearnDash LMS Multiple Information Disclosure Vulnerabilities (4.10.2)
CVE-2024-1210
CWE-200
High
WordPress Plugin MasterStudy LMS-for Online Courses and Education Information Disclosure (3.2.10)
CVE-2024-2106
CWE-200
High
WordPress Plugin Academy LMS-eLearning and online course solution for WordPress Information Disclosure (1.9.25)
CVE-2024-35171
CWE-200
High
WordPress Plugin SiteGuard WP Information Disclosure (1.7.6)
CVE-2024-37881
CWE-201
High
WordPress Plugin WP STAGING WordPress Backup-Migration Backup Restore Information Disclosure (3.4.3)
CVE-2024-3682
CWE-200
High
WordPress Plugin WP-RecentComments Information Disclosure (2.2.7)
CVE-2023-23886
CWE-200
High
WordPress Plugin Simple File Downloader Cross-Site Scripting (1.0.4)
CVE-2022-4764
CWE-79
High
WordPress Plugin WP Import Export Lite Information Disclosure (3.9.15)
CVE-2022-0236
CWE-200
High
WordPress Plugin Simple File List Arbitrary File Download (3.2.7)
CVE-2022-1119
CWE-538
High
WordPress Plugin WP Import Export Information Disclosure (3.9.15)
CVE-2022-0236
CWE-200
High
WordPress Plugin Customize WordPress Emails and Alerts-Better Notifications for WP Information Disclosure (1.8.6)
CVE-2022-0345
CWE-200
High
WordPress Plugin BackupBuddy Arbitrary File Download (8.7.4.1)
CVE-2022-31474
CWE-22
High
WordPress Plugin Be POPIA Compliant Information Disclosure (1.1.5)
CVE-2022-1186
CWE-200
High
WordPress Plugin GiveWP-Donation and Fundraising Platform Information Disclosure (2.20.2)
CVE-2022-2117
CWE-200
High
WordPress Plugin Metform Elementor Contact Form Builder-Flexible and Design-Friendly Contact Form builder for WordPress Information Disclosure (2.1.3)
CVE-2022-1442
CWE-200
High
WordPress Plugin Helpful Information Disclosure (4.5.25)
CVE-2022-2834
CWE-200
High
WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor Information Disclosure (3.9.0)
CVE-2023-0814
CWE-200
High
WordPress Plugin Salon Booking System Multiple Information Disclosure Vulnerabilities (7.6.2)
CVE-2022-0920
CWE-200
High
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Information Disclosure (5.1.2)
CVE-2022-4346
CWE-200
High
WordPress Plugin Wholesale Market Arbitrary File Download (2.2.0)
CVE-2022-4298
CWE-552
High
WordPress Plugin Wholesale Market for WooCommerce Arbitrary File Download (1.0.7)
CVE-2022-4108
CWE-552
High
WordPress Plugin Wholesale Market for WooCommerce Arbitrary File Download (1.0.6)
CVE-2022-4106
CWE-552
High
WordPress Plugin Correos Woocommerce Arbitrary File Download (1.3.0.0)
CVE-2023-0331
CWE-552
High
WordPress Plugin Media Library Assistant Information Disclosure (3.00)
CVE-2022-41618
CWE-200
High
WordPress Plugin ApplyOnline-Application Form Builder and Manager Arbitrary File Disclosure (1.9.92)
-
CWE-538
High
WordPress Plugin Stop User Enumeration Security Bypass (1.3.18)
-
CWE-264
High
WordPress Plugin IBS Mappro Arbitrary File Download (0.6)
CVE-2015-5472
CWE-22
High
WordPress Plugin Caldera Forms-More Than Contact Forms Information Disclosure (1.3.5.2)
-
CWE-200
High
WordPress Plugin Child Theme Configurator Arbitrary File Disclosure (1.7.4)
-
CWE-538
High
«
1
2
3
4
...
9
»