vciy

10up ElasticPress: 27 records in one advisory

27 records announced together, published between 2023-07-01 and 2023-10-20, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-1/. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

10 of 27 records publish a fixed version. The other 17 do not, in held sources.

No record in this batch is listed by CISA in held sources.

Every record names something of its own, listed against it below.

Most commonly mapped weakness across the batch: CWE-352 Cross-Site Request Forgery (CSRF).

What this page does not cover

This batch is 27 of the 71 records that cite the same advisory. The other 44 are different findings announced alongside it.

None of those 44 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2020-36738Cool Timeline (Horizontal & Vertical Timeline) <= 2.0.2 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2020-36741MultiVendorX – MultiVendor Marketplace Solution For WooCommerce <= 3.5.7 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2020-36744NotificationX <= 1.8.2 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2020-36746Menu Swapper <= 1.1.0.2 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2020-36748Dokan <= 3.0.8 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2020-36749Easy Testimonials <= 3.6.1 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2020-36751Coupon Creator <= 3.1 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2020-36754Paid Memberships Pro <= 2.4.2 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2020-3675610WebAnalytics <= 1.2.8 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2020-36759Woody code snippets <= 2.3.9 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2020-36760Ocean Extra <=1.6.5 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4387Opal Estate <= 1.6.11 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4394Locations <= 3.2.1 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4396Rucy <= 0.4.4 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4398Amministrazione Trasparente <= 7.1 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4399Edwiser Bridge <= 2.0.6 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4402Multiple Roles <= 1.3.1- Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4403Remove Schema <= 1.5 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4405ElasticPress <= 3.5.3 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4410Qtranslate Slug <= 1.1.18 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4416wp-mpdf <= 3.5.1 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4420Sell Media <= 2.5.5 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4421Advanced Popups <= 1.1.1 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4423RAYS Grid <= 1.2.2 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4424Slider Hero <= 8.2.0 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4426Absolute Reviews <= 1.0.8 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)
CVE-2021-4427Vuukle Comments, Reactions, Share Bar, Revenue <= 3.4.31 - Cross-Site Request Forgery BypassCWE-352 Cross-Site Request Forgery (CSRF)

27 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.