CVEs we hold for Wpchill
Records whose assigning authority named Wpchill as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-92622Strong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode…wpchill Strong Testimonials
CVE-2026-9107Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components'…wpchill Kali Forms — Contact Form & Drag-and-Drop Builder
CVE-2026-4559Image Photo Gallery Final Tiles Grid <= 3.6.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'delay'…wpchill Image Photo Gallery Final Tiles Grid
CVE-2026-4401Download Monitor <= 5.1.10 - Cross-Site Request Forgery to Download Path Deletion and Disablingwpchill Download Monitor
CVE-2026-3584Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_processwpchill Kali Forms — Contact Form & Drag-and-Drop Builder
CVE-2026-3239Strong Testimonials <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via testimonial_view Shortcodewpchill Strong Testimonials
CVE-2026-3124Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token'…wpchill Download Monitor
CVE-2026-1860Kali Forms <= 2.4.8 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposurewpchill Kali Forms — Contact Form & Drag-and-Drop Builder
CVE-2026-16144Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameterwpchill Kali Forms — Contact Form & Drag-and-Drop Builder
CVE-2026-15395Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Valuewpchill Kali Forms — Contact Form & Drag-and-Drop Builder
CVE-2026-1254Modula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 - Missing Authorization to Authenticated (Contributor+)…wpchill Modula Image Gallery – Photo Grid & Video Gallery
CVE-2025-7367Strong Testimonials <= 3.2.11 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Fieldswpchill Strong Testimonials
CVE-2025-15466Image Photo Gallery Final Tiles Grid <= 3.6.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Gallery…wpchill Image Photo Gallery Final Tiles Grid
CVE-2025-14865Passster – Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via…wpchill Passster – Password Protect Pages and Content
CVE-2025-14632Filr – Secure document library <= 1.2.11 - Authenticated (Administrator+) Stored Cross-Site Scripting via HTML Uploadwpchill Filr – Secure document library
CVE-2025-14455Image Photo Gallery Final Tiles Grid <= 3.6.7 - Missing Authorization to Authenticated (Contributor+) Gallery Managementwpchill Image Photo Gallery Final Tiles Grid
CVE-2025-14426Strong Testimonials <= 3.2.18 - Missing Authorization to Authenticated (Contributor+) Rating Meta Updatewpchill Strong Testimonials
CVE-2025-14003Image Gallery – Photo Grid & Video Gallery <= 2.13.3 - Missing Authorization to Authenticated (Author+) Arbitrary…wpchill Modula Image Gallery – Photo Grid & Video Gallery
CVE-2025-13891Image Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listingwpchill Modula Image Gallery – Photo Grid & Video Gallery
CVE-2025-13693Image Photo Gallery Final Tiles Grid <= 3.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'Custom…wpchill Image Photo Gallery Final Tiles Grid
CVE-2025-13646Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Conditionwpchill Image Gallery – Photo Grid & Video Gallery
CVE-2025-13645Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletionwpchill Image Gallery – Photo Grid & Video Gallery
CVE-2025-12494Image Gallery – Photo Grid & Video Gallery <= 2.12.28 - Improper Authorization to Authenticated (Author+) Arbitrary…wpchill Modula Image Gallery – Photo Grid & Video Gallery
CVE-2025-11268Strong Testimonials <= 3.2.16 - Unauthenticated Arbitrary Shortcode Executionwpchill Strong Testimonials
CVE-2025-10000Qyrr – simply and modern QR-Code creation <= 2.0.7 - Authenticated (Contributor+) Arbitrary File Uploadwpchill Qyrr – simply and modern QR-Code creation
CVE-2024-9416Modula Image Gallery <= 2.10.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5…wpchill Modula Image Gallery – Photo Grid & Video Gallery
CVE-2024-8552Download Monitor <= 5.0.9 - Missing Authorization to Authenticated (Subscriber+) Shop Enablewpchill Download Monitor
CVE-2024-6261Image Photo Gallery Final Tiles Grid <= 3.6.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scriptingwpchill Image Photo Gallery Final Tiles Grid
CVE-2024-32429WordPress Remove Footer Credit plugin <= 1.0.13 - Cross Site Scripting (XSS) vulnerabilityWPChill Remove Footer Credit
CVE-2024-30501WordPress Download Monitor theme <= 4.9.4 - Auth. SQL Injection vulnerabilityWPChill Download Monitor
CVE-2024-2026Passster <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via content_protector Shortcodewpchill Passster – Password Protect Pages and Content
CVE-2024-12853Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Uploadwpchill Modula Image Gallery – Photo Grid & Video Gallery
CVE-2024-12711RSVP and Event Management <= 2.7.13 - Missing Authorizationwpchill RSVP and Event Management
CVE-2024-1218Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorizationwpchill Kali Forms — Contact Form & Drag-and-Drop Builder
CVE-2024-1217Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin…wpchill Kali Forms — Contact Form & Drag-and-Drop Builder
CVE-2024-11282Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive…wpchill Passster – Password Protect Pages and Content
CVE-2024-11106Simple Restrict <= 1.2.7 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposurewpchill Simple Restrict
CVE-2024-1083Simple Restrict <= 1.2.6 - Missing Authorization to Sensitive Information Exposurewpchill Simple Restrict
CVE-2024-10399Download Monitor <= 5.0.13 - Missing Authorization to Sensitive Information Exposurewpchill Download Monitor
CVE-2024-10092Download Monitor <= 5.0.12 - Missing Authorization to API Key Manipulationwpchill Download Monitor
CVE-2024-0616Passster – Password Protect Pages and Content <= 4.2.6.2 - Missing Authorization to Sensitive Information Exposurewpchill Passster – Password Protect Pages and Content
CVE-2023-6491Strong Testimonials <= 3.1.12 - Authenticated(Contributor+) Improper Authorization to Views Modificationwpchill Strong Testimonials
CVE-2023-5704CPO Shortcodes <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodewpchill CPO Shortcodes
CVE-2023-52123WordPress Strong Testimonials Plugin <= 3.1.10 is vulnerable to Cross Site Request Forgery (CSRF)WPChill Strong Testimonials
CVE-2023-34007WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File UploadWPChill Download Monitor
CVE-2023-31219WordPress Download Monitor Plugin <= 4.8.1 is vulnerable to Server Side Request Forgery (SSRF)WPChill Download Monitor
CVE-2023-26013WordPress Strong Testimonials Plugin <= 3.0.2 is vulnerable to Cross Site Scripting (XSS)WPChill Strong Testimonials
CVE-2023-25451WordPress CPO Content Types Plugin <= 1.1.0 is vulnerable to Cross Site Scripting (XSS)WPChill CPO Content Types
CVE-2023-0162CPO Companion <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scriptingwpchill CPO Companion
CVE-2022-4972Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Exportwpchill Download Monitor
CVE-2022-45354WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data ExposureWPChill Download Monitor
CVE-2022-41135WordPress Modula plugin <= 2.6.9 - Unauth. Plugin Settings Change vulnerabilityWPChill Modula Image Gallery (WordPress plugin)
CVE-2022-40672WordPress CPO Shortcodes plugin <= 1.5.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityWPChill CPO Shortcodes (WordPress plugin)
CVE-2022-37407WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitiesWPChill Gallery PhotoBlocks (WordPress plugin)
CVE-2022-36292WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Cross-Site Request Forgery (CSRF) vulnerabilitiesWPChill Gallery PhotoBlocks (WordPress plugin)
CVE-2022-27852WordPress KB Support plugin <= 1.5.5 - Multiple Unauth. Stored Cross-Site Scripting (XSS) vulnerabilitiesWPChill Media Labs L.L.C KB Support
CVE-2021-36920WordPress plugin Download Monitor <= 4.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilityWPChill Download Monitor (WordPress plugin)
CVE-2021-23174WordPress Download Monitor plugin <= 4.4.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilityWPChill Download Monitor
CVE-2020-36721Epsilon Framework Themes (Various Versions) - Unauthenticated Plugin Activation/Deactivationwpchill Brilliance; silkalns Newspaper X; silkalns Activello
CVE-2020-36720Kali Forms <= 2.1.1 - Missing Authorization to Settings Updatewpchill Kali Forms — Contact Form & Drag-and-Drop Builder
CVE-2020-36717Kali Forms <= 2.1.1 - Cross-Site Request Forgerywpchill Kali Forms — Contact Form & Drag-and-Drop Builder
CVE-2020-36712Kali Forms <= 2.1.1 - Unauthenticated Arbitrary Post Deletionwpchill Kali Forms — Contact Form & Drag-and-Drop Builder
63 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.