Pricing
Case studies
Login
Start trial
Download Monitor
WP Chill
Developer
5.1.12
Latest version
90,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
23 patched
4 Mitigation rules
Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' vulnerability
<= 5.1.7
3 days ago
Local File Inclusion Vulnerability
<= 5.0.22
07/05/2025
Missing Authorization to Sensitive Information Exposure vulnerability
<= 5.0.13
29/10/2024
Missing Authorization to API Key Manipulation vulnerability
<= 5.0.12
25/10/2024
Missing Authorization to Authenticated (Subscriber+) Shop Enable vulnerability
<= 5.0.9
26/09/2024
Missing Authorization vulnerability
<= 4.9.13
29/05/2024
Auth. SQL Injection vulnerability
<= 4.9.4
28/03/2024
Authenticated SQL Injection vulnerability
< 4.9.5
08/01/2024
Arbitrary File Upload vulnerability
<= 4.8.3
13/06/2023
Server Side Request Forgery (SSRF) vulnerability
<= 4.8.1
30/05/2023
Sensitive Data Exposure vulnerability
<= 4.7.60
10/05/2023
Authenticated Arbitrary File Download vulnerability
<= 4.5.97
19/09/2022
Authenticated Arbitrary File Download vulnerability
<= 4.5.9
27/06/2022
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
<= 4.4.6
29/10/2021
Authenticated Arbitrary File Download vulnerability
<= 4.4.6
29/10/2021
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
<= 4.4.6
29/10/2021
SQL Injection (SQLi) vulnerability
<= 4.4.4
20/10/2021
Authenticated Directory Listing
<= 1.6.3
11/08/2016
Cross Site Scripting
<= 1.7.0
15/05/2015
XSS #1
<= 3.3.6.1
09/08/2013
XSS #2
<= 3.3.6.1
22/04/2013
Cross Site Scripting
<= 3.3.5.7
30/08/2012
SQL Injection
<= 2.0.6
30/04/2008