Pricing
Case studies
Login
Start trial
WP Statistics
VeronaLabs
Developer
14.16.4
Latest version
600,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
28 patched
12 Mitigation rules
Unauthenticated Stored Cross-Site Scripting via User-Agent Header vulnerability
<= 14.15.4
27/09/2025
Broken Access Control Vulnerability
<= 14.15
14/08/2025
Missing Authorization to Authenticated (Subscriber+) Arbitrary plugin Settings Update vulnerability
<= 14.13.3
29/04/2025
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 14.5
12/03/2024
Admin+ SQL Injection vulnerability
< 14.0
28/03/2023
Multiple Authenticated SQL Injection vulnerabilities
<= 13.2.10
31/01/2023
Authenticated SQLi vulnerability
< 13.2.9
27/12/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 13.2.1
24/05/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 13.2.1
10/05/2022
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 13.1.5
17/02/2022
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 13.1.5
17/02/2022
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 13.1.5
17/02/2022
Unauthenticated Blind SQL Injection (SQLi) vulnerability
<= 13.1.5
16/02/2022
Unauthenticated Blind SQL Injection (SQLi) vulnerability
<= 13.1.5
16/02/2022
Unauthenticated Blind SQL Injection (SQLi) via IP vulnerability
<= 13.1.5
16/02/2022
Unauthenticated SQL Injection vulnerability
<= 13.1.4
10/02/2022
Unauthenticated Time-Based Blind SQL Injection (SQLi) vulnerability
<= 13.0.7
18/05/2021
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 12.6.6.1
04/07/2019
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 12.6.5
12/06/2019
Cross-Site Scripting (XSS) vulnerability
<= 12.6.3
24/04/2019
Authenticated SQL Injection vulnerability
<= 12.0.7
01/07/2017
Reflected Cross-Site Scripting (XSS) vulnerability
<= 12.0.5
28/04/2017
SQL Injection
<= 9.4
22/11/2015
Cross Site Scripting
<= 9.5.1
10/08/2015
Cross Site Scripting
<= 2.2.4
25/06/2015
Stored & Reflected XSS
<= 8.3
15/05/2015
Stored XSS
<= 8.4
15/05/2015
Stored Cross Site Scripting
<= 9.1.2
15/05/2015