plugin

Top 10 Vulnerabilities

32 known security issues reported for the Top 10 WordPress plugin. Most recent disclosed May 7, 2025.

1 high 9 medium

Running Top 10 on your site? Check whether your installed version is affected.

Scan your site free

Top 10 <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Top 10 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will...

CVSS:
6.4
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
May 7, 2025

CVE-2025-47509 on NVD →

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 4.1.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Top 10 allows Stored XSS. This issue affects Top 10: from n/a through 4.1.0.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
May 7, 2025

CVE-2025-47509 on NVD →

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 3.2.4

unknown

[en] Missing Authorization vulnerability in WebberZone Top 10 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Top 10: from n/a through 3.2.3.

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Dec 9, 2024

CVE-2023-25993 on NVD →

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 3.3.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WebberZone Top 10 – WordPress Popular posts by WebberZone plugin <= 3.3.2 versions.

Affected:
up to 3.3.3
Fixed in:
3.3.3
Disclosed:
Nov 9, 2023

CVE-2023-47238 on NVD →

Top 10 <= 3.3.2 - Cross-Site Request Forgery via edit_count_ajax

medium

The Top 10 – WordPress Popular posts by WebberZone plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on the 'edit_count_ajax' function. This makes it possible for unauthenticated attackers to edit post coun...

CVSS:
4.3
Affected:
up to 3.3.2
Fixed in:
3.3.3
Disclosed:
Nov 3, 2023

CVE-2023-47238 on NVD →

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 3.3.3

unknown

The Top 10 – WordPress Popular posts by WebberZone plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on the 'edit_count_ajax' function. This makes it possible for unauthenticated attackers to edit post coun...

Affected:
up to 3.3.3
Fixed in:
3.3.3
Disclosed:
Nov 3, 2023

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 2.9.5

unknown

[en] The Top 10 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.4. This is due to missing or incorrect nonce validation on the tptn_export_tables() function. This makes it possible for unauthenticated attackers to generate an export of the top 10 table via a forge...

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jul 12, 2023

CVE-2020-36761 on NVD →

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 2.9.5

unknown
Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 3.2.5

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay D'Souza Top 10 – Popular posts plugin for WordPress plugin <= 3.2.4 versions.

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Mar 23, 2023

CVE-2023-26008 on NVD →

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 3.2.5

unknown

Update the WordPress Top 10 plugin to the latest available version (at least 3.2.5). WordFence discovered and reported this Broken Access Control vulnerability in WordPress Top 10 Plugin. This vulnerability has been fixed in version 3.2.5.

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Feb 24, 2023

Top 10 – Popular posts plugin - <= 3.2.4 - Authenticated(Admin+) Stored Cross-Site Scripting

medium

The Top 10 – Popular posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to injec...

CVSS:
4.4
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Feb 22, 2023

CVE-2023-26008 on NVD →

Top 10 – Popular posts plugin for WordPress <= 3.2.4 - Missing Authorization on tptn_chart_data

medium

The Top 10 – Popular posts plugin for WordPress is vulnerable to insufficient access control in the 'tptn_chart_data' AJAX action in versions up to, and including, 3.2.4. This allows authenticated attackers to access chart data granted they can access the admin dashboard and retrieve the nonce used for access control.

CVSS:
4.3
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Feb 22, 2023

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 3.2.5

unknown

The Top 10 – Popular posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to injec...

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Feb 22, 2023

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 3.2.5

unknown

The Top 10 – Popular posts plugin for WordPress is vulnerable to insufficient access control in the 'tptn_chart_data' AJAX action in versions up to, and including, 3.2.4. This allows authenticated attackers to access chart data granted they can access the admin dashboard and retrieve the nonce used for access control.

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Feb 22, 2023

Top 10 – Popular posts plugin for WordPress <= 3.2.3 - Missing Authorization on tptn_ajax_clearcache

medium

The Top 10 – Popular posts plugin for WordPress is vulnerable to unauthorized cache deletion due to a missing capability check on the tptn_ajax_clearcache function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers with subscriber-level access to delete the plugin's cache.

CVSS:
4.3
Affected:
up to 3.2.3
Fixed in:
3.2.4
Disclosed:
Feb 20, 2023

CVE-2023-25993 on NVD →

Top 10 – Popular posts plugin for WordPress <= 3.2.3 - Cross-Site Request Forgery via tptn_ajax_clearcache

medium

The Top 10 – Popular posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.3. This is due to missing or incorrect nonce validation on the tptn_ajax_clearcache function. This makes it possible for unauthenticated attackers to clear the plugin's cache via a forged re...

CVSS:
4.3
Affected:
up to 3.2.3
Fixed in:
3.2.4
Disclosed:
Feb 20, 2023

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 3.2.4

unknown

The Top 10 – Popular posts plugin for WordPress is vulnerable to unauthorized cache deletion due to a missing capability check on the tptn_ajax_clearcache function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers with subscriber-level access to delete the plugin's cache.

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Feb 20, 2023

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 3.2.4

unknown

The Top 10 – Popular posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.3. This is due to missing or incorrect nonce validation on the tptn_ajax_clearcache function. This makes it possible for unauthenticated attackers to clear the plugin's cache via a forged re...

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Feb 20, 2023

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 3.2.3

unknown

[en] The Top 10 WordPress plugin before 3.2.3 does not validate and escape some of its Block attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Jan 23, 2023

CVE-2022-4570 on NVD →

Top 10 – Popular posts plugin for WordPress <= 3.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Blocks

medium

The Top 10 – Popular posts plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers wit...

CVSS:
6.4
Affected:
up to 3.2.2
Fixed in:
3.2.3
Disclosed:
Dec 29, 2022

CVE-2022-4570 on NVD →

Top 10 <= 2.9.4 - Cross-Site Request Forgery Bypass

medium

The Top 10 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.4. This is due to missing or incorrect nonce validation on the tptn_export_tables() function. This makes it possible for unauthenticated attackers to generate an export of the top 10 table via a forged req...

CVSS:
4.3
Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Sep 16, 2020

CVE-2020-36761 on NVD →

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 2.9.5

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Top 10 plugin (versions <= 2.9.4).

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Sep 16, 2020

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 2.4.4

unknown

Authenticated SQL Injection (SQLi) vulnerability found by Defense Code in WordPress Top 10 plugin (versions <=2.4.3)

Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Dec 20, 2017

Top 10 – Popular posts plugin for WordPress <= 2.4.3 - SQL Injection

high

The Top 10 – Popular posts plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘get_results’ parameter in versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

CVSS:
7.4
Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Dec 13, 2017

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 2.4.4

unknown

The Top 10 – Popular posts plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘get_results’ parameter in versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Dec 13, 2017

Top 10 – Popular posts plugin for WordPress < 2.3.1 - Cross-Site Scripting

medium

The Top 10 – Popular posts plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'page' parameter in versions before 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser...

CVSS:
6.1
Affected:
up to 2.3.1
Fixed in:
2.3.1
Disclosed:
Jul 15, 2016

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 2.3.1

unknown

The Top 10 – Popular posts plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'page' parameter in versions before 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser...

Affected:
up to 2.3.1
Fixed in:
2.3.1
Disclosed:
Jul 15, 2016

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 2.3.1

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.3.1
Fixed in:
2.3.1
Disclosed:
Jul 14, 2016

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 1.9.3

unknown

This plugin is prone to a cross site request forgery vulnerability. Update the plugin.

Affected:
up to 1.9.3
Fixed in:
1.9.3
Disclosed:
May 15, 2015

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 2.3.1

unknown

The Top 10 &ndash; Popular posts plugin for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.3.1
Fixed in:
2.3.1

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 2.4.4

unknown

The Top 10 &ndash; Popular posts plugin for WordPress WordPress plugin was affected by an Authenticated SQL Injection security vulnerability.

Affected:
up to 2.4.4
Fixed in:
2.4.4

Top 10 &#8211; WordPress Popular posts by WebberZone [top-10] < 2.9.5

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 2.9.5
Fixed in:
2.9.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database