Justiice (Patchstack Alliance)
21 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2023-36526No exploit | WordPress Duplicate Post Page Menu & Custom Post Type plugin <= 2.4.1 - Broken Access Control vulnerabilityinqsys technology · duplicate post page menu & custom post type · CWE-862 | Medium5.4 | — | 0.6% | Dec 13, 2024 |
17Monitor | CVE-2022-47604No exploit | WordPress AJAX Thumbnail Rebuild plugin <= 1.13 - Broken Access Control vulnerabilityjunkcoder, ristoniinemets · ajax thumbnail rebuild · CWE-862 | Medium4.3 | — | 0.5% | Apr 10, 2024 |
35Monitor | CVE-2023-32504No exploit | WordPress Wise Chat Plugin <= 3.1.3 is vulnerable to Cross Site Request Forgery (CSRF)kaine · wise chat · CWE-352 | High8.8 | — | 0.3% | Nov 18, 2023 |
35Monitor | CVE-2023-28420No exploit | WordPress Custom Options Plus Plugin <= 1.8.1 is vulnerable to Cross Site Request Forgery (CSRF)leocaseiro · custom options plus · CWE-352 | High8.8 | — | 0.3% | Nov 12, 2023 |
35Monitor | CVE-2023-34033No exploit | WordPress Ajax Pagination and Infinite Scroll Plugin <= 2.0.1 is vulnerable to Cross Site Request Forgery (CSRF)malinky · malinky-ajax-pagination · CWE-352 | High8.8 | — | 0.3% | Nov 9, 2023 |
35Monitor | CVE-2022-47442No exploit | WordPress UsersWP Plugin <= 1.2.3.9 is vulnerable to CSV Injectionayecode · userswp · CWE-1236 | High8.8 | — | 0.7% | Nov 7, 2023 |
39Monitor | CVE-2022-46859No exploit | WordPress Spiffy Calendar Plugin <= 4.9.1 is vulnerable to SQL Injectionspiffyplugins · spiffy calendar · CWE-89 | Critical9.8 | — | 0.6% | Nov 3, 2023 |
19Monitor | CVE-2023-25063No exploit | WordPress Quick Page/Post Redirect Plugin <= 5.2.3 is vulnerable to Cross Site Scripting (XSS)anadnet · quick page\/post redirect plugin · CWE-79 | Medium4.8 | — | 0.4% | Aug 8, 2023 |
35Monitor | CVE-2023-22689No exploit | WordPress Auto Affiliate Links Plugin <= 6.3 is vulnerable to Broken Access Controlflamescorpion · auto affiliate links · CWE-352 | High8.8 | — | 0.3% | May 20, 2023 |
19Monitor | CVE-2022-47157No exploit | WordPress WP Custom Fields Search Plugin <= 1.2.34 is vulnerable to Cross Site Scripting (XSS)webhammer · wp custom fields search · CWE-79 | Medium4.8 | — | 0.4% | May 18, 2023 |
19Monitor | CVE-2022-47606No exploit | WordPress WP-CORS Plugin <= 0.2.1 is vulnerable to Cross Site Scripting (XSS)wp-cors project · wp-cors · CWE-79 | Medium4.8 | — | 0.4% | May 10, 2023 |
19Monitor | CVE-2022-47587No exploit | WordPress WP Search Analytics Plugin <= 1.4.5 is vulnerable to Cross Site Scripting (XSS)wp search analytics project · wp search analytics · CWE-79 | Medium4.8 | — | 0.4% | May 10, 2023 |
19Monitor | CVE-2022-47423No exploit | WordPress WP-dTree Plugin <= 4.4.5 is vulnerable to Cross Site Scripting (XSS)wp-dtree project · wp-dtree · CWE-79 | Medium4.8 | — | 0.4% | May 10, 2023 |
19Monitor | CVE-2022-46861No exploit | WordPress Login Page Styler Plugin <= 6.2 is vulnerable to Cross Site Scripting (XSS)web-settler · custom login page styler · CWE-79 | Medium4.8 | — | 0.4% | May 10, 2023 |
19Monitor | CVE-2022-46819No exploit | WordPress Continuous announcement scroller Plugin <= 13.0 is vulnerable to Cross Site Scripting (XSS)gopiplus · continuous announcement scroller · CWE-79 | Medium4.8 | — | 0.4% | May 10, 2023 |
19Monitor | CVE-2022-46817No exploit | WordPress Flyzoo Chat Plugin <= 2.3.3 is vulnerable to Cross Site Scripting (XSS)flyzoo · flyzoo chat · CWE-79 | Medium4.8 | — | 0.4% | May 10, 2023 |
21Monitor | CVE-2023-22696No exploit | WordPress Affiliate Links Lite Plugin <= 2.5 is vulnerable to Cross Site Scripting (XSS)custom4web · affiliate links lite · CWE-79 | Medium5.4 | — | 0.4% | May 10, 2023 |
21Monitor | CVE-2022-46844No exploit | WordPress PixFields Plugin <= 0.7.0 is vulnerable to Cross Site Scripting (XSS)pixelgrade · pixfields · CWE-79 | Medium5.4 | — | 0.4% | May 9, 2023 |
30Monitor | CVE-2023-22687No exploit | WordPress Freesoul Deactivate Plugins – Plugin manager and cleanup Plugin <= 1.9.4.0 is vulnerable to Sensitive Data Exposurefreesoul deactivate plugins - plugin manager and cleanup project · freesoul deactivate plugins - plugin manager and cleanup · CWE-922 | High7.5 | — | 0.5% | Apr 16, 2023 |
19Monitor | CVE-2022-47596No exploit | WordPress Media Library Categories Plugin <= 1.9.9 is vulnerable to Cross Site Scripting (XSS)jeffrey-wp · media library categories · CWE-79 | Medium4.8 | — | 0.4% | Mar 29, 2023 |
19Monitor | CVE-2022-46863No exploit | WordPress Quick Event Manager Plugin <= 9.6.4 is vulnerable to Cross Site Scripting (XSS)fullworksplugins · quick event manager · CWE-79 | Medium4.8 | — | 0.4% | Mar 28, 2023 |
- CVE-2023-3652621Monitor
WordPress Duplicate Post Page Menu & Custom Post Type plugin <= 2.4.1 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 1%inqsys technology · duplicate post page menu & custom post typeDec 13, 2024
- CVE-2022-4760417Monitor
WordPress AJAX Thumbnail Rebuild plugin <= 1.13 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 1%junkcoder, ristoniinemets · ajax thumbnail rebuildApr 10, 2024
- CVE-2023-3250435Monitor
WordPress Wise Chat Plugin <= 3.1.3 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%kaine · wise chatNov 18, 2023
- CVE-2023-2842035Monitor
WordPress Custom Options Plus Plugin <= 1.8.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%leocaseiro · custom options plusNov 12, 2023
- CVE-2023-3403335Monitor
WordPress Ajax Pagination and Infinite Scroll Plugin <= 2.0.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%malinky · malinky-ajax-paginationNov 9, 2023
- CVE-2022-4744235Monitor
WordPress UsersWP Plugin <= 1.2.3.9 is vulnerable to CSV Injection
HighCVSS 8.8No exploitEPSS 1%ayecode · userswpNov 7, 2023
- CVE-2022-4685939Monitor
WordPress Spiffy Calendar Plugin <= 4.9.1 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%spiffyplugins · spiffy calendarNov 3, 2023
- CVE-2023-2506319Monitor
WordPress Quick Page/Post Redirect Plugin <= 5.2.3 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%anadnet · quick page\/post redirect pluginAug 8, 2023
- CVE-2023-2268935Monitor
WordPress Auto Affiliate Links Plugin <= 6.3 is vulnerable to Broken Access Control
HighCVSS 8.8No exploitEPSS 0%flamescorpion · auto affiliate linksMay 20, 2023
- CVE-2022-4715719Monitor
WordPress WP Custom Fields Search Plugin <= 1.2.34 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%webhammer · wp custom fields searchMay 18, 2023
- CVE-2022-4760619Monitor
WordPress WP-CORS Plugin <= 0.2.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%wp-cors project · wp-corsMay 10, 2023
- CVE-2022-4758719Monitor
WordPress WP Search Analytics Plugin <= 1.4.5 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%wp search analytics project · wp search analyticsMay 10, 2023
- CVE-2022-4742319Monitor
WordPress WP-dTree Plugin <= 4.4.5 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%wp-dtree project · wp-dtreeMay 10, 2023
- CVE-2022-4686119Monitor
WordPress Login Page Styler Plugin <= 6.2 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%web-settler · custom login page stylerMay 10, 2023
- CVE-2022-4681919Monitor
WordPress Continuous announcement scroller Plugin <= 13.0 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%gopiplus · continuous announcement scrollerMay 10, 2023
- CVE-2022-4681719Monitor
WordPress Flyzoo Chat Plugin <= 2.3.3 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%flyzoo · flyzoo chatMay 10, 2023
- CVE-2023-2269621Monitor
WordPress Affiliate Links Lite Plugin <= 2.5 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%custom4web · affiliate links liteMay 10, 2023
- CVE-2022-4684421Monitor
WordPress PixFields Plugin <= 0.7.0 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%pixelgrade · pixfieldsMay 9, 2023
- CVE-2023-2268730Monitor
WordPress Freesoul Deactivate Plugins – Plugin manager and cleanup Plugin <= 1.9.4.0 is vulnerable to Sensitive Data Exposure
HighCVSS 7.5No exploitEPSS 1%freesoul deactivate plugins - plugin manager and cleanup project · freesoul deactivate plugins - plugin manager and cleanupApr 16, 2023
- CVE-2022-4759619Monitor
WordPress Media Library Categories Plugin <= 1.9.9 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%jeffrey-wp · media library categoriesMar 29, 2023
- CVE-2022-4686319Monitor
WordPress Quick Event Manager Plugin <= 9.6.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%fullworksplugins · quick event managerMar 28, 2023