Skip to content
Noroxi

Justiice (Patchstack Alliance)

21 credited records · 0 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • WordPress Duplicate Post Page Menu & Custom Post Type plugin <= 2.4.1 - Broken Access Control vulnerability

    MediumCVSS 5.4No exploitEPSS 1%

    inqsys technology · duplicate post page menu & custom post typeDec 13, 2024

  • WordPress AJAX Thumbnail Rebuild plugin <= 1.13 - Broken Access Control vulnerability

    MediumCVSS 4.3No exploitEPSS 1%

    junkcoder, ristoniinemets · ajax thumbnail rebuildApr 10, 2024

  • WordPress Wise Chat Plugin <= 3.1.3 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    kaine · wise chatNov 18, 2023

  • WordPress Custom Options Plus Plugin <= 1.8.1 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    leocaseiro · custom options plusNov 12, 2023

  • WordPress Ajax Pagination and Infinite Scroll Plugin <= 2.0.1 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    malinky · malinky-ajax-paginationNov 9, 2023

  • WordPress UsersWP Plugin <= 1.2.3.9 is vulnerable to CSV Injection

    HighCVSS 8.8No exploitEPSS 1%

    ayecode · userswpNov 7, 2023

  • WordPress Spiffy Calendar Plugin <= 4.9.1 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    spiffyplugins · spiffy calendarNov 3, 2023

  • WordPress Quick Page/Post Redirect Plugin <= 5.2.3 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    anadnet · quick page\/post redirect pluginAug 8, 2023

  • WordPress Auto Affiliate Links Plugin <= 6.3 is vulnerable to Broken Access Control

    HighCVSS 8.8No exploitEPSS 0%

    flamescorpion · auto affiliate linksMay 20, 2023

  • WordPress WP Custom Fields Search Plugin <= 1.2.34 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    webhammer · wp custom fields searchMay 18, 2023

  • WordPress WP-CORS Plugin <= 0.2.1 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    wp-cors project · wp-corsMay 10, 2023

  • WordPress WP Search Analytics Plugin <= 1.4.5 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    wp search analytics project · wp search analyticsMay 10, 2023

  • WordPress WP-dTree Plugin <= 4.4.5 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    wp-dtree project · wp-dtreeMay 10, 2023

  • WordPress Login Page Styler Plugin <= 6.2 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    web-settler · custom login page stylerMay 10, 2023

  • WordPress Continuous announcement scroller Plugin <= 13.0 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    gopiplus · continuous announcement scrollerMay 10, 2023

  • WordPress Flyzoo Chat Plugin <= 2.3.3 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    flyzoo · flyzoo chatMay 10, 2023

  • WordPress Affiliate Links Lite Plugin <= 2.5 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    custom4web · affiliate links liteMay 10, 2023

  • WordPress PixFields Plugin <= 0.7.0 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    pixelgrade · pixfieldsMay 9, 2023

  • WordPress Freesoul Deactivate Plugins – Plugin manager and cleanup Plugin <= 1.9.4.0 is vulnerable to Sensitive Data Exposure

    HighCVSS 7.5No exploitEPSS 1%

    freesoul deactivate plugins - plugin manager and cleanup project · freesoul deactivate plugins - plugin manager and cleanupApr 16, 2023

  • WordPress Media Library Categories Plugin <= 1.9.9 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    jeffrey-wp · media library categoriesMar 29, 2023

  • WordPress Quick Event Manager Plugin <= 9.6.4 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    fullworksplugins · quick event managerMar 28, 2023