Skip to content
Noroxi

minhtuanact (Patchstack Alliance)

64 credited records · 0 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • WordPress Dynamic Visibility for Elementor plugin <= 5.0.5 - Broken Access Control vulnerability

    MediumCVSS 5.4No exploitEPSS 1%

    dynamic.ooo · dynamic visibility for elementorDec 13, 2024

  • WordPress Woo Custom Emails plugin <= 2.2 - Broken Access Control vulnerability

    HighCVSS 7.3No exploitEPSS 1%

    wp3sixty · woo custom emailsDec 13, 2024

  • WordPress Dynamics 365 Integration plugin <= 1.3.13 - Broken Access Control vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    alexacrm · dynamics 365 integrationDec 9, 2024

  • WordPress VideoWhisper Live Streaming Integration plugin <= 5.5.15 - Remote Code Execution (RCE)

    CriticalCVSS 9.8No exploitEPSS 1%

    videowhisper · videowhisper live streaming integrationApr 3, 2024

  • WordPress MailChimp Subscribe Forms Plugin <= 4.0.9.3 is vulnerable to Open Redirection

    MediumCVSS 6.1No exploitEPSS 0%

    ibericode · mailchimpDec 29, 2023

  • WordPress Advanced Page Visit Counter Plugin <= 6.4.2 is vulnerable to SQL Injection

    HighCVSS 8.8No exploitEPSS 1%

    pagevisitcounter · advanced page visit counterDec 20, 2023

  • WordPress Slideshow Gallery Plugin <= 1.7.6 is vulnerable to SQL Injection

    HighCVSS 7.2No exploitEPSS 1%

    tribulant · slideshow galleryDec 20, 2023

  • WordPress affiliate-toolkit – WordPress Affiliate Plugin Plugin <= 3.3.9 is vulnerable to Open Redirection

    MediumCVSS 6.1No exploitEPSS 0%

    servit · affiliate-toolkitDec 19, 2023

  • WordPress Doofinder for WooCommerce Plugin <= 1.5.49 is vulnerable to Open Redirection

    MediumCVSS 6.1No exploitEPSS 0%

    doofinder · doofinderDec 19, 2023

  • WordPress Integrate Google Drive Plugin <= 1.3.2 is vulnerable to Open Redirection

    MediumCVSS 6.1No exploitEPSS 0%

    softlabbd · integrate google driveDec 7, 2023

  • WordPress Landing Page Builder Plugin <= 1.5.1.5 is vulnerable to Open Redirection

    MediumCVSS 6.1No exploitEPSS 0%

    pluginops · landing page builderDec 7, 2023

  • WordPress Libsyn Publisher Hub Plugin <= 1.4.4 is vulnerable to Sensitive Data Exposure

    MediumCVSS 5.3No exploitEPSS 1%

    libsyn · libsyn publisher hubNov 30, 2023

  • WordPress EazyDocs Plugin <= 2.3.3 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    spider-themes · eazydocsNov 14, 2023

  • WordPress Icons Font Loader Plugin <= 1.1.2 is vulnerable to SQL Injection

    HighCVSS 8.8No exploitEPSS 1%

    bplugins · icons font loaderNov 6, 2023

  • WordPress Accessibility Suite by Online ADA Plugin <= 4.12 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    adaplugin · accessibility suite by online adaNov 6, 2023

  • WordPress Contact form 7 Custom validation Plugin <= 1.1.3 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    rocklobster · contact form 7 custom validationNov 6, 2023

  • WordPress Donations Made Easy – Smart Donations Plugin <= 4.0.12 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    rednao · donations made easy - smart donationsNov 6, 2023

  • WordPress Copy Or Move Comments Plugin <= 5.0.4 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    appjetty · copy or move commentsNov 6, 2023

  • WordPress Shortcode IMDB Plugin <= 6.0.8 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    kemalyazici · shortcode imdbNov 6, 2023

  • WordPress The School Management – Education & Learning Management Plugin <= 4.1 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    weblizar · school management - education \& learning managementNov 6, 2023

  • WordPress Accessibility Suite by Online ADA Plugin <= 4.12 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 0%

    adaplugin · accessibility suite by online adaNov 6, 2023

  • WordPress Onepage Builder – Easiest Landing Page Builder For WordPress Plugin <= 2.4.1 is vulnerable to SQL Injection

    HighCVSS 7.2No exploitEPSS 1%

    themesgrove · onepage builderNov 3, 2023

  • WordPress Order Your Posts Manually Plugin <= 2.2.5 is vulnerable to SQL Injection

    HighCVSS 7.2No exploitEPSS 1%

    cagewebdev · order your posts manuallyNov 3, 2023

  • WordPress Neshan Maps Plugin <= 1.1.4 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    neshan · neshan mapsNov 3, 2023

  • WordPress Simple Photo Gallery Plugin <= v1.8.1 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    tipsandtricks-hq · simple photo galleryNov 3, 2023