minhtuanact (Patchstack Alliance)
64 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2023-35046No exploit | WordPress Dynamic Visibility for Elementor plugin <= 5.0.5 - Broken Access Control vulnerabilitydynamic.ooo · dynamic visibility for elementor · CWE-862 | Medium5.4 | — | 0.6% | Dec 13, 2024 |
29Monitor | CVE-2023-32507No exploit | WordPress Woo Custom Emails plugin <= 2.2 - Broken Access Control vulnerabilitywp3sixty · woo custom emails · CWE-862 | High7.3 | — | 0.5% | Dec 13, 2024 |
17Monitor | CVE-2023-29422No exploit | WordPress Dynamics 365 Integration plugin <= 1.3.13 - Broken Access Control vulnerabilityalexacrm · dynamics 365 integration · CWE-862 | Medium4.3 | — | 0.4% | Dec 9, 2024 |
39Monitor | CVE-2023-25699No exploit | WordPress VideoWhisper Live Streaming Integration plugin <= 5.5.15 - Remote Code Execution (RCE)videowhisper · videowhisper live streaming integration · CWE-78 | Critical9.8 | — | 1.3% | Apr 3, 2024 |
24Monitor | CVE-2023-32517No exploit | WordPress MailChimp Subscribe Forms Plugin <= 4.0.9.3 is vulnerable to Open Redirectionibericode · mailchimp · CWE-601 | Medium6.1 | — | 0.4% | Dec 29, 2023 |
35Monitor | CVE-2023-28788No exploit | WordPress Advanced Page Visit Counter Plugin <= 6.4.2 is vulnerable to SQL Injectionpagevisitcounter · advanced page visit counter · CWE-89 | High8.8 | — | 0.7% | Dec 20, 2023 |
28Monitor | CVE-2023-28491No exploit | WordPress Slideshow Gallery Plugin <= 1.7.6 is vulnerable to SQL Injectiontribulant · slideshow gallery · CWE-89 | High7.2 | — | 0.8% | Dec 20, 2023 |
24Monitor | CVE-2023-45105No exploit | WordPress affiliate-toolkit – WordPress Affiliate Plugin Plugin <= 3.3.9 is vulnerable to Open Redirectionservit · affiliate-toolkit · CWE-601 | Medium6.1 | — | 0.5% | Dec 19, 2023 |
24Monitor | CVE-2023-40602No exploit | WordPress Doofinder for WooCommerce Plugin <= 1.5.49 is vulnerable to Open Redirectiondoofinder · doofinder · CWE-601 | Medium6.1 | — | 0.5% | Dec 19, 2023 |
24Monitor | CVE-2023-47548No exploit | WordPress Integrate Google Drive Plugin <= 1.3.2 is vulnerable to Open Redirectionsoftlabbd · integrate google drive · CWE-601 | Medium6.1 | — | 0.4% | Dec 7, 2023 |
24Monitor | CVE-2023-48325No exploit | WordPress Landing Page Builder Plugin <= 1.5.1.5 is vulnerable to Open Redirectionpluginops · landing page builder · CWE-601 | Medium6.1 | — | 0.4% | Dec 7, 2023 |
21Monitor | CVE-2023-45834No exploit | WordPress Libsyn Publisher Hub Plugin <= 1.4.4 is vulnerable to Sensitive Data Exposurelibsyn · libsyn publisher hub · CWE-200 | Medium5.3 | — | 0.5% | Nov 30, 2023 |
24Monitor | CVE-2023-47549No exploit | WordPress EazyDocs Plugin <= 2.3.3 is vulnerable to Cross Site Scripting (XSS)spider-themes · eazydocs · CWE-79 | Medium6.1 | — | 0.4% | Nov 14, 2023 |
35Monitor | CVE-2023-46084No exploit | WordPress Icons Font Loader Plugin <= 1.1.2 is vulnerable to SQL Injectionbplugins · icons font loader · CWE-89 | High8.8 | — | 0.5% | Nov 6, 2023 |
39Monitor | CVE-2023-45830No exploit | WordPress Accessibility Suite by Online ADA Plugin <= 4.12 is vulnerable to SQL Injectionadaplugin · accessibility suite by online ada · CWE-89 | Critical9.8 | — | 0.6% | Nov 6, 2023 |
39Monitor | CVE-2023-40609No exploit | WordPress Contact form 7 Custom validation Plugin <= 1.1.3 is vulnerable to SQL Injectionrocklobster · contact form 7 custom validation · CWE-89 | Critical9.8 | — | 0.7% | Nov 6, 2023 |
39Monitor | CVE-2023-40207No exploit | WordPress Donations Made Easy – Smart Donations Plugin <= 4.0.12 is vulnerable to SQL Injectionrednao · donations made easy - smart donations · CWE-89 | Critical9.8 | — | 0.7% | Nov 6, 2023 |
39Monitor | CVE-2023-28748No exploit | WordPress Copy Or Move Comments Plugin <= 5.0.4 is vulnerable to SQL Injectionappjetty · copy or move comments · CWE-89 | Critical9.8 | — | 0.6% | Nov 6, 2023 |
39Monitor | CVE-2022-47432No exploit | WordPress Shortcode IMDB Plugin <= 6.0.8 is vulnerable to SQL Injectionkemalyazici · shortcode imdb · CWE-89 | Critical9.8 | — | 0.7% | Nov 6, 2023 |
39Monitor | CVE-2022-47430No exploit | WordPress The School Management – Education & Learning Management Plugin <= 4.1 is vulnerable to SQL Injectionweblizar · school management - education \& learning management · CWE-89 | Critical9.8 | — | 0.7% | Nov 6, 2023 |
39Monitor | CVE-2022-47420No exploit | WordPress Accessibility Suite by Online ADA Plugin <= 4.12 is vulnerable to SQL Injectionadaplugin · accessibility suite by online ada · CWE-89 | Critical9.8 | — | 0.5% | Nov 6, 2023 |
28Monitor | CVE-2023-38391No exploit | WordPress Onepage Builder – Easiest Landing Page Builder For WordPress Plugin <= 2.4.1 is vulnerable to SQL Injectionthemesgrove · onepage builder · CWE-89 | High7.2 | — | 0.7% | Nov 3, 2023 |
28Monitor | CVE-2023-32508No exploit | WordPress Order Your Posts Manually Plugin <= 2.2.5 is vulnerable to SQL Injectioncagewebdev · order your posts manually · CWE-89 | High7.2 | — | 0.7% | Nov 3, 2023 |
39Monitor | CVE-2022-47426No exploit | WordPress Neshan Maps Plugin <= 1.1.4 is vulnerable to SQL Injectionneshan · neshan maps · CWE-89 | Critical9.8 | — | 0.5% | Nov 3, 2023 |
39Monitor | CVE-2022-47588No exploit | WordPress Simple Photo Gallery Plugin <= v1.8.1 is vulnerable to SQL Injectiontipsandtricks-hq · simple photo gallery · CWE-89 | Critical9.8 | — | 0.7% | Nov 3, 2023 |
- CVE-2023-3504621Monitor
WordPress Dynamic Visibility for Elementor plugin <= 5.0.5 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 1%dynamic.ooo · dynamic visibility for elementorDec 13, 2024
- CVE-2023-3250729Monitor
WordPress Woo Custom Emails plugin <= 2.2 - Broken Access Control vulnerability
HighCVSS 7.3No exploitEPSS 1%wp3sixty · woo custom emailsDec 13, 2024
- CVE-2023-2942217Monitor
WordPress Dynamics 365 Integration plugin <= 1.3.13 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%alexacrm · dynamics 365 integrationDec 9, 2024
- CVE-2023-2569939Monitor
WordPress VideoWhisper Live Streaming Integration plugin <= 5.5.15 - Remote Code Execution (RCE)
CriticalCVSS 9.8No exploitEPSS 1%videowhisper · videowhisper live streaming integrationApr 3, 2024
- CVE-2023-3251724Monitor
WordPress MailChimp Subscribe Forms Plugin <= 4.0.9.3 is vulnerable to Open Redirection
MediumCVSS 6.1No exploitEPSS 0%ibericode · mailchimpDec 29, 2023
- CVE-2023-2878835Monitor
WordPress Advanced Page Visit Counter Plugin <= 6.4.2 is vulnerable to SQL Injection
HighCVSS 8.8No exploitEPSS 1%pagevisitcounter · advanced page visit counterDec 20, 2023
- CVE-2023-2849128Monitor
WordPress Slideshow Gallery Plugin <= 1.7.6 is vulnerable to SQL Injection
HighCVSS 7.2No exploitEPSS 1%tribulant · slideshow galleryDec 20, 2023
- CVE-2023-4510524Monitor
WordPress affiliate-toolkit – WordPress Affiliate Plugin Plugin <= 3.3.9 is vulnerable to Open Redirection
MediumCVSS 6.1No exploitEPSS 0%servit · affiliate-toolkitDec 19, 2023
- CVE-2023-4060224Monitor
WordPress Doofinder for WooCommerce Plugin <= 1.5.49 is vulnerable to Open Redirection
MediumCVSS 6.1No exploitEPSS 0%doofinder · doofinderDec 19, 2023
- CVE-2023-4754824Monitor
WordPress Integrate Google Drive Plugin <= 1.3.2 is vulnerable to Open Redirection
MediumCVSS 6.1No exploitEPSS 0%softlabbd · integrate google driveDec 7, 2023
- CVE-2023-4832524Monitor
WordPress Landing Page Builder Plugin <= 1.5.1.5 is vulnerable to Open Redirection
MediumCVSS 6.1No exploitEPSS 0%pluginops · landing page builderDec 7, 2023
- CVE-2023-4583421Monitor
WordPress Libsyn Publisher Hub Plugin <= 1.4.4 is vulnerable to Sensitive Data Exposure
MediumCVSS 5.3No exploitEPSS 1%libsyn · libsyn publisher hubNov 30, 2023
- CVE-2023-4754924Monitor
WordPress EazyDocs Plugin <= 2.3.3 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%spider-themes · eazydocsNov 14, 2023
- CVE-2023-4608435Monitor
WordPress Icons Font Loader Plugin <= 1.1.2 is vulnerable to SQL Injection
HighCVSS 8.8No exploitEPSS 1%bplugins · icons font loaderNov 6, 2023
- CVE-2023-4583039Monitor
WordPress Accessibility Suite by Online ADA Plugin <= 4.12 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%adaplugin · accessibility suite by online adaNov 6, 2023
- CVE-2023-4060939Monitor
WordPress Contact form 7 Custom validation Plugin <= 1.1.3 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%rocklobster · contact form 7 custom validationNov 6, 2023
- CVE-2023-4020739Monitor
WordPress Donations Made Easy – Smart Donations Plugin <= 4.0.12 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%rednao · donations made easy - smart donationsNov 6, 2023
- CVE-2023-2874839Monitor
WordPress Copy Or Move Comments Plugin <= 5.0.4 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%appjetty · copy or move commentsNov 6, 2023
- CVE-2022-4743239Monitor
WordPress Shortcode IMDB Plugin <= 6.0.8 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%kemalyazici · shortcode imdbNov 6, 2023
- CVE-2022-4743039Monitor
WordPress The School Management – Education & Learning Management Plugin <= 4.1 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%weblizar · school management - education \& learning managementNov 6, 2023
- CVE-2022-4742039Monitor
WordPress Accessibility Suite by Online ADA Plugin <= 4.12 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 0%adaplugin · accessibility suite by online adaNov 6, 2023
- CVE-2023-3839128Monitor
WordPress Onepage Builder – Easiest Landing Page Builder For WordPress Plugin <= 2.4.1 is vulnerable to SQL Injection
HighCVSS 7.2No exploitEPSS 1%themesgrove · onepage builderNov 3, 2023
- CVE-2023-3250828Monitor
WordPress Order Your Posts Manually Plugin <= 2.2.5 is vulnerable to SQL Injection
HighCVSS 7.2No exploitEPSS 1%cagewebdev · order your posts manuallyNov 3, 2023
- CVE-2022-4742639Monitor
WordPress Neshan Maps Plugin <= 1.1.4 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%neshan · neshan mapsNov 3, 2023
- CVE-2022-4758839Monitor
WordPress Simple Photo Gallery Plugin <= v1.8.1 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%tipsandtricks-hq · simple photo galleryNov 3, 2023