Webula
Patchstack Bug Bounty Program
16 записей с упоминанием · 0 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
23Наблюдать | CVE-2025-32135Эксплойта нет | WordPress Split Test For Elementor plugin <= 1.8.4 - Cross Site Scripting (XSS) vulnerabilityrocketelements · split test for elementor · CWE-79 | Средняя5,9 | — | 0,4 % | 4 апр. 2025 г. |
23Наблюдать | CVE-2025-31864Proof of concept | WordPress Beam me up Scotty – Back to Top Button plugin <= 1.0.23 - Cross Site Scripting (XSS) vulnerabilityout the box · beam me up scotty · CWE-79 | Средняя5,9 | — | 0,3 % | 1 апр. 2025 г. |
35Наблюдать | CVE-2025-22783Proof of concept | WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.03 - SQL Injection vulnerabilitysquirrly · seo plugin by squirrly seo · CWE-89 | Высокая8,8 | — | 0,6 % | 27 мар. 2025 г. |
30Наблюдать | CVE-2025-22652Proof of concept | WordPress Payment Forms for Paystack plugin <= 4.0.1 - SQL Injection vulnerabilitykendysond · payment forms for paystack · CWE-89 | Высокая7,6 | — | 0,9 % | 27 мар. 2025 г. |
30Наблюдать | CVE-2025-30921Proof of concept | WordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerabilitytribulant software · newsletters · CWE-89 | Высокая7,6 | — | 0,5 % | 27 мар. 2025 г. |
30Наблюдать | CVE-2025-26886Эксплойта нет | WordPress PublishPress Authors plugin <= 4.7.3 - SQL Injection vulnerabilitypublishpress · publishpress authors · CWE-89 | Высокая7,6 | — | 0,4 % | 15 мар. 2025 г. |
39Наблюдать | CVE-2025-26971Эксплойта нет | WordPress Poll Maker <= 5.6.5 - SQL Injection vulnerabilityays-pro · poll maker · CWE-89 | Критическая9,8 | — | 0,5 % | 25 февр. 2025 г. |
26Наблюдать | CVE-2025-26769Эксплойта нет | WordPress Vertex Addons for Elementor plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerabilitywebilia inc. · vertex addons for elementor · CWE-79 | Средняя6,5 | — | 0,2 % | 17 февр. 2025 г. |
26Наблюдать | CVE-2025-22662Эксплойта нет | WordPress SendPulse Email Marketing Newsletter plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerabilitysendpulse · sendpulse email marketing newsletter · CWE-79 | Средняя6,5 | — | 0,2 % | 4 февр. 2025 г. |
30Наблюдать | CVE-2025-24659Proof of concept | WordPress Premium Packages – Sell Digital Products Securely plugin <= 5.9.6 - SQL Injection vulnerabilityshahjada · wpdm – premium packages · CWE-89 | Высокая7,6 | — | 1,0 % | 24 янв. 2025 г. |
40В плане | CVE-2025-24587Proof of concept | WordPress Email Subscription Popup plugin <= 1.2.23 - SQL Injection vulnerabilitynks · email subscription popup · CWE-89 | Высокая7,6 | — | 32,2 % | 24 янв. 2025 г. |
30Наблюдать | CVE-2025-22710Proof of concept | WordPress Smart Manager Plugin <= 8.52.0 - SQL Injection vulnerabilitystoreapps · smart manager · CWE-89 | Высокая7,6 | — | 0,8 % | 21 янв. 2025 г. |
28Наблюдать | CVE-2025-22510Proof of concept | WordPress WC Price History for Omnibus plugin <= 2.1.4 - PHP Object Injection vulnerabilitykkarpieszuk · wc price history for omnibus · CWE-502 | Высокая7,2 | — | 1,2 % | 9 янв. 2025 г. |
30Наблюдать | CVE-2025-22352Proof of concept | WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin <= 1.4.9 - SQL Injection vulnerabilityelextensions · elex woocommerce advanced bulk edit products, prices & attributes · CWE-89 | Высокая7,6 | — | 0,7 % | 7 янв. 2025 г. |
28Наблюдать | CVE-2024-56289Proof of concept | WordPress Groundhogg plugin <= 3.7.3.3 - Reflected Cross Site Scripting (XSS) vulnerabilityadrian tobey · groundhogg · CWE-79 | Высокая7,1 | — | 0,7 % | 7 янв. 2025 г. |
37Наблюдать | CVE-2024-56278Proof of concept | WordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerabilitysmackcoders inc., · wp ultimate exporter · CWE-94 | Критическая9,1 | — | 1,9 % | 7 янв. 2025 г. |
- CVE-2025-3213523Наблюдать
WordPress Split Test For Elementor plugin <= 1.8.4 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 5,9Эксплойта нетEPSS 0 %rocketelements · split test for elementor4 апр. 2025 г.
- CVE-2025-3186423Наблюдать
WordPress Beam me up Scotty – Back to Top Button plugin <= 1.0.23 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 5,9Proof of conceptEPSS 0 %out the box · beam me up scotty1 апр. 2025 г.
- CVE-2025-2278335Наблюдать
WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.03 - SQL Injection vulnerability
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %squirrly · seo plugin by squirrly seo27 мар. 2025 г.
- CVE-2025-2265230Наблюдать
WordPress Payment Forms for Paystack plugin <= 4.0.1 - SQL Injection vulnerability
ВысокаяCVSS 7,6Proof of conceptEPSS 1 %kendysond · payment forms for paystack27 мар. 2025 г.
- CVE-2025-3092130Наблюдать
WordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerability
ВысокаяCVSS 7,6Proof of conceptEPSS 1 %tribulant software · newsletters27 мар. 2025 г.
- CVE-2025-2688630Наблюдать
WordPress PublishPress Authors plugin <= 4.7.3 - SQL Injection vulnerability
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %publishpress · publishpress authors15 мар. 2025 г.
- CVE-2025-2697139Наблюдать
WordPress Poll Maker <= 5.6.5 - SQL Injection vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %ays-pro · poll maker25 февр. 2025 г.
- CVE-2025-2676926Наблюдать
WordPress Vertex Addons for Elementor plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 0 %webilia inc. · vertex addons for elementor17 февр. 2025 г.
- CVE-2025-2266226Наблюдать
WordPress SendPulse Email Marketing Newsletter plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 0 %sendpulse · sendpulse email marketing newsletter4 февр. 2025 г.
- CVE-2025-2465930Наблюдать
WordPress Premium Packages – Sell Digital Products Securely plugin <= 5.9.6 - SQL Injection vulnerability
ВысокаяCVSS 7,6Proof of conceptEPSS 1 %shahjada · wpdm – premium packages24 янв. 2025 г.
- CVE-2025-2458740В плане
WordPress Email Subscription Popup plugin <= 1.2.23 - SQL Injection vulnerability
ВысокаяCVSS 7,6Proof of conceptEPSS 32 %nks · email subscription popup24 янв. 2025 г.
- CVE-2025-2271030Наблюдать
WordPress Smart Manager Plugin <= 8.52.0 - SQL Injection vulnerability
ВысокаяCVSS 7,6Proof of conceptEPSS 1 %storeapps · smart manager21 янв. 2025 г.
- CVE-2025-2251028Наблюдать
WordPress WC Price History for Omnibus plugin <= 2.1.4 - PHP Object Injection vulnerability
ВысокаяCVSS 7,2Proof of conceptEPSS 1 %kkarpieszuk · wc price history for omnibus9 янв. 2025 г.
- CVE-2025-2235230Наблюдать
WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin <= 1.4.9 - SQL Injection vulnerability
ВысокаяCVSS 7,6Proof of conceptEPSS 1 %elextensions · elex woocommerce advanced bulk edit products, prices & attributes7 янв. 2025 г.
- CVE-2024-5628928Наблюдать
WordPress Groundhogg plugin <= 3.7.3.3 - Reflected Cross Site Scripting (XSS) vulnerability
ВысокаяCVSS 7,1Proof of conceptEPSS 1 %adrian tobey · groundhogg7 янв. 2025 г.
- CVE-2024-5627837Наблюдать
WordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerability
КритическаяCVSS 9,1Proof of conceptEPSS 2 %smackcoders inc., · wp ultimate exporter7 янв. 2025 г.