Записи wpchill
47 опубликованных записей вендора wpchill.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 27,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-862 Missing Authorization4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-434 Unrestricted Upload of File with Dangerous Type3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
47 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2021-23174Эксплойта нет | WordPress Download Monitor plugin <= 4.4.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilitywpchill · download monitor · CWE-79 | Средняя4,8 | — | 83,9 % | 28 янв. 2022 г. |
41В плане | CVE-2022-45354Proof of concept | WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposurewpchill · download monitor · CWE-200 | Высокая7,5 | — | 38,1 % | 8 янв. 2024 г. |
35Наблюдать | CVE-2023-34007Эксплойта нет | WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Uploadwpchill · download monitor · CWE-434 | Высокая8,8 | — | 0,9 % | 20 дек. 2023 г. |
35Наблюдать | CVE-2024-12853Эксплойта нет | Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Uploadwpchill · modula image gallery · CWE-434 | Высокая8,8 | — | 0,9 % | 8 янв. 2025 г. |
35Наблюдать | CVE-2024-47362Эксплойта нет | WordPress Strong Testimonials plugin <= 3.1.16 - Broken Access Control vulnerabilitywpchill · strong testimonials · CWE-862 | Высокая8,8 | — | 0,4 % | 1 нояб. 2024 г. |
35Наблюдать | CVE-2024-49256Эксплойта нет | WordPress Htaccess File Editor plugin <= 1.0.18 - Broken Access Control vulnerabilitywpchill · htaccess file editor · CWE-863 | Высокая8,8 | — | 0,4 % | 1 нояб. 2024 г. |
35Наблюдать | CVE-2022-36292Эксплойта нет | WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Cross-Site Request Forgery (CSRF) vulnerabilitieswpchill · gallery photoblocks · CWE-352 | Высокая8,8 | — | 0,4 % | 23 авг. 2022 г. |
35Наблюдать | CVE-2023-52123Эксплойта нет | WordPress Strong Testimonials Plugin <= 3.1.10 is vulnerable to Cross Site Request Forgery (CSRF)wpchill · strong testimonials · CWE-352 | Высокая8,8 | — | 0,2 % | 5 янв. 2024 г. |
33Наблюдать | CVE-2021-24786Proof of concept | Download Monitor < 4.4.5 - Admin+ SQL Injectionwpchill · download monitor · CWE-89 | Высокая7,2 | — | 17,3 % | 3 янв. 2022 г. |
30Наблюдать | CVE-2022-4972Эксплойта нет | Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Exportwpchill · download monitor · CWE-862 | Высокая7,5 | — | 0,5 % | 16 окт. 2024 г. |
30Наблюдать | CVE-2024-11282Эксплойта нет | Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposurewpchill · passster · CWE-200 | Высокая7,5 | — | 0,4 % | 7 янв. 2025 г. |
28Наблюдать | CVE-2021-24774Эксплойта нет | Check & Log Email < 1.0.3 - Admin+ SQL Injectionswpchill · check \& log email · CWE-89 | Высокая7,2 | — | 1,3 % | 25 окт. 2021 г. |
28Наблюдать | CVE-2025-13645Эксплойта нет | Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletionwpchill · modula image gallery · CWE-22 | Высокая7,2 | — | 1,0 % | 2 дек. 2025 г. |
28Наблюдать | CVE-2024-30501Эксплойта нет | WordPress Download Monitor theme <= 4.9.4 - Auth. SQL Injection vulnerabilitywpchill · download monitor · CWE-89 | Высокая7,2 | — | 0,6 % | 29 мар. 2024 г. |
27Наблюдать | CVE-2021-31567Эксплойта нет | WordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerabilitywpchill · download monitor · CWE-200 | Средняя6,8 | — | 1,4 % | 28 янв. 2022 г. |
27Наблюдать | CVE-2024-3710Эксплойта нет | Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSSwpchill · image photo gallery final tiles grid · CWE-79 | Средняя6,8 | — | 0,5 % | 13 июл. 2024 г. |
26Наблюдать | CVE-2025-13646Эксплойта нет | Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Conditionwpchill · modula image gallery · CWE-434 | Средняя6,6 | — | 0,8 % | 2 дек. 2025 г. |
25Наблюдать | CVE-2020-8549Эксплойта нет | Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as steawpchill · strong testimonials · CWE-79 | Средняя6,1 | — | 1,9 % | 3 февр. 2020 г. |
24Наблюдать | CVE-2022-1547Эксплойта нет | Check & Log email < 1.0.6 - Reflected Cross-Site Scriptingwpchill · check \& log email · CWE-79 | Средняя6,1 | — | 0,8 % | 23 мая 2022 г. |
24Наблюдать | CVE-2021-24908Эксплойта нет | Check & Log Email < 1.0.4 - Reflected Cross-Site Scriptingwpchill · check \& log email · CWE-79 | Средняя6,1 | — | 0,8 % | 29 нояб. 2021 г. |
24Наблюдать | CVE-2022-27852Эксплойта нет | WordPress KB Support plugin <= 1.5.5 - Multiple Unauth. Stored Cross-Site Scripting (XSS) vulnerabilitieswpchill · kb support · CWE-79 | Средняя6,1 | — | 0,7 % | 15 апр. 2022 г. |
22Наблюдать | CVE-2022-1054Proof of concept | RSVP and Event Management < 2.7.8 - Unauthenticated Entries Exportwpchill · rsvp and event management · CWE-862 | Средняя5,3 | — | 4,2 % | 18 апр. 2022 г. |
21Наблюдать | CVE-2020-9003Эксплойта нет | A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress.wpchill · modula image gallery · CWE-79 | Средняя5,4 | — | 1,0 % | 20 февр. 2020 г. |
21Наблюдать | CVE-2022-37407Эксплойта нет | WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitieswpchill · gallery photoblocks · CWE-79 | Средняя5,4 | — | 0,6 % | 9 сент. 2022 г. |
21Наблюдать | CVE-2021-36920Эксплойта нет | WordPress plugin Download Monitor <= 4.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilitywpchill · download monitor · CWE-79 | Средняя5,4 | — | 0,6 % | 14 янв. 2022 г. |
- CVE-2021-2317444В плане
WordPress Download Monitor plugin <= 4.4.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
СредняяCVSS 4,8Эксплойта нетEPSS 84 %wpchill · download monitor28 янв. 2022 г.
- CVE-2022-4535441В плане
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
ВысокаяCVSS 7,5Proof of conceptEPSS 38 %wpchill · download monitor8 янв. 2024 г.
- CVE-2023-3400735Наблюдать
WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Upload
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wpchill · download monitor20 дек. 2023 г.
- CVE-2024-1285335Наблюдать
Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Upload
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wpchill · modula image gallery8 янв. 2025 г.
- CVE-2024-4736235Наблюдать
WordPress Strong Testimonials plugin <= 3.1.16 - Broken Access Control vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wpchill · strong testimonials1 нояб. 2024 г.
- CVE-2024-4925635Наблюдать
WordPress Htaccess File Editor plugin <= 1.0.18 - Broken Access Control vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wpchill · htaccess file editor1 нояб. 2024 г.
- CVE-2022-3629235Наблюдать
WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Cross-Site Request Forgery (CSRF) vulnerabilities
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wpchill · gallery photoblocks23 авг. 2022 г.
- CVE-2023-5212335Наблюдать
WordPress Strong Testimonials Plugin <= 3.1.10 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wpchill · strong testimonials5 янв. 2024 г.
- CVE-2021-2478633Наблюдать
Download Monitor < 4.4.5 - Admin+ SQL Injection
ВысокаяCVSS 7,2Proof of conceptEPSS 17 %wpchill · download monitor3 янв. 2022 г.
- CVE-2022-497230Наблюдать
Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Export
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %wpchill · download monitor16 окт. 2024 г.
- CVE-2024-1128230Наблюдать
Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %wpchill · passster7 янв. 2025 г.
- CVE-2021-2477428Наблюдать
Check & Log Email < 1.0.3 - Admin+ SQL Injections
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %wpchill · check \& log email25 окт. 2021 г.
- CVE-2025-1364528Наблюдать
Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %wpchill · modula image gallery2 дек. 2025 г.
- CVE-2024-3050128Наблюдать
WordPress Download Monitor theme <= 4.9.4 - Auth. SQL Injection vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %wpchill · download monitor29 мар. 2024 г.
- CVE-2021-3156727Наблюдать
WordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerability
СредняяCVSS 6,8Эксплойта нетEPSS 1 %wpchill · download monitor28 янв. 2022 г.
- CVE-2024-371027Наблюдать
Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSS
СредняяCVSS 6,8Эксплойта нетEPSS 0 %wpchill · image photo gallery final tiles grid13 июл. 2024 г.
- CVE-2025-1364626Наблюдать
Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition
СредняяCVSS 6,6Эксплойта нетEPSS 1 %wpchill · modula image gallery2 дек. 2025 г.
- CVE-2020-854925Наблюдать
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stea
СредняяCVSS 6,1Эксплойта нетEPSS 2 %wpchill · strong testimonials3 февр. 2020 г.
- CVE-2022-154724Наблюдать
Check & Log email < 1.0.6 - Reflected Cross-Site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %wpchill · check \& log email23 мая 2022 г.
- CVE-2021-2490824Наблюдать
Check & Log Email < 1.0.4 - Reflected Cross-Site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %wpchill · check \& log email29 нояб. 2021 г.
- CVE-2022-2785224Наблюдать
WordPress KB Support plugin <= 1.5.5 - Multiple Unauth. Stored Cross-Site Scripting (XSS) vulnerabilities
СредняяCVSS 6,1Эксплойта нетEPSS 1 %wpchill · kb support15 апр. 2022 г.
- CVE-2022-105422Наблюдать
RSVP and Event Management < 2.7.8 - Unauthenticated Entries Export
СредняяCVSS 5,3Proof of conceptEPSS 4 %wpchill · rsvp and event management18 апр. 2022 г.
- CVE-2020-900321Наблюдать
A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %wpchill · modula image gallery20 февр. 2020 г.
- CVE-2022-3740721Наблюдать
WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
СредняяCVSS 5,4Эксплойта нетEPSS 1 %wpchill · gallery photoblocks9 сент. 2022 г.
- CVE-2021-3692021Наблюдать
WordPress plugin Download Monitor <= 4.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 1 %wpchill · download monitor14 янв. 2022 г.