Перейти к содержимому
Noroxi

Записи wpWax

24 опубликованных записей вендора wpwax.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
29,2 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

24 записей
  • CVE-2025-1570
    39Наблюдать

    Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTP

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    wpwax · directorist28 февр. 2025 г.

  • CVE-2024-2006
    35Наблюдать

    Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 - Authenticated (Contributor+) PHP Object Injection in outpo

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    wpwax · post grid\, slider \& carousel ultimate13 мар. 2024 г.

  • CVE-2024-1950
    35Наблюдать

    Product Carousel Slider & Grid Ultimate for WooCommerce <= 1.9.7 - Authenticated(Contributor+) PHP Object Injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    wpwax · product carousel slider \& grid ultimate for woocommerce13 мар. 2024 г.

  • CVE-2023-1888
    35Наблюдать

    Directorist <= 7.5.4 - Authenticated (Subscriber+) Arbitrary User Password Reset to Privilege Escalation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    wpwax · directorist9 июн. 2023 г.

  • CVE-2024-13409
    35Наблюдать

    Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via pos

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    wpwax · post grid\, slider \& carousel ultimate24 янв. 2025 г.

  • CVE-2023-41798
    35Наблюдать

    WordPress Directorist Plugin <= 7.7.1 is vulnerable to CSV Injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    wpwax · directorist7 нояб. 2023 г.

  • CVE-2025-24782
    35Наблюдать

    WordPress Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    wpwax · post grid\, slider \& carousel ultimate27 янв. 2025 г.

  • CVE-2023-47824
    35Наблюдать

    WordPress Legal Pages Plugin <= 1.3.8 is vulnerable to Cross Site Request Forgery (CSRF)

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    wpwax · legal pages22 нояб. 2023 г.

  • CVE-2023-50886
    32Наблюдать

    WordPress Legal Pages plugin <= 1.3.7 - CSRF + Broken Access Control vulnerability

    ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %

    wpwax · legal pages15 мар. 2024 г.

  • CVE-2024-1951
    30Наблюдать

    Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid <= 1.3.8 - Authenticated(Contributor+) PHP Object Injection

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    wpwax · logo showcase ultimate – logo carousel, logo slider & logo grid13 мар. 2024 г.

  • CVE-2021-24981
    30Наблюдать

    Directorist – Business Directory Plugin < 7.0.6.2 - CSRF to Remote File Upload

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    wpwax · directorist21 дек. 2021 г.

  • CVE-2022-3961
    26Наблюдать

    Directorist < 7.4.4 - Subscriber+ Sensitive Information Disclosure

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    wpwax · directorist19 дек. 2022 г.

  • CVE-2022-3930
    26Наблюдать

    Directorist < 7.4.2.2 - Subscriber+ Arbitrary User Password Update via IDOR

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    wpwax · directorist12 дек. 2022 г.

  • CVE-2023-1889
    26Наблюдать

    Directorist <= 7.5.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Deletion in listing_task

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    wpwax · directorist9 июн. 2023 г.

  • CVE-2022-2376
    22Наблюдать

    Directorist < 7.3.1 - Unauthenticated Email Address Disclosure

    СредняяCVSS 5,3Proof of conceptEPSS 2 %

    wpwax · directorist5 сент. 2022 г.

  • CVE-2022-34853
    21Наблюдать

    WordPress Team plugin <= 1.2.6 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    wpwax · team22 июл. 2022 г.

  • CVE-2022-34650
    21Наблюдать

    WordPress Team plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    wpwax · team22 июл. 2022 г.

  • CVE-2024-1322
    21Наблюдать

    Directorist <= 7.8.4 - Missing Authorization to Unauthenticated Settings Change

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    wpwax · directorist28 февр. 2024 г.

  • CVE-2024-12041
    21Наблюдать

    Directorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information Exposure

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    wpwax · directorist1 февр. 2025 г.

  • CVE-2024-29925
    21Наблюдать

    WordPress Post Grid, Slider & Carousel Ultimate plugin <= 1.6.6 - Cross Site Scripting (XSS) vulnerability

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    wpwax · post grid\, slider \& carousel ultimate27 мар. 2024 г.

  • CVE-2022-2046
    19Наблюдать

    Directorist - Business Directory Plugin < 7.2.3 - Admin+ Arbitrary File Upload

    СредняяCVSS 4,9Эксплойта нетEPSS 1 %

    wpwax · directorist8 авг. 2022 г.

  • CVE-2022-1266
    19Наблюдать

    Post Grid, Slider & Carousel Ultimate < 1.5.0 - Admin+ Stored XSS

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    wpwax · post grid\, slider \& carousel ultimate20 июн. 2022 г.

  • CVE-2022-2377
    17Наблюдать

    Directorist < 7.3.0 - Subscriber+ Arbitrary E-mail Sending

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    wpwax · directorist22 авг. 2022 г.

  • CVE-2023-2252
    10Наблюдать

    Directorist < 7.5.4 - Admin+ LFI

    НизкаяCVSS 2,7Proof of conceptEPSS 1 %

    wpwax · directorist16 янв. 2024 г.