Bugbang
9 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-24384No exploit | JoomSport < 5.1.8 - Unauthenticated PHP Object Injectionbeardev · joomsport · CWE-502 | Critical9.8 | — | 2.1% | Jul 6, 2021 |
35Monitor | CVE-2021-24195No exploit | Login as User or Customer (User Switching) < 1.9 - Arbitrary Plugin Installation/Activation via Low Privilege Userwp-buy · login as user or customer \(user switching\) · CWE-285 | High8.8 | — | 1.3% | May 14, 2021 |
35Monitor | CVE-2021-24194No exploit | Login Protection - Limit Failed Login Attempts < 2.9 - Arbitrary Plugin Installation/Activation via Low Privilege Userwp-buy · login protection - limit failed login attempts · CWE-285 | High8.8 | — | 1.3% | May 14, 2021 |
35Monitor | CVE-2021-24193No exploit | Visitor Traffic Real Time Statistics < 2.12 - Arbitrary Plugin Installation/Activation via Low Privilege Userwp-buy · visitor traffic real time statistics · CWE-285 | High8.8 | — | 1.3% | May 14, 2021 |
35Monitor | CVE-2021-24192No exploit | Tree Sitemap < 2.9 - Arbitrary Plugin Installation/Activation via Low Privilege Usersitemap project · sitemap · CWE-285 | High8.8 | — | 1.3% | May 14, 2021 |
35Monitor | CVE-2021-24191No exploit | WP Maintenance Mode & Site Under Construction < 1.8.2 - Arbitrary Plugin Installation/Activation via Low Privilege Userwpshopmart · coming soon page \& maintenance mode · CWE-285 | High8.8 | — | 1.3% | May 14, 2021 |
35Monitor | CVE-2021-24190No exploit | WooCommerce Conditional Marketing Mailer < 1.5.2 - Arbitrary Plugin Installation/Activation via Low Privilege Userwp-buy · conditional marketing mailer · CWE-285 | High8.8 | — | 1.3% | May 14, 2021 |
35Monitor | CVE-2021-24189No exploit | Captchinoo, Google recaptcha for admin login page < 2.4 - Arbitrary Plugin Installation/Activation via Low Privilege Userwp-buy · captchinoo · CWE-285 | High8.8 | — | 1.3% | May 14, 2021 |
35Monitor | CVE-2021-24188No exploit | WP Content Copy Protection & No Right Click < 3.1.5 - Arbitrary Plugin Installation/Activation via Low Privilege Userwp-buy · wp content copy protection \& no right click · CWE-285 | High8.8 | — | 1.3% | May 14, 2021 |
- CVE-2021-2438440Plan
JoomSport < 5.1.8 - Unauthenticated PHP Object Injection
CriticalCVSS 9.8No exploitEPSS 2%beardev · joomsportJul 6, 2021
- CVE-2021-2419535Monitor
Login as User or Customer (User Switching) < 1.9 - Arbitrary Plugin Installation/Activation via Low Privilege User
HighCVSS 8.8No exploitEPSS 1%wp-buy · login as user or customer \(user switching\)May 14, 2021
- CVE-2021-2419435Monitor
Login Protection - Limit Failed Login Attempts < 2.9 - Arbitrary Plugin Installation/Activation via Low Privilege User
HighCVSS 8.8No exploitEPSS 1%wp-buy · login protection - limit failed login attemptsMay 14, 2021
- CVE-2021-2419335Monitor
Visitor Traffic Real Time Statistics < 2.12 - Arbitrary Plugin Installation/Activation via Low Privilege User
HighCVSS 8.8No exploitEPSS 1%wp-buy · visitor traffic real time statisticsMay 14, 2021
- CVE-2021-2419235Monitor
Tree Sitemap < 2.9 - Arbitrary Plugin Installation/Activation via Low Privilege User
HighCVSS 8.8No exploitEPSS 1%sitemap project · sitemapMay 14, 2021
- CVE-2021-2419135Monitor
WP Maintenance Mode & Site Under Construction < 1.8.2 - Arbitrary Plugin Installation/Activation via Low Privilege User
HighCVSS 8.8No exploitEPSS 1%wpshopmart · coming soon page \& maintenance modeMay 14, 2021
- CVE-2021-2419035Monitor
WooCommerce Conditional Marketing Mailer < 1.5.2 - Arbitrary Plugin Installation/Activation via Low Privilege User
HighCVSS 8.8No exploitEPSS 1%wp-buy · conditional marketing mailerMay 14, 2021
- CVE-2021-2418935Monitor
Captchinoo, Google recaptcha for admin login page < 2.4 - Arbitrary Plugin Installation/Activation via Low Privilege User
HighCVSS 8.8No exploitEPSS 1%wp-buy · captchinooMay 14, 2021
- CVE-2021-2418835Monitor
WP Content Copy Protection & No Right Click < 3.1.5 - Arbitrary Plugin Installation/Activation via Low Privilege User
HighCVSS 8.8No exploitEPSS 1%wp-buy · wp content copy protection \& no right clickMay 14, 2021