Cat (Patchstack Alliance)
39 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2022-47601No exploit | WordPress WP Table Manager plugin <= 3.5.2 - Broken Access Controljoomunited · wp table manager · CWE-862 | Medium5.3 | — | 0.4% | Jan 2, 2025 |
17Monitor | CVE-2023-39994No exploit | WordPress ARMember Premium plugin <= 5.9.2 - Broken Access Controlreputeinfosystems · armember · CWE-862 | Medium4.3 | — | 0.3% | Jan 2, 2025 |
21Monitor | CVE-2023-39996No exploit | WordPress Accordion and Accordion Slider plugin <= 1.2.4 - Broken Access Controlwp onlinesupport, essential plugin · accordion and accordion slider · CWE-862 | Medium5.3 | — | 0.5% | Dec 13, 2024 |
17Monitor | CVE-2023-39995No exploit | WordPress Portfolio and Projects plugin <= 1.3.7 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · portfolio and projects · CWE-862 | Medium4.3 | — | 0.5% | Dec 13, 2024 |
21Monitor | CVE-2023-36519No exploit | WordPress SW Product Bundles plugin <= 2.0.15 - Broken Access Control vulnerabilitywpthemego · sw product bundles · CWE-862 | Medium5.4 | — | 0.6% | Dec 13, 2024 |
17Monitor | CVE-2023-36518No exploit | WordPress Post Hit Counter plugin <= 1.3.2 - Broken Access Controlhugh lashbrooke · post hit counter · CWE-862 | Medium4.3 | — | 0.5% | Dec 13, 2024 |
21Monitor | CVE-2022-47182No exploit | WordPress APIExperts Square for WooCommerce plugin <= 4.4.1 - Broken Access Controlwpexpertsio · apiexperts square for woocommerce · CWE-862 | Medium5.3 | — | 0.5% | Dec 13, 2024 |
21Monitor | CVE-2022-46846No exploit | WordPress Trending/Popular Post Slider and Widget plugin <= 1.5.7 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · trending/popular post slider and widget · CWE-862 | Medium5.3 | — | 0.5% | Dec 13, 2024 |
17Monitor | CVE-2022-46811No exploit | WordPress ALD Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 1.0.21 - Broken Access Control + CSRFvillatheme(villatheme.com) · ald – dropshipping and fulfillment for aliexpress and woocommerce · CWE-862 | Medium4.3 | — | 0.5% | Dec 13, 2024 |
17Monitor | CVE-2022-46807No exploit | WordPress Stock Sync for WooCommerce plugin <= 2.3.2 - Broken Access Controllauri karisola / wp trio · stock sync for woocommerce · CWE-862 | Medium4.3 | — | 0.5% | Dec 13, 2024 |
21Monitor | CVE-2023-30488No exploit | WordPress Featured Post Creative plugin <= 1.2.7 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · featured post creative · CWE-862 | Medium5.3 | — | 0.4% | Dec 9, 2024 |
21Monitor | CVE-2023-25703No exploit | WordPress Meta slider and carousel with lightbox plugin <= 1.6.2 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · meta slider and carousel with lightbox · CWE-862 | Medium5.3 | — | 0.5% | Dec 9, 2024 |
21Monitor | CVE-2023-25060No exploit | WordPress Album and Image Gallery plus Lightbox plugin <= 1.6.2 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · album and image gallery plus lightbox · CWE-862 | Medium5.3 | — | 0.6% | Dec 9, 2024 |
21Monitor | CVE-2023-23868No exploit | WordPress Cost of Goods for WooCommerce plugin <= 2.8.6 - Broken Access Control vulnerabilitywpfactory · cost of goods for woocommerce · CWE-862 | Medium5.4 | — | 0.6% | Dec 9, 2024 |
35Monitor | CVE-2022-47181No exploit | WordPress Email Templates Plugin <= 1.4.2 is vulnerable to Cross Site Request Forgery (CSRF)wpexperts · email templates customizer and designer · CWE-352 | High8.8 | — | 0.3% | Nov 7, 2023 |
21Monitor | CVE-2022-45821No exploit | WordPress NOO Timetable Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)nootheme · noo timetable · CWE-79 | Medium5.4 | — | 0.4% | Aug 8, 2023 |
19Monitor | CVE-2022-47421No exploit | WordPress ARMember (free) and ARMember (premium) plugins - vulnerable to Auth. Stored Cross Site Scripting (XSS)armemberplugin · armember · CWE-79 | Medium4.8 | — | 0.4% | Jul 18, 2023 |
35Monitor | CVE-2022-46857No exploit | WordPress SiteAlert (Formerly WP Health) Plugin <= 1.9.7 is vulnerable to Cross Site Request Forgery (CSRF)sitealert · sitealert · CWE-352 | High8.8 | — | 0.3% | Jul 18, 2023 |
35Monitor | CVE-2022-45828No exploit | WordPress NOO Timetable Plugin <= 2.1.3 is vulnerable to Cross Site Request Forgery (CSRF)nootheme · noo timetable · CWE-352 | High8.8 | — | 0.3% | Jul 18, 2023 |
35Monitor | CVE-2022-45823No exploit | WordPress Video Contest WordPress Plugin Plugin <= 3.2 is vulnerable to Cross Site Request Forgery (CSRF)video contest wordpress project · video contest wordpress · CWE-352 | High8.8 | — | 0.3% | Jul 11, 2023 |
19Monitor | CVE-2022-45827No exploit | WordPress Video Contest WordPress Plugin Plugin <= 3.2 is vulnerable to Cross Site Scripting (XSS)galleryplugins · video contest · CWE-79 | Medium4.8 | — | 0.4% | Jun 12, 2023 |
35Monitor | CVE-2022-47144No exploit | WordPress Mediamatic – Media Library Folders Plugin <= 2.8.1 is vulnerable to Cross Site Request Forgery (CSRF)frenify · mediamatic · CWE-352 | High8.8 | — | 0.2% | May 25, 2023 |
35Monitor | CVE-2022-46856No exploit | WordPress Woocommerce Product Designer Plugin <= 4.3.3 is vulnerable to Cross Site Request Forgery (CSRF)orion · woocommerce products designer · CWE-352 | High8.8 | — | 0.3% | May 25, 2023 |
35Monitor | CVE-2022-46810No exploit | WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF)villatheme · woocommerce thank you page customizer · CWE-352 | High8.8 | — | 0.2% | May 25, 2023 |
35Monitor | CVE-2022-47177No exploit | WordPress WP EasyPay Plugin <= 4.1 is vulnerable to Cross Site Request Forgery (CSRF)wpeasypay · wp easypay · CWE-352 | High8.8 | — | 0.3% | May 25, 2023 |
- CVE-2022-4760121Monitor
WordPress WP Table Manager plugin <= 3.5.2 - Broken Access Control
MediumCVSS 5.3No exploitEPSS 0%joomunited · wp table managerJan 2, 2025
- CVE-2023-3999417Monitor
WordPress ARMember Premium plugin <= 5.9.2 - Broken Access Control
MediumCVSS 4.3No exploitEPSS 0%reputeinfosystems · armemberJan 2, 2025
- CVE-2023-3999621Monitor
WordPress Accordion and Accordion Slider plugin <= 1.2.4 - Broken Access Control
MediumCVSS 5.3No exploitEPSS 1%wp onlinesupport, essential plugin · accordion and accordion sliderDec 13, 2024
- CVE-2023-3999517Monitor
WordPress Portfolio and Projects plugin <= 1.3.7 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%wp onlinesupport, essential plugin · portfolio and projectsDec 13, 2024
- CVE-2023-3651921Monitor
WordPress SW Product Bundles plugin <= 2.0.15 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 1%wpthemego · sw product bundlesDec 13, 2024
- CVE-2023-3651817Monitor
WordPress Post Hit Counter plugin <= 1.3.2 - Broken Access Control
MediumCVSS 4.3No exploitEPSS 0%hugh lashbrooke · post hit counterDec 13, 2024
- CVE-2022-4718221Monitor
WordPress APIExperts Square for WooCommerce plugin <= 4.4.1 - Broken Access Control
MediumCVSS 5.3No exploitEPSS 1%wpexpertsio · apiexperts square for woocommerceDec 13, 2024
- CVE-2022-4684621Monitor
WordPress Trending/Popular Post Slider and Widget plugin <= 1.5.7 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 1%wp onlinesupport, essential plugin · trending/popular post slider and widgetDec 13, 2024
- CVE-2022-4681117Monitor
WordPress ALD Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 1.0.21 - Broken Access Control + CSRF
MediumCVSS 4.3No exploitEPSS 1%villatheme(villatheme.com) · ald – dropshipping and fulfillment for aliexpress and woocommerceDec 13, 2024
- CVE-2022-4680717Monitor
WordPress Stock Sync for WooCommerce plugin <= 2.3.2 - Broken Access Control
MediumCVSS 4.3No exploitEPSS 1%lauri karisola / wp trio · stock sync for woocommerceDec 13, 2024
- CVE-2023-3048821Monitor
WordPress Featured Post Creative plugin <= 1.2.7 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%wp onlinesupport, essential plugin · featured post creativeDec 9, 2024
- CVE-2023-2570321Monitor
WordPress Meta slider and carousel with lightbox plugin <= 1.6.2 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 1%wp onlinesupport, essential plugin · meta slider and carousel with lightboxDec 9, 2024
- CVE-2023-2506021Monitor
WordPress Album and Image Gallery plus Lightbox plugin <= 1.6.2 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 1%wp onlinesupport, essential plugin · album and image gallery plus lightboxDec 9, 2024
- CVE-2023-2386821Monitor
WordPress Cost of Goods for WooCommerce plugin <= 2.8.6 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 1%wpfactory · cost of goods for woocommerceDec 9, 2024
- CVE-2022-4718135Monitor
WordPress Email Templates Plugin <= 1.4.2 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wpexperts · email templates customizer and designerNov 7, 2023
- CVE-2022-4582121Monitor
WordPress NOO Timetable Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%nootheme · noo timetableAug 8, 2023
- CVE-2022-4742119Monitor
WordPress ARMember (free) and ARMember (premium) plugins - vulnerable to Auth. Stored Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%armemberplugin · armemberJul 18, 2023
- CVE-2022-4685735Monitor
WordPress SiteAlert (Formerly WP Health) Plugin <= 1.9.7 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%sitealert · sitealertJul 18, 2023
- CVE-2022-4582835Monitor
WordPress NOO Timetable Plugin <= 2.1.3 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%nootheme · noo timetableJul 18, 2023
- CVE-2022-4582335Monitor
WordPress Video Contest WordPress Plugin Plugin <= 3.2 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%video contest wordpress project · video contest wordpressJul 11, 2023
- CVE-2022-4582719Monitor
WordPress Video Contest WordPress Plugin Plugin <= 3.2 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%galleryplugins · video contestJun 12, 2023
- CVE-2022-4714435Monitor
WordPress Mediamatic – Media Library Folders Plugin <= 2.8.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%frenify · mediamaticMay 25, 2023
- CVE-2022-4685635Monitor
WordPress Woocommerce Product Designer Plugin <= 4.3.3 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%orion · woocommerce products designerMay 25, 2023
- CVE-2022-4681035Monitor
WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%villatheme · woocommerce thank you page customizerMay 25, 2023
- CVE-2022-4717735Monitor
WordPress WP EasyPay Plugin <= 4.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wpeasypay · wp easypayMay 25, 2023