Skip to content
Noroxi

Cat (Patchstack Alliance)

39 credited records · 0 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • WordPress WP Table Manager plugin <= 3.5.2 - Broken Access Control

    MediumCVSS 5.3No exploitEPSS 0%

    joomunited · wp table managerJan 2, 2025

  • WordPress ARMember Premium plugin <= 5.9.2 - Broken Access Control

    MediumCVSS 4.3No exploitEPSS 0%

    reputeinfosystems · armemberJan 2, 2025

  • WordPress Accordion and Accordion Slider plugin <= 1.2.4 - Broken Access Control

    MediumCVSS 5.3No exploitEPSS 1%

    wp onlinesupport, essential plugin · accordion and accordion sliderDec 13, 2024

  • WordPress Portfolio and Projects plugin <= 1.3.7 - Broken Access Control vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    wp onlinesupport, essential plugin · portfolio and projectsDec 13, 2024

  • WordPress SW Product Bundles plugin <= 2.0.15 - Broken Access Control vulnerability

    MediumCVSS 5.4No exploitEPSS 1%

    wpthemego · sw product bundlesDec 13, 2024

  • WordPress Post Hit Counter plugin <= 1.3.2 - Broken Access Control

    MediumCVSS 4.3No exploitEPSS 0%

    hugh lashbrooke · post hit counterDec 13, 2024

  • WordPress APIExperts Square for WooCommerce plugin <= 4.4.1 - Broken Access Control

    MediumCVSS 5.3No exploitEPSS 1%

    wpexpertsio · apiexperts square for woocommerceDec 13, 2024

  • WordPress Trending/Popular Post Slider and Widget plugin <= 1.5.7 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 1%

    wp onlinesupport, essential plugin · trending/popular post slider and widgetDec 13, 2024

  • WordPress ALD Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 1.0.21 - Broken Access Control + CSRF

    MediumCVSS 4.3No exploitEPSS 1%

    villatheme(villatheme.com) · ald – dropshipping and fulfillment for aliexpress and woocommerceDec 13, 2024

  • WordPress Stock Sync for WooCommerce plugin <= 2.3.2 - Broken Access Control

    MediumCVSS 4.3No exploitEPSS 1%

    lauri karisola / wp trio · stock sync for woocommerceDec 13, 2024

  • WordPress Featured Post Creative plugin <= 1.2.7 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    wp onlinesupport, essential plugin · featured post creativeDec 9, 2024

  • WordPress Meta slider and carousel with lightbox plugin <= 1.6.2 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 1%

    wp onlinesupport, essential plugin · meta slider and carousel with lightboxDec 9, 2024

  • WordPress Album and Image Gallery plus Lightbox plugin <= 1.6.2 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 1%

    wp onlinesupport, essential plugin · album and image gallery plus lightboxDec 9, 2024

  • WordPress Cost of Goods for WooCommerce plugin <= 2.8.6 - Broken Access Control vulnerability

    MediumCVSS 5.4No exploitEPSS 1%

    wpfactory · cost of goods for woocommerceDec 9, 2024

  • WordPress Email Templates Plugin <= 1.4.2 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wpexperts · email templates customizer and designerNov 7, 2023

  • WordPress NOO Timetable Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    nootheme · noo timetableAug 8, 2023

  • WordPress ARMember (free) and ARMember (premium) plugins - vulnerable to Auth. Stored Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    armemberplugin · armemberJul 18, 2023

  • WordPress SiteAlert (Formerly WP Health) Plugin <= 1.9.7 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    sitealert · sitealertJul 18, 2023

  • WordPress NOO Timetable Plugin <= 2.1.3 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    nootheme · noo timetableJul 18, 2023

  • WordPress Video Contest WordPress Plugin Plugin <= 3.2 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    video contest wordpress project · video contest wordpressJul 11, 2023

  • WordPress Video Contest WordPress Plugin Plugin <= 3.2 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    galleryplugins · video contestJun 12, 2023

  • WordPress Mediamatic – Media Library Folders Plugin <= 2.8.1 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    frenify · mediamaticMay 25, 2023

  • WordPress Woocommerce Product Designer Plugin <= 4.3.3 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    orion · woocommerce products designerMay 25, 2023

  • WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    villatheme · woocommerce thank you page customizerMay 25, 2023

  • WordPress WP EasyPay Plugin <= 4.1 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wpeasypay · wp easypayMay 25, 2023