Skip to content
Noroxi

Elliot (Patchstack Alliance)

26 credited records · 0 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • WordPress Animator plugin <= 3.0.10 - Unauthenticated Plugin Settings Change Vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    toast plugins · animatorJan 2, 2025

  • WordPress BadgeOS plugin <= 3.7.1.6 - Broken Access Control vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    learningtimes · badgeosJan 2, 2025

  • WordPress WP Crowdfunding plugin <= 2.1.5 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    themeum · wp crowdfundingDec 13, 2024

  • WordPress Posts Like Dislike plugin <= 1.1.0 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    wp happy coders · posts like dislikeDec 13, 2024

  • WordPress Button Generator – easily Button Builder plugin <= 2.3.8 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 1%

    wow-company · button generator – easily button builderDec 9, 2024

  • WordPress LuckyWP Scripts Control plugin <= 1.2.1 - Broken Access Control vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    luckywp · luckywp scripts controlDec 9, 2024

  • WordPress Load More Anything plugin <= 3.3.3 - Broken Access Control vulnerability

    MediumCVSS 6.3No exploitEPSS 0%

    addonmaster · load more anythingJun 11, 2024

  • CVE-2024-2906
    26Monitor

    WordPress Radio Player plugin <= 2.0.73 - Unauthenticated Broken Access Control vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    softlab · radio playerMar 26, 2024

  • WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    cleantalk · anti-spamFeb 29, 2024

  • WordPress Droit Elementor Addons Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    droitthemes · droit elementor addonsJan 31, 2024

  • WordPress Editorial Calendar Plugin <= 3.7.12 is vulnerable to Insecure Direct Object References (IDOR)

    HighCVSS 8.1No exploitEPSS 0%

    zackgrossbart · editorial calendarDec 20, 2023

  • WordPress Button Generator – easily Button Builder Plugin <= 2.3.8 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wow-company · button generatorDec 18, 2023

  • WordPress Quantity Plus Minus Button for WooCommerce by CodeAstrology Plugin <= 1.1.9 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    codeastrology · quantity plus minus button for woocommerceDec 18, 2023

  • WordPress Droit Dark Mode Plugin <= 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    droitthemes · droit dark modeNov 18, 2023

  • WordPress ShiftController Employee Shift Scheduling Plugin <= 4.9.23 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    plainware · shiftcontrollerNov 12, 2023

  • WordPress WP Full Auto Tags Manager Plugin <= 2.2 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    guillemantdavid · full auto tags managerNov 9, 2023

  • WordPress Duplicate Theme Plugin <= 0.1.6 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    mullerdigital · duplicate themeOct 25, 2023

  • WordPress Video Player Plugin <= 1.5.22 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    web-dorado · spidervplayerOct 18, 2023

  • WordPress Tweeple Plugin <= 0.9.5 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    themeblvd · tweepleOct 18, 2023

  • WordPress Maintenance Switch Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    fugu · maintenance switchOct 6, 2023

  • WordPress Simple Org Chart Plugin <= 2.3.4 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    webtechforce · simple org chartOct 6, 2023

  • WordPress Simple Org Chart Plugin <= 2.3.4 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    webtechforce · simple org chartOct 6, 2023

  • WordPress POEditor Plugin <= 0.9.4 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    poeditor · poeditorOct 3, 2023

  • WordPress Five Star Restaurant Menu Plugin <= 2.4.6 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    fivestarplugins · five star restaurant menuJul 17, 2023

  • WordPress WP Dummy Content Generator Plugin <= 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wp dummy content generator project · wp dummy content generatorJul 10, 2023