Elliot (Patchstack Alliance)
26 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2023-47689No exploit | WordPress Animator plugin <= 3.0.10 - Unauthenticated Plugin Settings Change Vulnerabilitytoast plugins · animator · CWE-862 | Medium6.5 | — | 0.4% | Jan 2, 2025 |
17Monitor | CVE-2023-47647No exploit | WordPress BadgeOS plugin <= 3.7.1.6 - Broken Access Control vulnerabilitylearningtimes · badgeos · CWE-862 | Medium4.3 | — | 0.4% | Jan 2, 2025 |
35Monitor | CVE-2023-41870No exploit | WordPress WP Crowdfunding plugin <= 2.1.5 - Broken Access Control vulnerabilitythemeum · wp crowdfunding · CWE-862 | High8.8 | — | 0.8% | Dec 13, 2024 |
21Monitor | CVE-2023-41849No exploit | WordPress Posts Like Dislike plugin <= 1.1.0 - Broken Access Control vulnerabilitywp happy coders · posts like dislike · CWE-862 | Medium5.3 | — | 0.5% | Dec 13, 2024 |
21Monitor | CVE-2023-49154No exploit | WordPress Button Generator – easily Button Builder plugin <= 2.3.8 - Broken Access Control vulnerabilitywow-company · button generator – easily button builder · CWE-862 | Medium5.3 | — | 0.6% | Dec 9, 2024 |
21Monitor | CVE-2023-29239No exploit | WordPress LuckyWP Scripts Control plugin <= 1.2.1 - Broken Access Control vulnerabilityluckywp · luckywp scripts control · CWE-862 | Medium5.4 | — | 0.4% | Dec 9, 2024 |
25Monitor | CVE-2024-24704No exploit | WordPress Load More Anything plugin <= 3.3.3 - Broken Access Control vulnerabilityaddonmaster · load more anything · CWE-862 | Medium6.3 | — | 0.3% | Jun 11, 2024 |
26Monitor | CVE-2024-2906No exploit | WordPress Radio Player plugin <= 2.0.73 - Unauthenticated Broken Access Control vulnerabilitysoftlab · radio player · CWE-862 | Medium6.5 | — | 0.5% | Mar 26, 2024 |
35Monitor | CVE-2023-51696No exploit | WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF)cleantalk · anti-spam · CWE-352 | High8.8 | — | 0.2% | Feb 29, 2024 |
35Monitor | CVE-2024-22136No exploit | WordPress Droit Elementor Addons Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF)droitthemes · droit elementor addons · CWE-352 | High8.8 | — | 0.2% | Jan 31, 2024 |
32Monitor | CVE-2023-36520No exploit | WordPress Editorial Calendar Plugin <= 3.7.12 is vulnerable to Insecure Direct Object References (IDOR)zackgrossbart · editorial calendar · CWE-639 | High8.1 | — | 0.4% | Dec 20, 2023 |
35Monitor | CVE-2023-49155No exploit | WordPress Button Generator – easily Button Builder Plugin <= 2.3.8 is vulnerable to Cross Site Request Forgery (CSRF)wow-company · button generator · CWE-352 | High8.8 | — | 0.3% | Dec 18, 2023 |
35Monitor | CVE-2023-48768No exploit | WordPress Quantity Plus Minus Button for WooCommerce by CodeAstrology Plugin <= 1.1.9 is vulnerable to Cross Site Request Forgery (CSRF)codeastrology · quantity plus minus button for woocommerce · CWE-352 | High8.8 | — | 0.3% | Dec 18, 2023 |
35Monitor | CVE-2023-47531No exploit | WordPress Droit Dark Mode Plugin <= 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF)droitthemes · droit dark mode · CWE-352 | High8.8 | — | 0.3% | Nov 18, 2023 |
35Monitor | CVE-2023-29425No exploit | WordPress ShiftController Employee Shift Scheduling Plugin <= 4.9.23 is vulnerable to Cross Site Request Forgery (CSRF)plainware · shiftcontroller · CWE-352 | High8.8 | — | 0.3% | Nov 12, 2023 |
35Monitor | CVE-2023-34024No exploit | WordPress WP Full Auto Tags Manager Plugin <= 2.2 is vulnerable to Cross Site Request Forgery (CSRF)guillemantdavid · full auto tags manager · CWE-352 | High8.8 | — | 0.3% | Nov 9, 2023 |
35Monitor | CVE-2023-46204No exploit | WordPress Duplicate Theme Plugin <= 0.1.6 is vulnerable to Cross Site Request Forgery (CSRF)mullerdigital · duplicate theme · CWE-352 | High8.8 | — | 0.3% | Oct 25, 2023 |
24Monitor | CVE-2023-45632No exploit | WordPress Video Player Plugin <= 1.5.22 is vulnerable to Cross Site Scripting (XSS)web-dorado · spidervplayer · CWE-79 | Medium6.1 | — | 0.3% | Oct 18, 2023 |
24Monitor | CVE-2023-30781No exploit | WordPress Tweeple Plugin <= 0.9.5 is vulnerable to Cross Site Scripting (XSS)themeblvd · tweeple · CWE-79 | Medium6.1 | — | 0.3% | Oct 18, 2023 |
35Monitor | CVE-2023-29235No exploit | WordPress Maintenance Switch Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF)fugu · maintenance switch · CWE-352 | High8.8 | — | 0.2% | Oct 6, 2023 |
35Monitor | CVE-2023-28791No exploit | WordPress Simple Org Chart Plugin <= 2.3.4 is vulnerable to Cross Site Request Forgery (CSRF)webtechforce · simple org chart · CWE-352 | High8.8 | — | 0.3% | Oct 6, 2023 |
35Monitor | CVE-2023-40008No exploit | WordPress Simple Org Chart Plugin <= 2.3.4 is vulnerable to Cross Site Request Forgery (CSRF)webtechforce · simple org chart · CWE-352 | High8.8 | — | 0.2% | Oct 6, 2023 |
35Monitor | CVE-2023-32091No exploit | WordPress POEditor Plugin <= 0.9.4 is vulnerable to Cross Site Request Forgery (CSRF)poeditor · poeditor · CWE-352 | High8.8 | — | 0.2% | Oct 3, 2023 |
35Monitor | CVE-2023-37985No exploit | WordPress Five Star Restaurant Menu Plugin <= 2.4.6 is vulnerable to Cross Site Request Forgery (CSRF)fivestarplugins · five star restaurant menu · CWE-352 | High8.8 | — | 0.3% | Jul 17, 2023 |
35Monitor | CVE-2023-37392No exploit | WordPress WP Dummy Content Generator Plugin <= 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)wp dummy content generator project · wp dummy content generator · CWE-352 | High8.8 | — | 0.3% | Jul 10, 2023 |
- CVE-2023-4768926Monitor
WordPress Animator plugin <= 3.0.10 - Unauthenticated Plugin Settings Change Vulnerability
MediumCVSS 6.5No exploitEPSS 0%toast plugins · animatorJan 2, 2025
- CVE-2023-4764717Monitor
WordPress BadgeOS plugin <= 3.7.1.6 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%learningtimes · badgeosJan 2, 2025
- CVE-2023-4187035Monitor
WordPress WP Crowdfunding plugin <= 2.1.5 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 1%themeum · wp crowdfundingDec 13, 2024
- CVE-2023-4184921Monitor
WordPress Posts Like Dislike plugin <= 1.1.0 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%wp happy coders · posts like dislikeDec 13, 2024
- CVE-2023-4915421Monitor
WordPress Button Generator – easily Button Builder plugin <= 2.3.8 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 1%wow-company · button generator – easily button builderDec 9, 2024
- CVE-2023-2923921Monitor
WordPress LuckyWP Scripts Control plugin <= 1.2.1 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 0%luckywp · luckywp scripts controlDec 9, 2024
- CVE-2024-2470425Monitor
WordPress Load More Anything plugin <= 3.3.3 - Broken Access Control vulnerability
MediumCVSS 6.3No exploitEPSS 0%addonmaster · load more anythingJun 11, 2024
- CVE-2024-290626Monitor
WordPress Radio Player plugin <= 2.0.73 - Unauthenticated Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%softlab · radio playerMar 26, 2024
- CVE-2023-5169635Monitor
WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%cleantalk · anti-spamFeb 29, 2024
- CVE-2024-2213635Monitor
WordPress Droit Elementor Addons Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%droitthemes · droit elementor addonsJan 31, 2024
- CVE-2023-3652032Monitor
WordPress Editorial Calendar Plugin <= 3.7.12 is vulnerable to Insecure Direct Object References (IDOR)
HighCVSS 8.1No exploitEPSS 0%zackgrossbart · editorial calendarDec 20, 2023
- CVE-2023-4915535Monitor
WordPress Button Generator – easily Button Builder Plugin <= 2.3.8 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wow-company · button generatorDec 18, 2023
- CVE-2023-4876835Monitor
WordPress Quantity Plus Minus Button for WooCommerce by CodeAstrology Plugin <= 1.1.9 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%codeastrology · quantity plus minus button for woocommerceDec 18, 2023
- CVE-2023-4753135Monitor
WordPress Droit Dark Mode Plugin <= 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%droitthemes · droit dark modeNov 18, 2023
- CVE-2023-2942535Monitor
WordPress ShiftController Employee Shift Scheduling Plugin <= 4.9.23 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%plainware · shiftcontrollerNov 12, 2023
- CVE-2023-3402435Monitor
WordPress WP Full Auto Tags Manager Plugin <= 2.2 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%guillemantdavid · full auto tags managerNov 9, 2023
- CVE-2023-4620435Monitor
WordPress Duplicate Theme Plugin <= 0.1.6 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%mullerdigital · duplicate themeOct 25, 2023
- CVE-2023-4563224Monitor
WordPress Video Player Plugin <= 1.5.22 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%web-dorado · spidervplayerOct 18, 2023
- CVE-2023-3078124Monitor
WordPress Tweeple Plugin <= 0.9.5 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%themeblvd · tweepleOct 18, 2023
- CVE-2023-2923535Monitor
WordPress Maintenance Switch Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%fugu · maintenance switchOct 6, 2023
- CVE-2023-2879135Monitor
WordPress Simple Org Chart Plugin <= 2.3.4 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%webtechforce · simple org chartOct 6, 2023
- CVE-2023-4000835Monitor
WordPress Simple Org Chart Plugin <= 2.3.4 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%webtechforce · simple org chartOct 6, 2023
- CVE-2023-3209135Monitor
WordPress POEditor Plugin <= 0.9.4 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%poeditor · poeditorOct 3, 2023
- CVE-2023-3798535Monitor
WordPress Five Star Restaurant Menu Plugin <= 2.4.6 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%fivestarplugins · five star restaurant menuJul 17, 2023
- CVE-2023-3739235Monitor
WordPress WP Dummy Content Generator Plugin <= 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wp dummy content generator project · wp dummy content generatorJul 10, 2023