Friday (Patchstack Alliance)
8 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2023-37989No exploit | WordPress Easyship WooCommerce Shipping Rates plugin <= 0.9.0 - Broken Access Control vulnerabilityeasyship · easyship woocommerce shipping rates · CWE-862 | Medium5.4 | — | 0.5% | Dec 13, 2024 |
21Monitor | CVE-2023-29173No exploit | WordPress Product Category Tree plugin <= 2.5 - Broken Access Control vulnerabilityawesome togi · product category tree · CWE-862 | Medium5.3 | — | 0.4% | Dec 9, 2024 |
35Monitor | CVE-2024-30484No exploit | WordPress RT Easy Builder plugin <= 2.0 - Broken Access Control vulnerabilityrisethemes · rt easy builder · CWE-862 | High8.8 | — | 0.3% | Jun 4, 2024 |
17Monitor | CVE-2024-32689No exploit | WordPress WP Social Comments plugin <= 1.7.3 - Broken Access Control vulnerabilitygenialsouls · wp social comments · CWE-862 | Medium4.3 | — | 0.3% | Apr 18, 2024 |
21Monitor | CVE-2024-32515No exploit | WordPress Mega Addons For Elementor plugin <= 1.8 - Broken Access Control vulnerabilityqamar sheeraz, nasir ahmad · mega addons for elementor · CWE-862 | Medium5.4 | — | 0.4% | Apr 17, 2024 |
14Monitor | CVE-2024-31265No exploit | WordPress Sumo plugin <= 1.34 - Cross Site Request Forgery (CSRF) vulnerabilitysumome · sumo · CWE-352 | Low3.7 | — | 0.2% | Apr 12, 2024 |
35Monitor | CVE-2023-52214No exploit | WordPress Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.3 - Broken Access Control vulnerabilityvoidcoders · void contact form 7 widget for elementor page builder · CWE-862 | High8.8 | — | 0.4% | Mar 26, 2024 |
17Monitor | CVE-2024-24837No exploit | Cross-Site Request Forgery (CSRF) vulnerability in FG PrestaShop, FG Drupal and FG Joomla WordPress pluginsfrédéric gilles · fg prestashop to woocommerce · CWE-352 | Medium4.3 | — | 0.3% | Feb 21, 2024 |
- CVE-2023-3798921Monitor
WordPress Easyship WooCommerce Shipping Rates plugin <= 0.9.0 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 1%easyship · easyship woocommerce shipping ratesDec 13, 2024
- CVE-2023-2917321Monitor
WordPress Product Category Tree plugin <= 2.5 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%awesome togi · product category treeDec 9, 2024
- CVE-2024-3048435Monitor
WordPress RT Easy Builder plugin <= 2.0 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%risethemes · rt easy builderJun 4, 2024
- CVE-2024-3268917Monitor
WordPress WP Social Comments plugin <= 1.7.3 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%genialsouls · wp social commentsApr 18, 2024
- CVE-2024-3251521Monitor
WordPress Mega Addons For Elementor plugin <= 1.8 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 0%qamar sheeraz, nasir ahmad · mega addons for elementorApr 17, 2024
- CVE-2024-3126514Monitor
WordPress Sumo plugin <= 1.34 - Cross Site Request Forgery (CSRF) vulnerability
LowCVSS 3.7No exploitEPSS 0%sumome · sumoApr 12, 2024
- CVE-2023-5221435Monitor
WordPress Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.3 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%voidcoders · void contact form 7 widget for elementor page builderMar 26, 2024
- CVE-2024-2483717Monitor
Cross-Site Request Forgery (CSRF) vulnerability in FG PrestaShop, FG Drupal and FG Joomla WordPress plugins
MediumCVSS 4.3No exploitEPSS 0%frédéric gilles · fg prestashop to woocommerceFeb 21, 2024