Rafie Muhammad (Patchstack)
502 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2025-49407No exploit | WordPress Houzez Theme <= 4.1.1 - Cross Site Scripting (XSS) Vulnerabilityfavethemes · houzez · CWE-79 | High8.8 | — | 0.4% | Aug 28, 2025 |
17Monitor | CVE-2025-49405No exploit | WordPress Houzez Theme < 4.1.4 - Local File Inclusion Vulnerabilityfavethemes · houzez · CWE-98 | Medium4.3 | — | 0.3% | Aug 28, 2025 |
34Monitor | CVE-2025-49406No exploit | WordPress Houzez Theme <= 4.1.1 - Broken Access Control Vulnerabilityfavethemes · houzez · CWE-862 | High8.5 | — | 0.3% | Aug 20, 2025 |
21Monitor | CVE-2025-46259No exploit | WordPress The Plus Addons for Elementor - Pro Plugin < 6.3.7 - Broken Access Control vulnerabilityposimyth innovation · the plus addons for elementor pro · CWE-862 | Medium5.4 | — | 0.3% | Jul 1, 2025 |
30Monitor | CVE-2025-47584No exploit | WordPress Photography theme <= 7.5.2 - PHP Object Injection vulnerabilitythemegoods · photography · CWE-502 | High7.5 | — | 0.4% | Jun 6, 2025 |
21Monitor | CVE-2025-46258No exploit | WordPress Element Pack Pro Plugin < 8.0.0 - Broken Access Control vulnerabilitybdthemes · element pack pro · CWE-862 | Medium5.4 | — | 0.2% | Jun 5, 2025 |
17Monitor | CVE-2025-46257No exploit | WordPress Element Pack Pro Plugin < 8.0.0 - Cross Site Request Forgery (CSRF) vulnerabilitybdthemes · element pack pro · CWE-352 | Medium4.3 | — | 0.1% | Jun 5, 2025 |
21Monitor | CVE-2024-56006No exploit | WordPress Jetpack Debug Tools plugin < 2.0.1 - Broken Access Control vulnerabilityautomattic · jetpack debug tools · CWE-862 | Medium5.3 | — | 0.3% | May 15, 2025 |
35Monitor | CVE-2025-26902No exploit | WordPress Brizy Pro plugin <= 2.6.1 - Cross Site Request Forgery (CSRF) vulnerabilitybrizy · brizy · CWE-352 | High8.8 | — | 0.2% | Apr 9, 2025 |
35Monitor | CVE-2025-26901No exploit | WordPress Brizy Pro plugin <= 2.6.1 - Broken Access Control vulnerabilitybrizy · brizy · CWE-862 | High8.8 | — | 0.3% | Apr 9, 2025 |
28Monitor | CVE-2025-26972No exploit | WordPress PrivateContent plugin <= 8.11.5 - Reflected Cross Site Scripting (XSS) vulnerabilitynotfound · privatecontent · CWE-79 | High7.1 | — | 0.2% | Mar 15, 2025 |
33Monitor | CVE-2025-26969No exploit | WordPress PrivateContent plugin <= 8.11.5 - Subscriber+ Site Wide Broken Access Control vulnerabilityaldo latino · privatecontent · CWE-862 | High8.3 | — | 0.3% | Mar 15, 2025 |
30Monitor | CVE-2024-43333No exploit | WordPress Admin and Site Enhancements (ASE) Pro Plugin <= 7.6.2.1 - Privilege Escalation vulnerabilitynotfound · admin and site enhancements (ase) pro · CWE-266 | High7.5 | — | 0.4% | Feb 3, 2025 |
17Monitor | CVE-2025-24653No exploit | WordPress Admin and Site Enhancements (ASE) Pro Plugin <= 7.6.1.1 - Broken Access Control vulnerabilitynotfound · admin and site enhancements (ase) pro · CWE-862 | Medium4.3 | — | 0.2% | Jan 27, 2025 |
24Monitor | CVE-2025-22763No exploit | WordPress Brizy Pro Plugin <= 2.6.1 - Reflected Cross Site Scripting (XSS) vulnerabilitybrizy · brizy · CWE-79 | Medium6.1 | — | 0.2% | Jan 21, 2025 |
16Monitor | CVE-2024-56275No exploit | WordPress Envato Elements plugin <= 2.0.14 - Server Side Request Forgery (SSRF) vulnerabilityenvato · envato elements · CWE-918 | Medium4.1 | — | 0.4% | Jan 7, 2025 |
17Monitor | CVE-2024-37241No exploit | WordPress WP Job Manager Resume Manager plugin <= 2.1.0 - Cross Site Request Forgery (CSRF) vulnerabilityautomattic · wp job manager - resume manager · CWE-352 | Medium4.3 | — | 0.2% | Jan 2, 2025 |
17Monitor | CVE-2023-50850No exploit | WordPress Woo Subscriptions plugin < 5.8.0 - Broken Access Control vulnerabilitywoo · woocommerce subscriptions · CWE-862 | Medium4.3 | — | 0.4% | Dec 31, 2024 |
17Monitor | CVE-2024-37251No exploit | WordPress Advanced Custom Fields Pro plugin < 6.3.2 - Cross-Site Request Forgery (CSRF) vulnerabilitywpengine, inc. · advanced custom fields pro · CWE-352 | Medium4.3 | — | 0.2% | Dec 16, 2024 |
35Monitor | CVE-2023-38385No exploit | WordPress Jupiter X Core plugin <= 3.3.0 - Multiple Auth. Broken Access Control vulnerabilityartbees · jupiter x core · CWE-862 | High8.8 | — | 0.6% | Dec 13, 2024 |
35Monitor | CVE-2024-43968No exploit | WordPress Newspack plugin < 3.8.7 - Broken Access Control vulnerabilityautomattic · newspack · CWE-862 | High8.8 | — | 0.5% | Nov 1, 2024 |
35Monitor | CVE-2024-43925No exploit | WordPress Envira Gallery Lite plugin <= 1.8.14 - Broken Access Control vulnerabilityenviragallery · envira gallery · CWE-862 | High8.8 | — | 0.5% | Nov 1, 2024 |
52Plan | CVE-2024-43919Proof of concept | WordPress Yet Another Related Posts Plugin (YARPP) plugin <= 5.30.10 - Broken Access Control vulnerabilityyarpp · yet another related posts plugin · CWE-862 | Critical9.8 | — | 44.9% | Nov 1, 2024 |
35Monitor | CVE-2024-43302No exploit | WordPress Fonts plugin <= 3.7.7 - Broken Access Control vulnerabilityfontsplugin · fonts · CWE-862 | High8.8 | — | 0.4% | Nov 1, 2024 |
25Monitor | CVE-2024-43285No exploit | WordPress Presto Player plugin <= 3.0.2 - Broken Access Control vulnerabilitypresto made, inc · presto player · CWE-862 | Medium6.3 | — | 0.4% | Nov 1, 2024 |
- CVE-2025-4940735Monitor
WordPress Houzez Theme <= 4.1.1 - Cross Site Scripting (XSS) Vulnerability
HighCVSS 8.8No exploitEPSS 0%favethemes · houzezAug 28, 2025
- CVE-2025-4940517Monitor
WordPress Houzez Theme < 4.1.4 - Local File Inclusion Vulnerability
MediumCVSS 4.3No exploitEPSS 0%favethemes · houzezAug 28, 2025
- CVE-2025-4940634Monitor
WordPress Houzez Theme <= 4.1.1 - Broken Access Control Vulnerability
HighCVSS 8.5No exploitEPSS 0%favethemes · houzezAug 20, 2025
- CVE-2025-4625921Monitor
WordPress The Plus Addons for Elementor - Pro Plugin < 6.3.7 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 0%posimyth innovation · the plus addons for elementor proJul 1, 2025
- CVE-2025-4758430Monitor
WordPress Photography theme <= 7.5.2 - PHP Object Injection vulnerability
HighCVSS 7.5No exploitEPSS 0%themegoods · photographyJun 6, 2025
- CVE-2025-4625821Monitor
WordPress Element Pack Pro Plugin < 8.0.0 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 0%bdthemes · element pack proJun 5, 2025
- CVE-2025-4625717Monitor
WordPress Element Pack Pro Plugin < 8.0.0 - Cross Site Request Forgery (CSRF) vulnerability
MediumCVSS 4.3No exploitEPSS 0%bdthemes · element pack proJun 5, 2025
- CVE-2024-5600621Monitor
WordPress Jetpack Debug Tools plugin < 2.0.1 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%automattic · jetpack debug toolsMay 15, 2025
- CVE-2025-2690235Monitor
WordPress Brizy Pro plugin <= 2.6.1 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%brizy · brizyApr 9, 2025
- CVE-2025-2690135Monitor
WordPress Brizy Pro plugin <= 2.6.1 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%brizy · brizyApr 9, 2025
- CVE-2025-2697228Monitor
WordPress PrivateContent plugin <= 8.11.5 - Reflected Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%notfound · privatecontentMar 15, 2025
- CVE-2025-2696933Monitor
WordPress PrivateContent plugin <= 8.11.5 - Subscriber+ Site Wide Broken Access Control vulnerability
HighCVSS 8.3No exploitEPSS 0%aldo latino · privatecontentMar 15, 2025
- CVE-2024-4333330Monitor
WordPress Admin and Site Enhancements (ASE) Pro Plugin <= 7.6.2.1 - Privilege Escalation vulnerability
HighCVSS 7.5No exploitEPSS 0%notfound · admin and site enhancements (ase) proFeb 3, 2025
- CVE-2025-2465317Monitor
WordPress Admin and Site Enhancements (ASE) Pro Plugin <= 7.6.1.1 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%notfound · admin and site enhancements (ase) proJan 27, 2025
- CVE-2025-2276324Monitor
WordPress Brizy Pro Plugin <= 2.6.1 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%brizy · brizyJan 21, 2025
- CVE-2024-5627516Monitor
WordPress Envato Elements plugin <= 2.0.14 - Server Side Request Forgery (SSRF) vulnerability
MediumCVSS 4.1No exploitEPSS 0%envato · envato elementsJan 7, 2025
- CVE-2024-3724117Monitor
WordPress WP Job Manager Resume Manager plugin <= 2.1.0 - Cross Site Request Forgery (CSRF) vulnerability
MediumCVSS 4.3No exploitEPSS 0%automattic · wp job manager - resume managerJan 2, 2025
- CVE-2023-5085017Monitor
WordPress Woo Subscriptions plugin < 5.8.0 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%woo · woocommerce subscriptionsDec 31, 2024
- CVE-2024-3725117Monitor
WordPress Advanced Custom Fields Pro plugin < 6.3.2 - Cross-Site Request Forgery (CSRF) vulnerability
MediumCVSS 4.3No exploitEPSS 0%wpengine, inc. · advanced custom fields proDec 16, 2024
- CVE-2023-3838535Monitor
WordPress Jupiter X Core plugin <= 3.3.0 - Multiple Auth. Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 1%artbees · jupiter x coreDec 13, 2024
- CVE-2024-4396835Monitor
WordPress Newspack plugin < 3.8.7 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%automattic · newspackNov 1, 2024
- CVE-2024-4392535Monitor
WordPress Envira Gallery Lite plugin <= 1.8.14 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 1%enviragallery · envira galleryNov 1, 2024
- CVE-2024-4391952Plan
WordPress Yet Another Related Posts Plugin (YARPP) plugin <= 5.30.10 - Broken Access Control vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 45%yarpp · yet another related posts pluginNov 1, 2024
- CVE-2024-4330235Monitor
WordPress Fonts plugin <= 3.7.7 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%fontsplugin · fontsNov 1, 2024
- CVE-2024-4328525Monitor
WordPress Presto Player plugin <= 3.0.2 - Broken Access Control vulnerability
MediumCVSS 6.3No exploitEPSS 0%presto made, inc · presto playerNov 1, 2024