Skip to content
Noroxi

Rafie Muhammad (Patchstack)

502 credited records · 0 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • WordPress Houzez Theme <= 4.1.1 - Cross Site Scripting (XSS) Vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    favethemes · houzezAug 28, 2025

  • WordPress Houzez Theme < 4.1.4 - Local File Inclusion Vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    favethemes · houzezAug 28, 2025

  • WordPress Houzez Theme <= 4.1.1 - Broken Access Control Vulnerability

    HighCVSS 8.5No exploitEPSS 0%

    favethemes · houzezAug 20, 2025

  • WordPress The Plus Addons for Elementor - Pro Plugin < 6.3.7 - Broken Access Control vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    posimyth innovation · the plus addons for elementor proJul 1, 2025

  • WordPress Photography theme <= 7.5.2 - PHP Object Injection vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    themegoods · photographyJun 6, 2025

  • WordPress Element Pack Pro Plugin < 8.0.0 - Broken Access Control vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    bdthemes · element pack proJun 5, 2025

  • WordPress Element Pack Pro Plugin < 8.0.0 - Cross Site Request Forgery (CSRF) vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    bdthemes · element pack proJun 5, 2025

  • WordPress Jetpack Debug Tools plugin < 2.0.1 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    automattic · jetpack debug toolsMay 15, 2025

  • WordPress Brizy Pro plugin <= 2.6.1 - Cross Site Request Forgery (CSRF) vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    brizy · brizyApr 9, 2025

  • WordPress Brizy Pro plugin <= 2.6.1 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    brizy · brizyApr 9, 2025

  • WordPress PrivateContent plugin <= 8.11.5 - Reflected Cross Site Scripting (XSS) vulnerability

    HighCVSS 7.1No exploitEPSS 0%

    notfound · privatecontentMar 15, 2025

  • WordPress PrivateContent plugin <= 8.11.5 - Subscriber+ Site Wide Broken Access Control vulnerability

    HighCVSS 8.3No exploitEPSS 0%

    aldo latino · privatecontentMar 15, 2025

  • WordPress Admin and Site Enhancements (ASE) Pro Plugin <= 7.6.2.1 - Privilege Escalation vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    notfound · admin and site enhancements (ase) proFeb 3, 2025

  • WordPress Admin and Site Enhancements (ASE) Pro Plugin <= 7.6.1.1 - Broken Access Control vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    notfound · admin and site enhancements (ase) proJan 27, 2025

  • WordPress Brizy Pro Plugin <= 2.6.1 - Reflected Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    brizy · brizyJan 21, 2025

  • WordPress Envato Elements plugin <= 2.0.14 - Server Side Request Forgery (SSRF) vulnerability

    MediumCVSS 4.1No exploitEPSS 0%

    envato · envato elementsJan 7, 2025

  • WordPress WP Job Manager Resume Manager plugin <= 2.1.0 - Cross Site Request Forgery (CSRF) vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    automattic · wp job manager - resume managerJan 2, 2025

  • WordPress Woo Subscriptions plugin < 5.8.0 - Broken Access Control vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    woo · woocommerce subscriptionsDec 31, 2024

  • WordPress Advanced Custom Fields Pro plugin < 6.3.2 - Cross-Site Request Forgery (CSRF) vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    wpengine, inc. · advanced custom fields proDec 16, 2024

  • WordPress Jupiter X Core plugin <= 3.3.0 - Multiple Auth. Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    artbees · jupiter x coreDec 13, 2024

  • WordPress Newspack plugin < 3.8.7 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    automattic · newspackNov 1, 2024

  • WordPress Envira Gallery Lite plugin <= 1.8.14 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    enviragallery · envira galleryNov 1, 2024

  • WordPress Yet Another Related Posts Plugin (YARPP) plugin <= 5.30.10 - Broken Access Control vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 45%

    yarpp · yet another related posts pluginNov 1, 2024

  • WordPress Fonts plugin <= 3.7.7 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    fontsplugin · fontsNov 1, 2024

  • WordPress Presto Player plugin <= 3.0.2 - Broken Access Control vulnerability

    MediumCVSS 6.3No exploitEPSS 0%

    presto made, inc · presto playerNov 1, 2024