rezaduty (Patchstack Alliance)
25 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2022-47429No exploit | WordPress Coming Soon Landing Page and Maintenance Mode WordPress Plugin plugin <= 2.2.0 - Broken Access Control8degree themes · coming soon landing page and maintenance mode wordpress plugin · CWE-862 | Medium5.3 | — | 0.5% | Dec 13, 2024 |
28Monitor | CVE-2022-47599No exploit | WordPress File Manager Plugin <= 5.2.7 is vulnerable to PHP Object Injectionbitapps · file manager · CWE-502 | High7.2 | — | 0.5% | Dec 20, 2023 |
30Monitor | CVE-2022-47597No exploit | WordPress Popup Maker Plugin <= 1.17.1 is vulnerable to Sensitive Data Exposurecode-atlantic · popup maker · CWE-200 | High7.5 | — | 0.6% | Dec 20, 2023 |
35Monitor | CVE-2022-47159No exploit | WordPress Logaster Logo Generator Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF)logaster · logo generator · CWE-352 | High8.8 | — | 0.3% | May 25, 2023 |
35Monitor | CVE-2022-47139No exploit | WordPress WP Basic Elements Plugin <= 5.2.15 is vulnerable to Cross Site Request Forgery (CSRF)wp basic elements project · wp basic elements · CWE-352 | High8.8 | — | 0.3% | May 25, 2023 |
35Monitor | CVE-2022-47138No exploit | WordPress LOGIN AND REGISTRATION ATTEMPTS LIMIT Plugin <= 2.1 is vulnerable to Cross Site Request Forgery (CSRF)login and registration attempts limit project · login and registration attempts limit · CWE-352 | High8.8 | — | 0.3% | May 25, 2023 |
35Monitor | CVE-2022-47135No exploit | WordPress Chronoforms Plugin <= 7.0.9 is vulnerable to Cross Site Request Forgery (CSRF)chronoengine · chronoforms · CWE-352 | High8.8 | — | 0.3% | May 25, 2023 |
35Monitor | CVE-2022-47448No exploit | WordPress xili-tidy-tags Plugin <= 1.12.03 is vulnerable to Cross Site Request Forgery (CSRF)xiligroup · xili-tidy-tags · CWE-352 | High8.8 | — | 0.3% | May 24, 2023 |
35Monitor | CVE-2022-47447Proof of concept | WordPress WP-Advanced-Search Plugin <= 3.3.8 is vulnerable to Cross Site Request Forgery (CSRF)internet-formation · wp-advanced-search · CWE-352 | High8.8 | — | 0.3% | May 24, 2023 |
35Monitor | CVE-2022-47446No exploit | WordPress Store Locator Plugin <= 3.98.7 is vulnerable to Cross Site Request Forgery (CSRF)viadat · store locator for wordpress with google maps · CWE-352 | High8.8 | — | 0.3% | May 24, 2023 |
35Monitor | CVE-2022-47152No exploit | WordPress clickfunnels Plugin <= 3.1.1 is vulnerable to Cross Site Request Forgery (CSRF)clickfunnels · clickfunnels · CWE-352 | High8.8 | — | 0.3% | May 24, 2023 |
35Monitor | CVE-2022-47427No exploit | WordPress My Calendar Plugin <= 3.3.24.1 is vulnerable to Cross Site Request Forgery (CSRF)my calendar project · my calendar · CWE-352 | High8.8 | — | 0.3% | Mar 15, 2023 |
35Monitor | CVE-2022-47443No exploit | WordPress Multi Rating Plugin <= 5.0.5 is vulnerable to Cross Site Request Forgery (CSRF)danielpowney · multi rating · CWE-352 | High8.8 | — | 0.3% | Mar 14, 2023 |
35Monitor | CVE-2022-47422No exploit | WordPress WordPress Stripe Donation and Payment Plugin Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF)hmplugin · accept stripe donation - aidwp · CWE-352 | High8.8 | — | 0.3% | Mar 14, 2023 |
35Monitor | CVE-2022-47147No exploit | WordPress ipBlockList Plugin <= 1.0 is vulnerable to Cross Site Request Forgery (CSRF)kesz1 · ipblocklist · CWE-352 | High8.8 | — | 0.3% | Mar 14, 2023 |
35Monitor | CVE-2022-47143No exploit | WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.9 is vulnerable to Cross Site Request Forgery (CSRF)themeisle · multiple page generator · CWE-352 | High8.8 | — | 0.3% | Mar 14, 2023 |
35Monitor | CVE-2022-47141No exploit | WordPress WP Dynamic Keywords Injector Plugin <= 2.3.15 is vulnerable to Cross Site Request Forgery (CSRF)seerox · wp dynamic keywords injector · CWE-352 | High8.8 | — | 0.3% | Mar 14, 2023 |
35Monitor | CVE-2022-47154No exploit | WordPress CSS JS Manager Plugin <= 2.4.49 is vulnerable to Cross Site Request Forgery (CSRF)piwebsolution · css js manager\, async javascript\, defer render blocking css supports woocommerce · CWE-352 | High8.8 | — | 0.3% | Mar 14, 2023 |
26Monitor | CVE-2022-47595No exploit | WordPress WP Google Maps Plugin <= 9.0.15 is vulnerable to Path Traversalcodecabin · wp go maps · CWE-22 | Medium6.5 | — | 0.8% | Mar 14, 2023 |
19Monitor | CVE-2022-47171No exploit | WordPress IP Vault – WP Firewall Plugin <= 1.1 is vulnerable to Cross Site Scripting (XSS)ip vault - wp firewall project · ip vault - wp firewall · CWE-79 | Medium4.8 | — | 0.4% | Mar 14, 2023 |
30Monitor | CVE-2022-47163No exploit | WordPress WP CSV to Database Plugin <= 2.6 is vulnerable to Cross Site Request Forgery (CSRF)wp csv to database project · wp csv to database · CWE-352 | High7.5 | — | 0.2% | Mar 14, 2023 |
35Monitor | CVE-2022-47162No exploit | WordPress DH – Anti AdBlocker Plugin <= 36 is vulnerable to Cross Site Request Forgery (CSRF)dh - anti adblocker project · dh - anti adblocker · CWE-352 | High8.8 | — | 0.3% | Mar 14, 2023 |
35Monitor | CVE-2022-47155No exploit | WordPress Slider by Supsystic Plugin <= 1.8.5 is vulnerable to Cross Site Request Forgery (CSRF)supsystic · slider · CWE-352 | High8.8 | — | 0.3% | Mar 14, 2023 |
35Monitor | CVE-2022-47440No exploit | WordPress My Tickets Plugin <= 1.9.10 is vulnerable to Cross Site Request Forgery (CSRF)my tickets project · my tickets · CWE-352 | High8.8 | — | 0.3% | Mar 13, 2023 |
17Monitor | CVE-2022-47612No exploit | WordPress Participants Database Plugin <= 2.4.5 is vulnerable to Cross Site Request Forgery (CSRF)xnau · participants database · CWE-352 | Medium4.3 | — | 0.2% | Feb 28, 2023 |
- CVE-2022-4742921Monitor
WordPress Coming Soon Landing Page and Maintenance Mode WordPress Plugin plugin <= 2.2.0 - Broken Access Control
MediumCVSS 5.3No exploitEPSS 1%8degree themes · coming soon landing page and maintenance mode wordpress pluginDec 13, 2024
- CVE-2022-4759928Monitor
WordPress File Manager Plugin <= 5.2.7 is vulnerable to PHP Object Injection
HighCVSS 7.2No exploitEPSS 1%bitapps · file managerDec 20, 2023
- CVE-2022-4759730Monitor
WordPress Popup Maker Plugin <= 1.17.1 is vulnerable to Sensitive Data Exposure
HighCVSS 7.5No exploitEPSS 1%code-atlantic · popup makerDec 20, 2023
- CVE-2022-4715935Monitor
WordPress Logaster Logo Generator Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%logaster · logo generatorMay 25, 2023
- CVE-2022-4713935Monitor
WordPress WP Basic Elements Plugin <= 5.2.15 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wp basic elements project · wp basic elementsMay 25, 2023
- CVE-2022-4713835Monitor
WordPress LOGIN AND REGISTRATION ATTEMPTS LIMIT Plugin <= 2.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%login and registration attempts limit project · login and registration attempts limitMay 25, 2023
- CVE-2022-4713535Monitor
WordPress Chronoforms Plugin <= 7.0.9 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%chronoengine · chronoformsMay 25, 2023
- CVE-2022-4744835Monitor
WordPress xili-tidy-tags Plugin <= 1.12.03 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%xiligroup · xili-tidy-tagsMay 24, 2023
- CVE-2022-4744735Monitor
WordPress WP-Advanced-Search Plugin <= 3.3.8 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8Proof of conceptEPSS 0%internet-formation · wp-advanced-searchMay 24, 2023
- CVE-2022-4744635Monitor
WordPress Store Locator Plugin <= 3.98.7 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%viadat · store locator for wordpress with google mapsMay 24, 2023
- CVE-2022-4715235Monitor
WordPress clickfunnels Plugin <= 3.1.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%clickfunnels · clickfunnelsMay 24, 2023
- CVE-2022-4742735Monitor
WordPress My Calendar Plugin <= 3.3.24.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%my calendar project · my calendarMar 15, 2023
- CVE-2022-4744335Monitor
WordPress Multi Rating Plugin <= 5.0.5 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%danielpowney · multi ratingMar 14, 2023
- CVE-2022-4742235Monitor
WordPress WordPress Stripe Donation and Payment Plugin Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%hmplugin · accept stripe donation - aidwpMar 14, 2023
- CVE-2022-4714735Monitor
WordPress ipBlockList Plugin <= 1.0 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%kesz1 · ipblocklistMar 14, 2023
- CVE-2022-4714335Monitor
WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.9 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%themeisle · multiple page generatorMar 14, 2023
- CVE-2022-4714135Monitor
WordPress WP Dynamic Keywords Injector Plugin <= 2.3.15 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%seerox · wp dynamic keywords injectorMar 14, 2023
- CVE-2022-4715435Monitor
WordPress CSS JS Manager Plugin <= 2.4.49 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%piwebsolution · css js manager\, async javascript\, defer render blocking css supports woocommerceMar 14, 2023
- CVE-2022-4759526Monitor
WordPress WP Google Maps Plugin <= 9.0.15 is vulnerable to Path Traversal
MediumCVSS 6.5No exploitEPSS 1%codecabin · wp go mapsMar 14, 2023
- CVE-2022-4717119Monitor
WordPress IP Vault – WP Firewall Plugin <= 1.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%ip vault - wp firewall project · ip vault - wp firewallMar 14, 2023
- CVE-2022-4716330Monitor
WordPress WP CSV to Database Plugin <= 2.6 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 7.5No exploitEPSS 0%wp csv to database project · wp csv to databaseMar 14, 2023
- CVE-2022-4716235Monitor
WordPress DH – Anti AdBlocker Plugin <= 36 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%dh - anti adblocker project · dh - anti adblockerMar 14, 2023
- CVE-2022-4715535Monitor
WordPress Slider by Supsystic Plugin <= 1.8.5 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%supsystic · sliderMar 14, 2023
- CVE-2022-4744035Monitor
WordPress My Tickets Plugin <= 1.9.10 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%my tickets project · my ticketsMar 13, 2023
- CVE-2022-4761217Monitor
WordPress Participants Database Plugin <= 2.4.5 is vulnerable to Cross Site Request Forgery (CSRF)
MediumCVSS 4.3No exploitEPSS 0%xnau · participants databaseFeb 28, 2023