Skip to content
Noroxi

rezaduty (Patchstack Alliance)

25 credited records · 0 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • WordPress Coming Soon Landing Page and Maintenance Mode WordPress Plugin plugin <= 2.2.0 - Broken Access Control

    MediumCVSS 5.3No exploitEPSS 1%

    8degree themes · coming soon landing page and maintenance mode wordpress pluginDec 13, 2024

  • WordPress File Manager Plugin <= 5.2.7 is vulnerable to PHP Object Injection

    HighCVSS 7.2No exploitEPSS 1%

    bitapps · file managerDec 20, 2023

  • WordPress Popup Maker Plugin <= 1.17.1 is vulnerable to Sensitive Data Exposure

    HighCVSS 7.5No exploitEPSS 1%

    code-atlantic · popup makerDec 20, 2023

  • WordPress Logaster Logo Generator Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    logaster · logo generatorMay 25, 2023

  • WordPress WP Basic Elements Plugin <= 5.2.15 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wp basic elements project · wp basic elementsMay 25, 2023

  • WordPress LOGIN AND REGISTRATION ATTEMPTS LIMIT Plugin <= 2.1 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    login and registration attempts limit project · login and registration attempts limitMay 25, 2023

  • WordPress Chronoforms Plugin <= 7.0.9 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    chronoengine · chronoformsMay 25, 2023

  • WordPress xili-tidy-tags Plugin <= 1.12.03 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    xiligroup · xili-tidy-tagsMay 24, 2023

  • WordPress WP-Advanced-Search Plugin <= 3.3.8 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8Proof of conceptEPSS 0%

    internet-formation · wp-advanced-searchMay 24, 2023

  • WordPress Store Locator Plugin <= 3.98.7 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    viadat · store locator for wordpress with google mapsMay 24, 2023

  • WordPress clickfunnels Plugin <= 3.1.1 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    clickfunnels · clickfunnelsMay 24, 2023

  • WordPress My Calendar Plugin <= 3.3.24.1 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    my calendar project · my calendarMar 15, 2023

  • WordPress Multi Rating Plugin <= 5.0.5 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    danielpowney · multi ratingMar 14, 2023

  • WordPress WordPress Stripe Donation and Payment Plugin Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    hmplugin · accept stripe donation - aidwpMar 14, 2023

  • WordPress ipBlockList Plugin <= 1.0 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    kesz1 · ipblocklistMar 14, 2023

  • WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.9 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    themeisle · multiple page generatorMar 14, 2023

  • WordPress WP Dynamic Keywords Injector Plugin <= 2.3.15 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    seerox · wp dynamic keywords injectorMar 14, 2023

  • WordPress CSS JS Manager Plugin <= 2.4.49 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    piwebsolution · css js manager\, async javascript\, defer render blocking css supports woocommerceMar 14, 2023

  • WordPress WP Google Maps Plugin <= 9.0.15 is vulnerable to Path Traversal

    MediumCVSS 6.5No exploitEPSS 1%

    codecabin · wp go mapsMar 14, 2023

  • WordPress IP Vault – WP Firewall Plugin <= 1.1 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    ip vault - wp firewall project · ip vault - wp firewallMar 14, 2023

  • WordPress WP CSV to Database Plugin <= 2.6 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 7.5No exploitEPSS 0%

    wp csv to database project · wp csv to databaseMar 14, 2023

  • WordPress DH – Anti AdBlocker Plugin <= 36 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    dh - anti adblocker project · dh - anti adblockerMar 14, 2023

  • WordPress Slider by Supsystic Plugin <= 1.8.5 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    supsystic · sliderMar 14, 2023

  • WordPress My Tickets Plugin <= 1.9.10 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    my tickets project · my ticketsMar 13, 2023

  • WordPress Participants Database Plugin <= 2.4.5 is vulnerable to Cross Site Request Forgery (CSRF)

    MediumCVSS 4.3No exploitEPSS 0%

    xnau · participants databaseFeb 28, 2023