Skip to content
Noroxi

Robert DeVore

Patchstack Bug Bounty Program

35 credited records · 0 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • CVE-2025-5537
    21Monitor

    Lightbox & Modal Popup WordPress Plugin – FooBox <= 2.7.34 - Authenticated (Author+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    fooplugins · fooboxJul 8, 2025

  • CVE-2025-5290
    25Monitor

    Borderless – Elementor Addons and Templates <= 1.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 6.4No exploitEPSS 0%

    visualmodo · borderless – addons and templates for elementorMay 31, 2025

  • CVE-2025-5292
    25Monitor

    Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+)

    MediumCVSS 6.4No exploitEPSS 0%

    bdthemes · element pack – widgets, templates & addons for elementorMay 31, 2025

  • CVE-2025-4944
    25Monitor

    LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Compare and Google Maps Widgets

    MediumCVSS 6.4No exploitEPSS 0%

    choijun · la-studio element kit for elementorMay 30, 2025

  • WordPress WP ULike plugin <= 4.7.9.1 - Content Spoofing Vulnerability

    MediumCVSS 5.3Proof of conceptEPSS 0%

    alimir · wp ulikeApr 10, 2025

  • WordPress Lightbox & Modal Popup WordPress Plugin – FooBox plugin <= 2.7.33 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.9No exploitEPSS 0%

    fooplugins · foobox image lightboxApr 10, 2025

  • WordPress CoDesigner plugin <= 4.29 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.9No exploitEPSS 0%

    codexpert, inc · codesignerJan 15, 2025

  • WordPress WP ULike plugin <= 4.7.6 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 4.8No exploitEPSS 0%

    wpulike · wp ulikeJan 15, 2025

  • WordPress Piotnet Addons For Elementor plugin <= 2.4.31 - Cross-Site Scripting vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    piotnetdotcom · piotnet addons for elementorJan 7, 2025

  • WordPress Smart Custom FIelds plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    takashi kitajima · smart custom fieldsJan 7, 2025

  • WordPress WPBITS Addons For Elementor Page Builder plugin <= 1.5.1 - Cross-Site Scripting vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    wpbits · wpbits addons for elementor page builderJan 7, 2025

  • CVE-2024-9502
    21Monitor

    Master Addons -- Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    master-addons · master addonsJan 7, 2025

  • WordPress Royal Elementor Addons and Templates plugin <= 1.3.987 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    royal-elementor-addons · royal elementor addonsDec 31, 2024

  • CVE-2024-8442
    21Monitor

    Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider <= 3.15.18 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    bdthemes · prime sliderNov 7, 2024

  • WordPress Firelight Lightbox plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 4.8No exploitEPSS 0%

    firelightwp · firelight lightboxOct 28, 2024

  • WordPress Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.21 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 4.8No exploitEPSS 0%

    robosoft · robo galleryOct 24, 2024

  • WordPress Responsive Lightbox & Gallery plugin <= 2.4.8 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.9No exploitEPSS 0%

    dfactory · responsive lightboxOct 17, 2024

  • WordPress Lightbox slider -- Responsive Lightbox Gallery plugin <= 1.10.6 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    weblizar - wordpress themes & plugin · lightbox slider – responsive lightbox galleryOct 17, 2024

  • WordPress G Meta Keywords plugin <= 1.4 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    sinan yorulmaz · g meta keywordsOct 17, 2024

  • WordPress Exclusive Addons for Elementor plugin <= 2.7.1 - Cross-Site Scripting vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    exclusiveaddons · exclusive addons for elementorOct 17, 2024

  • WordPress CM Tooltip Glossary plugin <= 4.3.9 - Stored Cross-Site Scripting vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    creativemindssolutions · cm tooltip glossaryOct 11, 2024

  • WordPress ARI Fancy Lightbox -- Popup for WordPress plugin <= 1.3.17 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    arisoft · ari fancy lightboxOct 6, 2024

  • WordPress Meta Slider and Carousel with Lightbox plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    essential plugin · meta slider and carousel with lightboxOct 6, 2024

  • WordPress Photo Gallery by 10Web plugin <= 1.8.27 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 4.8No exploitEPSS 0%

    10web · photo galleryOct 6, 2024

  • WordPress Accordion plugin <= 2.2.99 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    pickplugins · accordionOct 6, 2024