Rooting
Lucas Torres
8 credited records · 7 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
22Monitor | CVE-2026-44119No exploit | Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modulesapache · http server · CWE-269 | Medium5.5 | — | 0.3% | Jun 8, 2026 |
17Monitor | CVE-2025-62874No exploit | WordPress AnyComment plugin <= 0.3.6 - Broken Access Control vulnerabilityalexander · anycomment · CWE-862 | Medium4.3 | — | 0.3% | Dec 31, 2025 |
35Monitor | CVE-2025-62751No exploit | WordPress Vireo theme <= 1.0.24 - Broken Access Control vulnerabilityextendthemes · vireo · CWE-862 | High8.8 | — | 0.2% | Dec 31, 2025 |
26Monitor | CVE-2025-49041No exploit | WordPress Get Cash plugin <= 3.2.3 - Broken Access Control vulnerabilitythe african boss · get cash · CWE-862 | Medium6.5 | — | 0.4% | Dec 18, 2025 |
26Monitor | CVE-2025-10019No exploit | WordPress Contact Form Email plugin <= 1.3.60 - Insecure Direct Object References (IDOR) vulnerabilitycodepeople · contact form email · CWE-639 | Medium6.5 | — | 0.4% | Dec 18, 2025 |
26Monitor | CVE-2025-13835No exploit | WordPress Arconix Shortcodes plugin <= 2.1.20 - Cross Site Scripting (XSS) vulnerabilitytychesoftwares · arconix shortcodes · CWE-79 | Medium6.5 | — | 0.2% | Dec 1, 2025 |
34Monitor | CVE-2025-48091No exploit | WordPress AnyComment plugin <= 0.3.6 - SQL Injection vulnerabilityalexander · anycomment · CWE-89 | High8.5 | — | 0.4% | Oct 22, 2025 |
26Monitor | CVE-2025-54746No exploit | WordPress Shortcode Redirect Plugin <= 1.0.02 - Cross Site Scripting (XSS) Vulnerabilitycartpauj · shortcode redirect · CWE-79 | Medium6.5 | — | 0.2% | Aug 14, 2025 |
- CVE-2026-4411922Monitor
Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules
MediumCVSS 5.5No exploitEPSS 0%apache · http serverJun 8, 2026
- CVE-2025-6287417Monitor
WordPress AnyComment plugin <= 0.3.6 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%alexander · anycommentDec 31, 2025
- CVE-2025-6275135Monitor
WordPress Vireo theme <= 1.0.24 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%extendthemes · vireoDec 31, 2025
- CVE-2025-4904126Monitor
WordPress Get Cash plugin <= 3.2.3 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%the african boss · get cashDec 18, 2025
- CVE-2025-1001926Monitor
WordPress Contact Form Email plugin <= 1.3.60 - Insecure Direct Object References (IDOR) vulnerability
MediumCVSS 6.5No exploitEPSS 0%codepeople · contact form emailDec 18, 2025
- CVE-2025-1383526Monitor
WordPress Arconix Shortcodes plugin <= 2.1.20 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.5No exploitEPSS 0%tychesoftwares · arconix shortcodesDec 1, 2025
- CVE-2025-4809134Monitor
WordPress AnyComment plugin <= 0.3.6 - SQL Injection vulnerability
HighCVSS 8.5No exploitEPSS 0%alexander · anycommentOct 22, 2025
- CVE-2025-5474626Monitor
WordPress Shortcode Redirect Plugin <= 1.0.02 - Cross Site Scripting (XSS) Vulnerability
MediumCVSS 6.5No exploitEPSS 0%cartpauj · shortcode redirectAug 14, 2025