Vlad Vector (Patchstack)
20 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
19Monitor | CVE-2022-45082No exploit | WordPress Accordions plugin <= 2.0.3 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilitiesoxilab · accordions · CWE-79 | Medium4.8 | — | 0.4% | Nov 18, 2022 |
35Monitor | CVE-2022-44740No exploit | WordPress Creative Mail plugin <= 1.5.4 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilitiesconstantcontact · creative mail · CWE-352 | High8.8 | — | 0.3% | Nov 18, 2022 |
28Monitor | CVE-2022-42459No exploit | WordPress Image Hover Effects Ultimate plugin <= 9.7.1 - Auth. WordPress Options Change vulnerabilityoxilab · image hover effects ultimate · CWE-264 | High7.2 | — | 0.9% | Nov 18, 2022 |
35Monitor | CVE-2022-40695No exploit | WordPress SEO Redirection Plugin plugin <= 8.9 - Multiple Cross-Site Scripting (CSRF) vulnerabilitiesclogica · seo redirection · CWE-352 | High8.8 | — | 0.3% | Nov 18, 2022 |
21Monitor | CVE-2021-36905No exploit | WordPress Quiz And Survey Master plugin <= 7.3.4 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilitiesexpresstech · quiz and survey master · CWE-79 | Medium5.4 | — | 0.5% | Nov 17, 2022 |
35Monitor | CVE-2021-36906No exploit | WordPress Quiz And Survey Master plugin <= 7.3.6 - Multiple Insecure direct object references (IDOR) vulnerabilitiesexpresstech · quiz and survey master · CWE-639 | High8.8 | — | 0.6% | Nov 3, 2022 |
28Monitor | CVE-2021-36898No exploit | WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. SQL Injection (SQLi) vulnerabilityexpresstech · quiz and survey master · CWE-89 | High7.2 | — | 0.9% | Oct 28, 2022 |
19Monitor | CVE-2022-40311No exploit | WordPress Analytics Cat plugin <= 1.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityfatcatapps · analytics cat · CWE-79 | Medium4.8 | — | 0.5% | Oct 21, 2022 |
28Monitor | CVE-2022-38104No exploit | WordPress Accordions plugin <= 2.0.3 - Auth. WordPress Options Change vulnerabilityoxilab · accordions · CWE-264 | High7.2 | — | 1.0% | Oct 21, 2022 |
21Monitor | CVE-2022-40215No exploit | WordPress Tabs plugin <= 3.7.1 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitiestabs project · tabs · CWE-79 | Medium5.4 | — | 0.5% | Sep 23, 2022 |
28Monitor | CVE-2022-40217No exploit | WordPress WPide plugin <= 2.6 - Authenticated Arbitrary File Edit/Upload vulnerabilityxplodedthemes · wpide · CWE-434 | High7.2 | — | 1.0% | Sep 21, 2022 |
21Monitor | CVE-2022-38073No exploit | WordPress Awesome Support plugin <= 6.0.7 - Multiple Authenticated Persistent XSS (Additional Interested Parties)getawesomesupport · awesome support · CWE-79 | Medium5.4 | — | 0.6% | Sep 21, 2022 |
21Monitor | CVE-2022-36390No exploit | WordPress Event Calendar – Calendar plugin <= 1.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilitytotal-soft · event calendar · CWE-79 | Medium5.4 | — | 0.5% | Sep 21, 2022 |
21Monitor | CVE-2022-36383No exploit | WordPress Word Search Puzzles game plugin <= 2.0.1 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitieswebhelpagency · wha wordsearch · CWE-79 | Medium5.4 | — | 0.5% | Sep 21, 2022 |
21Monitor | CVE-2022-36365No exploit | WordPress WHA Crossword plugin <= 1.1.10 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitieswebhelpagency · wha crossword · CWE-79 | Medium5.4 | — | 0.7% | Sep 21, 2022 |
35Monitor | CVE-2022-36389No exploit | WordPress Better Messages plugin <= 1.9.9.148 - Cross-Site Request Forgery (CSRF) vulnerabilitywordplus · better messages · CWE-352 | High8.8 | — | 0.4% | Aug 23, 2022 |
35Monitor | CVE-2022-36288No exploit | WordPress Download Manager plugin <= 3.2.48 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilitiesw3eden · download manager · CWE-352 | High8.8 | — | 0.3% | Aug 23, 2022 |
21Monitor | CVE-2022-34658No exploit | WordPress Download Manager plugin <= 3.2.48 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilitiesw3eden · download manager · CWE-79 | Medium5.4 | — | 0.6% | Aug 23, 2022 |
24Monitor | CVE-2022-34857No exploit | WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerabilitysmartypantsplugins · sp project \& document manager · CWE-79 | Medium6.1 | — | 0.6% | Aug 22, 2022 |
26Monitor | CVE-2022-36284No exploit | WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Authenticated IDOR vulnerability leading to PayPal email changestoreapps · affiliate for woocommerce · CWE-639 | Medium6.5 | — | 0.6% | Aug 5, 2022 |
- CVE-2022-4508219Monitor
WordPress Accordions plugin <= 2.0.3 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 4.8No exploitEPSS 0%oxilab · accordionsNov 18, 2022
- CVE-2022-4474035Monitor
WordPress Creative Mail plugin <= 1.5.4 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
HighCVSS 8.8No exploitEPSS 0%constantcontact · creative mailNov 18, 2022
- CVE-2022-4245928Monitor
WordPress Image Hover Effects Ultimate plugin <= 9.7.1 - Auth. WordPress Options Change vulnerability
HighCVSS 7.2No exploitEPSS 1%oxilab · image hover effects ultimateNov 18, 2022
- CVE-2022-4069535Monitor
WordPress SEO Redirection Plugin plugin <= 8.9 - Multiple Cross-Site Scripting (CSRF) vulnerabilities
HighCVSS 8.8No exploitEPSS 0%clogica · seo redirectionNov 18, 2022
- CVE-2021-3690521Monitor
WordPress Quiz And Survey Master plugin <= 7.3.4 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 5.4No exploitEPSS 0%expresstech · quiz and survey masterNov 17, 2022
- CVE-2021-3690635Monitor
WordPress Quiz And Survey Master plugin <= 7.3.6 - Multiple Insecure direct object references (IDOR) vulnerabilities
HighCVSS 8.8No exploitEPSS 1%expresstech · quiz and survey masterNov 3, 2022
- CVE-2021-3689828Monitor
WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. SQL Injection (SQLi) vulnerability
HighCVSS 7.2No exploitEPSS 1%expresstech · quiz and survey masterOct 28, 2022
- CVE-2022-4031119Monitor
WordPress Analytics Cat plugin <= 1.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 0%fatcatapps · analytics catOct 21, 2022
- CVE-2022-3810428Monitor
WordPress Accordions plugin <= 2.0.3 - Auth. WordPress Options Change vulnerability
HighCVSS 7.2No exploitEPSS 1%oxilab · accordionsOct 21, 2022
- CVE-2022-4021521Monitor
WordPress Tabs plugin <= 3.7.1 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 5.4No exploitEPSS 1%tabs project · tabsSep 23, 2022
- CVE-2022-4021728Monitor
WordPress WPide plugin <= 2.6 - Authenticated Arbitrary File Edit/Upload vulnerability
HighCVSS 7.2No exploitEPSS 1%xplodedthemes · wpideSep 21, 2022
- CVE-2022-3807321Monitor
WordPress Awesome Support plugin <= 6.0.7 - Multiple Authenticated Persistent XSS (Additional Interested Parties)
MediumCVSS 5.4No exploitEPSS 1%getawesomesupport · awesome supportSep 21, 2022
- CVE-2022-3639021Monitor
WordPress Event Calendar – Calendar plugin <= 1.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 1%total-soft · event calendarSep 21, 2022
- CVE-2022-3638321Monitor
WordPress Word Search Puzzles game plugin <= 2.0.1 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 5.4No exploitEPSS 1%webhelpagency · wha wordsearchSep 21, 2022
- CVE-2022-3636521Monitor
WordPress WHA Crossword plugin <= 1.1.10 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 5.4No exploitEPSS 1%webhelpagency · wha crosswordSep 21, 2022
- CVE-2022-3638935Monitor
WordPress Better Messages plugin <= 1.9.9.148 - Cross-Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%wordplus · better messagesAug 23, 2022
- CVE-2022-3628835Monitor
WordPress Download Manager plugin <= 3.2.48 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
HighCVSS 8.8No exploitEPSS 0%w3eden · download managerAug 23, 2022
- CVE-2022-3465821Monitor
WordPress Download Manager plugin <= 3.2.48 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 5.4No exploitEPSS 1%w3eden · download managerAug 23, 2022
- CVE-2022-3485724Monitor
WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 1%smartypantsplugins · sp project \& document managerAug 22, 2022
- CVE-2022-3628426Monitor
WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Authenticated IDOR vulnerability leading to PayPal email change
MediumCVSS 6.5No exploitEPSS 1%storeapps · affiliate for woocommerceAug 5, 2022