Webula
Patchstack Bug Bounty Program
16 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
23Monitor | CVE-2025-32135No exploit | WordPress Split Test For Elementor plugin <= 1.8.4 - Cross Site Scripting (XSS) vulnerabilityrocketelements · split test for elementor · CWE-79 | Medium5.9 | — | 0.4% | Apr 4, 2025 |
23Monitor | CVE-2025-31864Proof of concept | WordPress Beam me up Scotty – Back to Top Button plugin <= 1.0.23 - Cross Site Scripting (XSS) vulnerabilityout the box · beam me up scotty · CWE-79 | Medium5.9 | — | 0.3% | Apr 1, 2025 |
35Monitor | CVE-2025-22783Proof of concept | WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.03 - SQL Injection vulnerabilitysquirrly · seo plugin by squirrly seo · CWE-89 | High8.8 | — | 0.6% | Mar 27, 2025 |
30Monitor | CVE-2025-22652Proof of concept | WordPress Payment Forms for Paystack plugin <= 4.0.1 - SQL Injection vulnerabilitykendysond · payment forms for paystack · CWE-89 | High7.6 | — | 0.9% | Mar 27, 2025 |
30Monitor | CVE-2025-30921Proof of concept | WordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerabilitytribulant software · newsletters · CWE-89 | High7.6 | — | 0.5% | Mar 27, 2025 |
30Monitor | CVE-2025-26886No exploit | WordPress PublishPress Authors plugin <= 4.7.3 - SQL Injection vulnerabilitypublishpress · publishpress authors · CWE-89 | High7.6 | — | 0.4% | Mar 15, 2025 |
39Monitor | CVE-2025-26971No exploit | WordPress Poll Maker <= 5.6.5 - SQL Injection vulnerabilityays-pro · poll maker · CWE-89 | Critical9.8 | — | 0.5% | Feb 25, 2025 |
26Monitor | CVE-2025-26769No exploit | WordPress Vertex Addons for Elementor plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerabilitywebilia inc. · vertex addons for elementor · CWE-79 | Medium6.5 | — | 0.2% | Feb 17, 2025 |
26Monitor | CVE-2025-22662No exploit | WordPress SendPulse Email Marketing Newsletter plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerabilitysendpulse · sendpulse email marketing newsletter · CWE-79 | Medium6.5 | — | 0.2% | Feb 4, 2025 |
30Monitor | CVE-2025-24659Proof of concept | WordPress Premium Packages – Sell Digital Products Securely plugin <= 5.9.6 - SQL Injection vulnerabilityshahjada · wpdm – premium packages · CWE-89 | High7.6 | — | 1.0% | Jan 24, 2025 |
40Plan | CVE-2025-24587Proof of concept | WordPress Email Subscription Popup plugin <= 1.2.23 - SQL Injection vulnerabilitynks · email subscription popup · CWE-89 | High7.6 | — | 32.2% | Jan 24, 2025 |
30Monitor | CVE-2025-22710Proof of concept | WordPress Smart Manager Plugin <= 8.52.0 - SQL Injection vulnerabilitystoreapps · smart manager · CWE-89 | High7.6 | — | 0.8% | Jan 21, 2025 |
28Monitor | CVE-2025-22510Proof of concept | WordPress WC Price History for Omnibus plugin <= 2.1.4 - PHP Object Injection vulnerabilitykkarpieszuk · wc price history for omnibus · CWE-502 | High7.2 | — | 1.2% | Jan 9, 2025 |
30Monitor | CVE-2025-22352Proof of concept | WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin <= 1.4.9 - SQL Injection vulnerabilityelextensions · elex woocommerce advanced bulk edit products, prices & attributes · CWE-89 | High7.6 | — | 0.7% | Jan 7, 2025 |
28Monitor | CVE-2024-56289Proof of concept | WordPress Groundhogg plugin <= 3.7.3.3 - Reflected Cross Site Scripting (XSS) vulnerabilityadrian tobey · groundhogg · CWE-79 | High7.1 | — | 0.7% | Jan 7, 2025 |
37Monitor | CVE-2024-56278Proof of concept | WordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerabilitysmackcoders inc., · wp ultimate exporter · CWE-94 | Critical9.1 | — | 1.9% | Jan 7, 2025 |
- CVE-2025-3213523Monitor
WordPress Split Test For Elementor plugin <= 1.8.4 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.9No exploitEPSS 0%rocketelements · split test for elementorApr 4, 2025
- CVE-2025-3186423Monitor
WordPress Beam me up Scotty – Back to Top Button plugin <= 1.0.23 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.9Proof of conceptEPSS 0%out the box · beam me up scottyApr 1, 2025
- CVE-2025-2278335Monitor
WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.03 - SQL Injection vulnerability
HighCVSS 8.8Proof of conceptEPSS 1%squirrly · seo plugin by squirrly seoMar 27, 2025
- CVE-2025-2265230Monitor
WordPress Payment Forms for Paystack plugin <= 4.0.1 - SQL Injection vulnerability
HighCVSS 7.6Proof of conceptEPSS 1%kendysond · payment forms for paystackMar 27, 2025
- CVE-2025-3092130Monitor
WordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerability
HighCVSS 7.6Proof of conceptEPSS 1%tribulant software · newslettersMar 27, 2025
- CVE-2025-2688630Monitor
WordPress PublishPress Authors plugin <= 4.7.3 - SQL Injection vulnerability
HighCVSS 7.6No exploitEPSS 0%publishpress · publishpress authorsMar 15, 2025
- CVE-2025-2697139Monitor
WordPress Poll Maker <= 5.6.5 - SQL Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 0%ays-pro · poll makerFeb 25, 2025
- CVE-2025-2676926Monitor
WordPress Vertex Addons for Elementor plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.5No exploitEPSS 0%webilia inc. · vertex addons for elementorFeb 17, 2025
- CVE-2025-2266226Monitor
WordPress SendPulse Email Marketing Newsletter plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.5No exploitEPSS 0%sendpulse · sendpulse email marketing newsletterFeb 4, 2025
- CVE-2025-2465930Monitor
WordPress Premium Packages – Sell Digital Products Securely plugin <= 5.9.6 - SQL Injection vulnerability
HighCVSS 7.6Proof of conceptEPSS 1%shahjada · wpdm – premium packagesJan 24, 2025
- CVE-2025-2458740Plan
WordPress Email Subscription Popup plugin <= 1.2.23 - SQL Injection vulnerability
HighCVSS 7.6Proof of conceptEPSS 32%nks · email subscription popupJan 24, 2025
- CVE-2025-2271030Monitor
WordPress Smart Manager Plugin <= 8.52.0 - SQL Injection vulnerability
HighCVSS 7.6Proof of conceptEPSS 1%storeapps · smart managerJan 21, 2025
- CVE-2025-2251028Monitor
WordPress WC Price History for Omnibus plugin <= 2.1.4 - PHP Object Injection vulnerability
HighCVSS 7.2Proof of conceptEPSS 1%kkarpieszuk · wc price history for omnibusJan 9, 2025
- CVE-2025-2235230Monitor
WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin <= 1.4.9 - SQL Injection vulnerability
HighCVSS 7.6Proof of conceptEPSS 1%elextensions · elex woocommerce advanced bulk edit products, prices & attributesJan 7, 2025
- CVE-2024-5628928Monitor
WordPress Groundhogg plugin <= 3.7.3.3 - Reflected Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1Proof of conceptEPSS 1%adrian tobey · groundhoggJan 7, 2025
- CVE-2024-5627837Monitor
WordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerability
CriticalCVSS 9.1Proof of conceptEPSS 2%smackcoders inc., · wp ultimate exporterJan 7, 2025