benjaminrojas records
7 published records for vendor benjaminrojas.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 28.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-10886No exploit | The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.benjaminrojas · wp editor · CWE-264 | Critical9.8 | — | 2.0% | Aug 14, 2019 |
35Monitor | CVE-2016-10885No exploit | The wp-editor plugin before 1.2.6 for WordPress has CSRF.benjaminrojas · wp editor · CWE-352 | High8.8 | — | 0.7% | Aug 14, 2019 |
30Monitor | CVE-2024-25591No exploit | WordPress WP Editor plugin <=1.2.7 - Sensitive Data Exposure vulnerabilitybenjaminrojas · wp editor · CWE-200 | High7.5 | — | 0.5% | Mar 17, 2024 |
28Monitor | CVE-2025-3294No exploit | WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Updatebenjaminrojas · wp editor · CWE-22 | High7.2 | — | 1.0% | Apr 17, 2025 |
28Monitor | CVE-2021-24151No exploit | WP Editor < 1.2.7 - Authenticated SQL injectionbenjaminrojas · wp editor · CWE-89 | High7.2 | — | 0.8% | Jan 16, 2024 |
28Monitor | CVE-2022-2446No exploit | WP Editor <= 1.2.9 - Authenticated (Admin+) PHAR Deserializationbenjaminrojas · wp editor · CWE-502 | High7.2 | — | 0.6% | Sep 13, 2024 |
19Monitor | CVE-2025-3295No exploit | WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Readbenjaminrojas · wp editor · CWE-22 | Medium4.9 | — | 0.5% | Apr 17, 2025 |
- CVE-2016-1088640Plan
The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
CriticalCVSS 9.8No exploitEPSS 2%benjaminrojas · wp editorAug 14, 2019
- CVE-2016-1088535Monitor
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
HighCVSS 8.8No exploitEPSS 1%benjaminrojas · wp editorAug 14, 2019
- CVE-2024-2559130Monitor
WordPress WP Editor plugin <=1.2.7 - Sensitive Data Exposure vulnerability
HighCVSS 7.5No exploitEPSS 0%benjaminrojas · wp editorMar 17, 2024
- CVE-2025-329428Monitor
WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Update
HighCVSS 7.2No exploitEPSS 1%benjaminrojas · wp editorApr 17, 2025
- CVE-2021-2415128Monitor
WP Editor < 1.2.7 - Authenticated SQL injection
HighCVSS 7.2No exploitEPSS 1%benjaminrojas · wp editorJan 16, 2024
- CVE-2022-244628Monitor
WP Editor <= 1.2.9 - Authenticated (Admin+) PHAR Deserialization
HighCVSS 7.2No exploitEPSS 1%benjaminrojas · wp editorSep 13, 2024
- CVE-2025-329519Monitor
WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read
MediumCVSS 4.9No exploitEPSS 1%benjaminrojas · wp editorApr 17, 2025