CodeRevolution records
9 published records for vendor coderevolution.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 44.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-269 Improper Privilege Management2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-862 Missing Authorization2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-9265No exploit | Echo RSS Feed Post Generator <= 5.4.6 - Unauthenticated Privilege Escalationcoderevolution · echo rss feed post generator · CWE-269 | Critical9.8 | — | 0.6% | Oct 1, 2024 |
39Monitor | CVE-2024-31290No exploit | WordPress Demo My WordPress plugin <= 1.0.9.1 - Unauthenticated Privilege Escalation vulnerabilitycoderevolution · demo my wordpress · CWE-269 | Critical9.8 | — | 0.5% | May 17, 2024 |
35Monitor | CVE-2024-13882No exploit | Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.8 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Uploadcoderevolution · aiomatic · CWE-434 | High8.8 | — | 0.8% | Mar 8, 2025 |
35Monitor | CVE-2024-34435No exploit | WordPress Aiomatic plugin <= 1.9.3 - Broken Access Control vulnerabilitycoderevolution · aiomatic · CWE-862 | High8.8 | — | 0.3% | Jun 9, 2024 |
30Monitor | CVE-2025-6206No exploit | Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.5.0 - Authenticated (Subscriber+) Arbitrary File Uploadcoderevolution · aiomatic · CWE-434 | High7.5 | — | 0.5% | Jun 24, 2025 |
24Monitor | CVE-2023-49176No exploit | WordPress WP Pocket URLs Plugin <= 1.0.2 is vulnerable to Cross Site Scripting (XSS)coderevolution · wp pocket urls · CWE-79 | Medium6.1 | — | 0.4% | Dec 15, 2023 |
21Monitor | CVE-2024-5969No exploit | AIomatic - Automatic AI Content Writer <= 2.0.5 - Unauthenticated Arbitrary Email Sendingcoderevolution · aiomatic · CWE-20 | Medium5.3 | — | 0.3% | Jul 27, 2024 |
21Monitor | CVE-2024-51681No exploit | WordPress WP Pocket URLs plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerabilitycoderevolution · wp pocket urls · CWE-79 | Medium5.4 | — | 0.3% | Nov 4, 2024 |
21Monitor | CVE-2024-13816No exploit | Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actionscoderevolution · aiomatic · CWE-862 | Medium5.4 | — | 0.2% | Mar 8, 2025 |
- CVE-2024-926539Monitor
Echo RSS Feed Post Generator <= 5.4.6 - Unauthenticated Privilege Escalation
CriticalCVSS 9.8No exploitEPSS 1%coderevolution · echo rss feed post generatorOct 1, 2024
- CVE-2024-3129039Monitor
WordPress Demo My WordPress plugin <= 1.0.9.1 - Unauthenticated Privilege Escalation vulnerability
CriticalCVSS 9.8No exploitEPSS 1%coderevolution · demo my wordpressMay 17, 2024
- CVE-2024-1388235Monitor
Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.8 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%coderevolution · aiomaticMar 8, 2025
- CVE-2024-3443535Monitor
WordPress Aiomatic plugin <= 1.9.3 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%coderevolution · aiomaticJun 9, 2024
- CVE-2025-620630Monitor
Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.5.0 - Authenticated (Subscriber+) Arbitrary File Upload
HighCVSS 7.5No exploitEPSS 1%coderevolution · aiomaticJun 24, 2025
- CVE-2023-4917624Monitor
WordPress WP Pocket URLs Plugin <= 1.0.2 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%coderevolution · wp pocket urlsDec 15, 2023
- CVE-2024-596921Monitor
AIomatic - Automatic AI Content Writer <= 2.0.5 - Unauthenticated Arbitrary Email Sending
MediumCVSS 5.3No exploitEPSS 0%coderevolution · aiomaticJul 27, 2024
- CVE-2024-5168121Monitor
WordPress WP Pocket URLs plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%coderevolution · wp pocket urlsNov 4, 2024
- CVE-2024-1381621Monitor
Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions
MediumCVSS 5.4No exploitEPSS 0%coderevolution · aiomaticMar 8, 2025