e-plugins records
3 published records for vendor e-plugins.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-269 Improper Privilege Management1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-10547No exploit | WP Membership <= 1.6.2 - Unauthenticated Arbitrary File Uploade-plugins · wp membership · CWE-434 | Critical9.8 | — | 0.9% | Nov 9, 2024 |
35Monitor | CVE-2020-36666No exploit | Multiple e-plugins - Subscriber+ Privilege Escalatione-plugins · directory pro · CWE-269 | High8.8 | — | 0.9% | Mar 27, 2023 |
22Monitor | CVE-2015-4039Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to injee-plugins · wp membership · CWE-79 | Medium5.4 | — | 2.8% | Jan 6, 2020 |
- CVE-2024-1054739Monitor
WP Membership <= 1.6.2 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.8No exploitEPSS 1%e-plugins · wp membershipNov 9, 2024
- CVE-2020-3666635Monitor
Multiple e-plugins - Subscriber+ Privilege Escalation
HighCVSS 8.8No exploitEPSS 1%e-plugins · directory proMar 27, 2023
- CVE-2015-403922Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inje
MediumCVSS 5.4Proof of conceptEPSS 3%e-plugins · wp membershipJan 6, 2020