fullworksplugins records
17 published records for vendor fullworksplugins.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 64.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-862 Missing Authorization3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-203 Observable Discrepancy1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2023-25714No exploit | WordPress Quick Paypal Payments plugin <= 5.7.25 - Broken Access Control vulnerabilityfullworks · quick paypal payments · CWE-862 | High7.5 | — | 0.8% | Dec 9, 2024 |
26Monitor | CVE-2023-25035No exploit | WordPress Quick Contact Form plugin <= 8.0.3.1 - Broken Access Control vulnerabilityfullworks · quick contact form · CWE-862 | Medium6.5 | — | 0.7% | Dec 9, 2024 |
25Monitor | CVE-2017-18536Proof of concept | The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.fullworksplugins · stop user enumeration · CWE-79 | Medium6.1 | — | 2.0% | Aug 21, 2019 |
24Monitor | CVE-2023-23491Proof of concept | The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' pfullworksplugins · quick event manager · CWE-79 | Medium6.1 | — | 1.2% | Jan 20, 2023 |
24Monitor | CVE-2023-23979No exploit | WordPress Quick Event Manager Plugin <= 9.7.4 is vulnerable to Cross Site Scripting (XSS)fullworksplugins · quick event manager · CWE-79 | Medium6.1 | — | 0.4% | Apr 6, 2023 |
24Monitor | CVE-2023-25713No exploit | WordPress Quick Paypal Payments Plugin <= 5.7.25 is vulnerable to Cross Site Scripting (XSS)fullworksplugins · quick paypal payments · CWE-79 | Medium6.1 | — | 0.4% | Apr 7, 2023 |
21Monitor | CVE-2017-1000226No exploit | Stop User Enumeration 1.3.8 allows user enumeration via the REST APIfullworksplugins · stop user enumeration · CWE-200 | Medium5.3 | — | 1.4% | Nov 17, 2017 |
21Monitor | CVE-2025-4302Proof of concept | Stop User Enumeration < 1.7.3 - Protection Bypassfullworksplugins · stop user enumeration · CWE-203 | Medium5.3 | — | 0.9% | Jul 17, 2025 |
21Monitor | CVE-2023-23975No exploit | WordPress Quick Event Manager plugin <= 9.7.4 - Broken Access Control vulnerabilityfullworks · quick event manager · CWE-862 | Medium5.3 | — | 0.7% | Dec 9, 2024 |
21Monitor | CVE-2022-37339No exploit | WordPress Meet My Team plugin <= 2.0.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityfullworksplugins · meet my team · CWE-79 | Medium5.4 | — | 0.5% | Sep 23, 2022 |
21Monitor | CVE-2023-23885No exploit | WordPress Quick Contact Form Plugin <= 8.0.3.1 is vulnerable to Cross Site Scripting (XSS)fullworksplugins · quick contact form · CWE-79 | Medium5.4 | — | 0.4% | Apr 7, 2023 |
21Monitor | CVE-2023-23889No exploit | WordPress Quick Paypal Payments Plugin <= 5.7.25 is vulnerable to Cross Site Scripting (XSS)fullworksplugins · quick paypal payments · CWE-79 | Medium5.4 | — | 0.4% | Apr 25, 2023 |
21Monitor | CVE-2023-23974No exploit | WordPress Quick Event Manager Plugin <= 9.7.4 is vulnerable to Cross Site Request Forgery (CSRF)fullworksplugins · quick event manager · CWE-352 | Medium5.4 | — | 0.2% | Mar 1, 2023 |
19Monitor | CVE-2023-1554No exploit | Quick Paypal Payments < 5.7.26.4 - Admin+ Stored XSSfullworksplugins · quick paypal payments · CWE-79 | Medium4.8 | — | 0.5% | May 2, 2023 |
19Monitor | CVE-2023-25702No exploit | WordPress Quick Paypal Payments Plugin <= 5.7.25 is vulnerable to Cross Site Scripting (XSS)fullworksplugins · quick paypal payments · CWE-79 | Medium4.8 | — | 0.4% | Apr 7, 2023 |
19Monitor | CVE-2022-47608No exploit | WordPress Quick Contact Form Plugin <= 8.0.3.1 is vulnerable to Cross Site Scripting (XSS)fullworksplugins · quick contact form · CWE-79 | Medium4.8 | — | 0.4% | Apr 25, 2023 |
19Monitor | CVE-2022-46863No exploit | WordPress Quick Event Manager Plugin <= 9.6.4 is vulnerable to Cross Site Scripting (XSS)fullworksplugins · quick event manager · CWE-79 | Medium4.8 | — | 0.4% | Mar 28, 2023 |
- CVE-2023-2571430Monitor
WordPress Quick Paypal Payments plugin <= 5.7.25 - Broken Access Control vulnerability
HighCVSS 7.5No exploitEPSS 1%fullworks · quick paypal paymentsDec 9, 2024
- CVE-2023-2503526Monitor
WordPress Quick Contact Form plugin <= 8.0.3.1 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 1%fullworks · quick contact formDec 9, 2024
- CVE-2017-1853625Monitor
The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.
MediumCVSS 6.1Proof of conceptEPSS 2%fullworksplugins · stop user enumerationAug 21, 2019
- CVE-2023-2349124Monitor
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' p
MediumCVSS 6.1Proof of conceptEPSS 1%fullworksplugins · quick event managerJan 20, 2023
- CVE-2023-2397924Monitor
WordPress Quick Event Manager Plugin <= 9.7.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%fullworksplugins · quick event managerApr 6, 2023
- CVE-2023-2571324Monitor
WordPress Quick Paypal Payments Plugin <= 5.7.25 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%fullworksplugins · quick paypal paymentsApr 7, 2023
- CVE-2017-100022621Monitor
Stop User Enumeration 1.3.8 allows user enumeration via the REST API
MediumCVSS 5.3No exploitEPSS 1%fullworksplugins · stop user enumerationNov 17, 2017
- CVE-2025-430221Monitor
Stop User Enumeration < 1.7.3 - Protection Bypass
MediumCVSS 5.3Proof of conceptEPSS 1%fullworksplugins · stop user enumerationJul 17, 2025
- CVE-2023-2397521Monitor
WordPress Quick Event Manager plugin <= 9.7.4 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 1%fullworks · quick event managerDec 9, 2024
- CVE-2022-3733921Monitor
WordPress Meet My Team plugin <= 2.0.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 1%fullworksplugins · meet my teamSep 23, 2022
- CVE-2023-2388521Monitor
WordPress Quick Contact Form Plugin <= 8.0.3.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%fullworksplugins · quick contact formApr 7, 2023
- CVE-2023-2388921Monitor
WordPress Quick Paypal Payments Plugin <= 5.7.25 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%fullworksplugins · quick paypal paymentsApr 25, 2023
- CVE-2023-2397421Monitor
WordPress Quick Event Manager Plugin <= 9.7.4 is vulnerable to Cross Site Request Forgery (CSRF)
MediumCVSS 5.4No exploitEPSS 0%fullworksplugins · quick event managerMar 1, 2023
- CVE-2023-155419Monitor
Quick Paypal Payments < 5.7.26.4 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%fullworksplugins · quick paypal paymentsMay 2, 2023
- CVE-2023-2570219Monitor
WordPress Quick Paypal Payments Plugin <= 5.7.25 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%fullworksplugins · quick paypal paymentsApr 7, 2023
- CVE-2022-4760819Monitor
WordPress Quick Contact Form Plugin <= 8.0.3.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%fullworksplugins · quick contact formApr 25, 2023
- CVE-2022-4686319Monitor
WordPress Quick Event Manager Plugin <= 9.6.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%fullworksplugins · quick event managerMar 28, 2023