GeneratePress records
5 published records for vendor generatepress.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-863 Incorrect Authorization2
- CWE-285 Improper Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
24Monitor | CVE-2024-3469Proof of concept | GP Premium <= 2.4.0 - Reflected Cross-Site Scriptinggeneratepress · generatepress · CWE-79 | Medium6.1 | — | 0.6% | Jun 5, 2024 |
21Monitor | CVE-2024-1479No exploit | WP Show Posts <= 1.1.4 - Information Exposuregeneratepress · wp show posts · CWE-863 | Medium5.3 | — | 0.7% | Mar 13, 2024 |
21Monitor | CVE-2023-6807No exploit | GeneratePress Premium <= 2.3.2 - Authenticated(Contributor+) Stored Cross-Site Scripting via Custom Metageneratepress · generatepress · CWE-79 | Medium5.4 | — | 0.5% | Feb 5, 2024 |
17Monitor | CVE-2024-1452No exploit | GenerateBlocks <= 1.8.2 - Sensitive Information Exposuregeneratepress · generateblocks · CWE-863 | Medium4.3 | — | 0.6% | Mar 13, 2024 |
17Monitor | CVE-2023-6731No exploit | WP Show Posts <= 1.1.5 - Improper Authorization to Information Exposuregeneratepress · wp show posts · CWE-285 | Medium4.3 | — | 0.4% | May 2, 2024 |
- CVE-2024-346924Monitor
GP Premium <= 2.4.0 - Reflected Cross-Site Scripting
MediumCVSS 6.1Proof of conceptEPSS 1%generatepress · generatepressJun 5, 2024
- CVE-2024-147921Monitor
WP Show Posts <= 1.1.4 - Information Exposure
MediumCVSS 5.3No exploitEPSS 1%generatepress · wp show postsMar 13, 2024
- CVE-2023-680721Monitor
GeneratePress Premium <= 2.3.2 - Authenticated(Contributor+) Stored Cross-Site Scripting via Custom Meta
MediumCVSS 5.4No exploitEPSS 0%generatepress · generatepressFeb 5, 2024
- CVE-2024-145217Monitor
GenerateBlocks <= 1.8.2 - Sensitive Information Exposure
MediumCVSS 4.3No exploitEPSS 1%generatepress · generateblocksMar 13, 2024
- CVE-2023-673117Monitor
WP Show Posts <= 1.1.5 - Improper Authorization to Information Exposure
MediumCVSS 4.3No exploitEPSS 0%generatepress · wp show postsMay 2, 2024