kraftplugins records
7 published records for vendor kraftplugins.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 57.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-862 Missing Authorization2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-47311No exploit | WordPress Wheel of Life plugin <= 1.1.8 - Broken Access Control vulnerabilitykraftplugins · wheel of life · CWE-862 | Critical9.8 | — | 0.4% | Nov 1, 2024 |
21Monitor | CVE-2024-3627No exploit | Wheel of Life: Coaching and Assessment Tool for Life Coach <= 1.1.7 - Missing Authorization on Several AJAX Endpointskraftplugins · wheel of life · CWE-862 | Medium5.4 | — | 0.4% | Jun 19, 2024 |
21Monitor | CVE-2024-4702No exploit | Mega Elements <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widgetkraftplugins · mega elements · CWE-79 | Medium5.4 | — | 0.3% | May 15, 2024 |
21Monitor | CVE-2024-9172No exploit | Demo Importer Plus <= 2.0.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploadkraftplugins · demo importer plus · CWE-79 | Medium5.4 | — | 0.3% | Oct 2, 2024 |
21Monitor | CVE-2024-32575No exploit | WordPress Mega Elements plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerabilitykraftplugins · mega elements · CWE-79 | Medium5.4 | — | 0.3% | Apr 18, 2024 |
21Monitor | CVE-2024-37466No exploit | WordPress Mega Elements plugin <= 1.2.2 - Contributor+ Cross Site Scripting (XSS) vulnerabilitykraftplugins · mega elements · CWE-79 | Medium5.4 | — | 0.3% | Jul 21, 2024 |
21Monitor | CVE-2024-49693No exploit | WordPress Mega Elements – Addons for Elementor plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerabilitykraftplugins · mega elements · CWE-79 | Medium5.4 | — | 0.3% | Oct 24, 2024 |
- CVE-2024-4731139Monitor
WordPress Wheel of Life plugin <= 1.1.8 - Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 0%kraftplugins · wheel of lifeNov 1, 2024
- CVE-2024-362721Monitor
Wheel of Life: Coaching and Assessment Tool for Life Coach <= 1.1.7 - Missing Authorization on Several AJAX Endpoints
MediumCVSS 5.4No exploitEPSS 0%kraftplugins · wheel of lifeJun 19, 2024
- CVE-2024-470221Monitor
Mega Elements <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget
MediumCVSS 5.4No exploitEPSS 0%kraftplugins · mega elementsMay 15, 2024
- CVE-2024-917221Monitor
Demo Importer Plus <= 2.0.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
MediumCVSS 5.4No exploitEPSS 0%kraftplugins · demo importer plusOct 2, 2024
- CVE-2024-3257521Monitor
WordPress Mega Elements plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%kraftplugins · mega elementsApr 18, 2024
- CVE-2024-3746621Monitor
WordPress Mega Elements plugin <= 1.2.2 - Contributor+ Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%kraftplugins · mega elementsJul 21, 2024
- CVE-2024-4969321Monitor
WordPress Mega Elements – Addons for Elementor plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%kraftplugins · mega elementsOct 24, 2024