Skip to content
Noroxi

kraftplugins records

7 published records for vendor kraftplugins.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
57.1%
Median publish → KEV
No record has entered KEV

Records by year

  1. 24

Bar: total · dark part: CISA KEV.

All records

7 records
  • WordPress Wheel of Life plugin <= 1.1.8 - Broken Access Control vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    kraftplugins · wheel of lifeNov 1, 2024

  • CVE-2024-3627
    21Monitor

    Wheel of Life: Coaching and Assessment Tool for Life Coach <= 1.1.7 - Missing Authorization on Several AJAX Endpoints

    MediumCVSS 5.4No exploitEPSS 0%

    kraftplugins · wheel of lifeJun 19, 2024

  • CVE-2024-4702
    21Monitor

    Mega Elements <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget

    MediumCVSS 5.4No exploitEPSS 0%

    kraftplugins · mega elementsMay 15, 2024

  • CVE-2024-9172
    21Monitor

    Demo Importer Plus <= 2.0.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

    MediumCVSS 5.4No exploitEPSS 0%

    kraftplugins · demo importer plusOct 2, 2024

  • WordPress Mega Elements plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    kraftplugins · mega elementsApr 18, 2024

  • WordPress Mega Elements plugin <= 1.2.2 - Contributor+ Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    kraftplugins · mega elementsJul 21, 2024

  • WordPress Mega Elements – Addons for Elementor plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    kraftplugins · mega elementsOct 24, 2024