LWS records
6 published records for vendor lws.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2023-32297No exploit | WordPress LWS Affiliation plugin <= 2.2.6 - Local File Inclusion vulnerabilitylws · lws affiliation · CWE-22 | Critical9.0 | — | 0.8% | May 17, 2024 |
35Monitor | CVE-2024-43962No exploit | WordPress LWS Affiliation plugin <= 2.3.4 - Broken Access Control vulnerabilitylws · affiliation · CWE-862 | High8.8 | — | 0.5% | Nov 1, 2024 |
35Monitor | CVE-2023-27453No exploit | WordPress LWS Tools Plugin <= 2.3.1 is vulnerable to Cross Site Request Forgery (CSRF)lws · lws tools · CWE-352 | High8.8 | — | 0.3% | Nov 22, 2023 |
35Monitor | CVE-2023-34025No exploit | WordPress LWS Hide Login Plugin <= 2.1.6 is vulnerable to Cross Site Request Forgery (CSRF)lws · lws hide login · CWE-352 | High8.8 | — | 0.3% | Nov 9, 2023 |
35Monitor | CVE-2023-35774No exploit | WordPress LWS Tools Plugin <= 2.4.1 is vulnerable to Cross Site Request Forgery (CSRF)lws · lws tools · CWE-352 | High8.8 | — | 0.2% | Jul 11, 2023 |
35Monitor | CVE-2023-35781No exploit | WordPress LWS Cleaner Plugin <= 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)lws · lws cleaner · CWE-352 | High8.8 | — | 0.2% | Jul 11, 2023 |
- CVE-2023-3229736Monitor
WordPress LWS Affiliation plugin <= 2.2.6 - Local File Inclusion vulnerability
CriticalCVSS 9.0No exploitEPSS 1%lws · lws affiliationMay 17, 2024
- CVE-2024-4396235Monitor
WordPress LWS Affiliation plugin <= 2.3.4 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%lws · affiliationNov 1, 2024
- CVE-2023-2745335Monitor
WordPress LWS Tools Plugin <= 2.3.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%lws · lws toolsNov 22, 2023
- CVE-2023-3402535Monitor
WordPress LWS Hide Login Plugin <= 2.1.6 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%lws · lws hide loginNov 9, 2023
- CVE-2023-3577435Monitor
WordPress LWS Tools Plugin <= 2.4.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%lws · lws toolsJul 11, 2023
- CVE-2023-3578135Monitor
WordPress LWS Cleaner Plugin <= 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%lws · lws cleanerJul 11, 2023