plugingarden records
3 published records for vendor plugingarden.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-8436No exploit | WP Easy Gallery – WordPress Gallery Plugin <= 4.8.5 - Authenticated (Subscriber+) SQL Injectionplugingarden · wp easy gallery · CWE-89 | Critical9.9 | — | 0.5% | Sep 24, 2024 |
35Monitor | CVE-2024-9018No exploit | WP Easy Gallery <= 4.8.5 - Authenticated (Contributor+) SQL Injection via key Parameterplugingarden · wp easy gallery · CWE-89 | High8.8 | — | 0.5% | Oct 1, 2024 |
17Monitor | CVE-2024-8437No exploit | WP Easy Gallery – WordPress Gallery Plugin <= 4.8.5 - Missing Authorization to Authenticated (Subscriber+) Gallery Manipulationplugingarden · wp easy gallery · CWE-862 | Medium4.3 | — | 0.3% | Sep 24, 2024 |
- CVE-2024-843639Monitor
WP Easy Gallery – WordPress Gallery Plugin <= 4.8.5 - Authenticated (Subscriber+) SQL Injection
CriticalCVSS 9.9No exploitEPSS 0%plugingarden · wp easy gallerySep 24, 2024
- CVE-2024-901835Monitor
WP Easy Gallery <= 4.8.5 - Authenticated (Contributor+) SQL Injection via key Parameter
HighCVSS 8.8No exploitEPSS 1%plugingarden · wp easy galleryOct 1, 2024
- CVE-2024-843717Monitor
WP Easy Gallery – WordPress Gallery Plugin <= 4.8.5 - Missing Authorization to Authenticated (Subscriber+) Gallery Manipulation
MediumCVSS 4.3No exploitEPSS 0%plugingarden · wp easy gallerySep 24, 2024