roninwp records
4 published records for vendor roninwp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-54214No exploit | WordPress Revy plugin <= 1.18 - Unauthenticated Arbitrary File Upload vulnerabilityroninwp · revy · CWE-434 | Critical10.0 | — | 0.7% | Dec 6, 2024 |
37Monitor | CVE-2024-54215No exploit | WordPress Revy plugin <= 1.18 - Unauthenticated SQL Injection vulnerabilityroninwp · revy · CWE-89 | Critical9.3 | — | 0.6% | Dec 9, 2024 |
37Monitor | CVE-2024-54221No exploit | WordPress FAT Services Booking plugin <= 5.6 - Unauthenticated SQL Injection vulnerabilityroninwp · fat services booking · CWE-89 | Critical9.3 | — | 0.4% | Dec 4, 2024 |
34Monitor | CVE-2025-32924No exploit | WordPress Revy plugin <= 2.1 - SQL Injection vulnerabilityroninwp · revy · CWE-89 | High8.5 | — | 0.3% | May 19, 2025 |
- CVE-2024-5421440Plan
WordPress Revy plugin <= 1.18 - Unauthenticated Arbitrary File Upload vulnerability
CriticalCVSS 10.0No exploitEPSS 1%roninwp · revyDec 6, 2024
- CVE-2024-5421537Monitor
WordPress Revy plugin <= 1.18 - Unauthenticated SQL Injection vulnerability
CriticalCVSS 9.3No exploitEPSS 1%roninwp · revyDec 9, 2024
- CVE-2024-5422137Monitor
WordPress FAT Services Booking plugin <= 5.6 - Unauthenticated SQL Injection vulnerability
CriticalCVSS 9.3No exploitEPSS 0%roninwp · fat services bookingDec 4, 2024
- CVE-2025-3292434Monitor
WordPress Revy plugin <= 2.1 - SQL Injection vulnerability
HighCVSS 8.5No exploitEPSS 0%roninwp · revyMay 19, 2025