smackcoders records
24 published records for vendor smackcoders.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 4.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-862 Missing Authorization3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-11000No exploit | The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.smackcoders · ultimate exporter · CWE-89 | Critical9.8 | — | 2.1% | Sep 20, 2019 |
40Plan | CVE-2024-43965Proof of concept | WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerabilitysmackcoders · sendgrid · CWE-89 | Critical9.8 | — | 2.0% | Aug 29, 2024 |
35Monitor | CVE-2023-4141No exploit | WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Executionsmackcoders · wp ultimate csv importer · CWE-94 | High8.8 | — | 1.6% | Aug 3, 2023 |
35Monitor | CVE-2023-4142No exploit | WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Executionsmackcoders · wp ultimate csv importer · CWE-94 | High8.8 | — | 1.6% | Aug 3, 2023 |
35Monitor | CVE-2022-3860No exploit | Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLismackcoders · visual email designer for woocommerce · CWE-89 | High8.8 | — | 0.9% | Jan 2, 2023 |
35Monitor | CVE-2023-4140No exploit | WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalationsmackcoders · wp ultimate csv importer · CWE-269 | High8.8 | — | 0.8% | Aug 3, 2023 |
35Monitor | CVE-2018-20967No exploit | The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-352 | High8.8 | — | 0.6% | Aug 14, 2019 |
35Monitor | CVE-2018-20968No exploit | The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.smackcoders · ultimate exporter · CWE-352 | High8.8 | — | 0.6% | Aug 14, 2019 |
35Monitor | CVE-2015-10125No exploit | WP Ultimate CSV Importer Plugin cross-site request forgerysmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-352 | High8.8 | — | 0.4% | Oct 5, 2023 |
30Monitor | CVE-2023-4139No exploit | WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listingsmackcoders · wp ultimate csv importer · CWE-200 | High7.5 | — | 0.7% | Aug 3, 2023 |
30Monitor | CVE-2023-45066No exploit | WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposuresmackcoders · export all posts\, products\, orders\, refunds \& users · CWE-200 | High7.5 | — | 0.5% | Nov 30, 2023 |
30Monitor | CVE-2024-12315No exploit | Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directorysmackcoders · export all posts\, products\, orders\, refunds \& users · CWE-922 | High7.5 | — | 0.5% | Feb 12, 2025 |
30Monitor | CVE-2023-2487No exploit | WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposuresmackcoders · export all posts\, products\, orders\, refunds \& users · CWE-200 | High7.5 | — | 0.5% | Dec 21, 2023 |
28Monitor | CVE-2022-1977No exploit | WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRFsmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-918 | High7.2 | — | 1.3% | Jun 27, 2022 |
28Monitor | CVE-2022-3243No exploit | Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLismackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-89 | High7.2 | — | 1.1% | Oct 17, 2022 |
26Monitor | CVE-2013-3264No exploit | The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2smackcoders · wp ultimate email marketer plugin · CWE-264 | Medium6.4 | — | 2.1% | Nov 5, 2013 |
24Monitor | CVE-2016-10985No exploit | The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.smackcoders · echo sign · CWE-79 | Medium6.1 | — | 1.4% | Sep 17, 2019 |
24Monitor | CVE-2016-10984No exploit | The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.smackcoders · echo sign · CWE-79 | Medium6.1 | — | 1.4% | Sep 17, 2019 |
24Monitor | CVE-2015-9306No exploit | The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-79 | Medium6.1 | — | 1.0% | Aug 12, 2019 |
19Monitor | CVE-2022-0360No exploit | WP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site Scriptingsmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-79 | Medium4.8 | — | 0.6% | Feb 28, 2022 |
17Monitor | CVE-2013-3263No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow smackcoders · wp ultimate email marketer plugin · CWE-79 | Medium4.3 | — | 1.6% | Nov 5, 2013 |
17Monitor | CVE-2024-9364No exploit | SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletionsmackcoders · sendgrid · CWE-862 | Medium4.3 | — | 0.4% | Oct 18, 2024 |
17Monitor | CVE-2025-5692No exploit | Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actionssmackcoders · lead form data collection to crm · CWE-862 | Medium4.3 | — | 0.2% | Jul 1, 2025 |
16Monitor | CVE-2022-3244No exploit | Import all XML, CSV & TXT into WordPress < 6.5.8 - Missing Authorisationsmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-862 | Medium4.2 | — | 0.4% | Oct 17, 2022 |
- CVE-2016-1100040Plan
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
CriticalCVSS 9.8No exploitEPSS 2%smackcoders · ultimate exporterSep 20, 2019
- CVE-2024-4396540Plan
WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 2%smackcoders · sendgridAug 29, 2024
- CVE-2023-414135Monitor
WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Execution
HighCVSS 8.8No exploitEPSS 2%smackcoders · wp ultimate csv importerAug 3, 2023
- CVE-2023-414235Monitor
WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Execution
HighCVSS 8.8No exploitEPSS 2%smackcoders · wp ultimate csv importerAug 3, 2023
- CVE-2022-386035Monitor
Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLi
HighCVSS 8.8No exploitEPSS 1%smackcoders · visual email designer for woocommerceJan 2, 2023
- CVE-2023-414035Monitor
WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalation
HighCVSS 8.8No exploitEPSS 1%smackcoders · wp ultimate csv importerAug 3, 2023
- CVE-2018-2096735Monitor
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
HighCVSS 8.8No exploitEPSS 1%smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvAug 14, 2019
- CVE-2018-2096835Monitor
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
HighCVSS 8.8No exploitEPSS 1%smackcoders · ultimate exporterAug 14, 2019
- CVE-2015-1012535Monitor
WP Ultimate CSV Importer Plugin cross-site request forgery
HighCVSS 8.8No exploitEPSS 0%smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvOct 5, 2023
- CVE-2023-413930Monitor
WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listing
HighCVSS 7.5No exploitEPSS 1%smackcoders · wp ultimate csv importerAug 3, 2023
- CVE-2023-4506630Monitor
WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure
HighCVSS 7.5No exploitEPSS 1%smackcoders · export all posts\, products\, orders\, refunds \& usersNov 30, 2023
- CVE-2024-1231530Monitor
Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directory
HighCVSS 7.5No exploitEPSS 0%smackcoders · export all posts\, products\, orders\, refunds \& usersFeb 12, 2025
- CVE-2023-248730Monitor
WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure
HighCVSS 7.5No exploitEPSS 0%smackcoders · export all posts\, products\, orders\, refunds \& usersDec 21, 2023
- CVE-2022-197728Monitor
WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRF
HighCVSS 7.2No exploitEPSS 1%smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvJun 27, 2022
- CVE-2022-324328Monitor
Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLi
HighCVSS 7.2No exploitEPSS 1%smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvOct 17, 2022
- CVE-2013-326426Monitor
The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2
MediumCVSS 6.4No exploitEPSS 2%smackcoders · wp ultimate email marketer pluginNov 5, 2013
- CVE-2016-1098524Monitor
The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.
MediumCVSS 6.1No exploitEPSS 1%smackcoders · echo signSep 17, 2019
- CVE-2016-1098424Monitor
The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.
MediumCVSS 6.1No exploitEPSS 1%smackcoders · echo signSep 17, 2019
- CVE-2015-930624Monitor
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
MediumCVSS 6.1No exploitEPSS 1%smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvAug 12, 2019
- CVE-2022-036019Monitor
WP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 1%smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvFeb 28, 2022
- CVE-2013-326317Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow
MediumCVSS 4.3No exploitEPSS 2%smackcoders · wp ultimate email marketer pluginNov 5, 2013
- CVE-2024-936417Monitor
SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletion
MediumCVSS 4.3No exploitEPSS 0%smackcoders · sendgridOct 18, 2024
- CVE-2025-569217Monitor
Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actions
MediumCVSS 4.3No exploitEPSS 0%smackcoders · lead form data collection to crmJul 1, 2025
- CVE-2022-324416Monitor
Import all XML, CSV & TXT into WordPress < 6.5.8 - Missing Authorisation
MediumCVSS 4.2No exploitEPSS 0%smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvOct 17, 2022