Skip to content
Noroxi

smackcoders records

24 published records for vendor smackcoders.

All records

24 records
  • The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

    CriticalCVSS 9.8No exploitEPSS 2%

    smackcoders · ultimate exporterSep 20, 2019

  • WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    smackcoders · sendgridAug 29, 2024

  • CVE-2023-4141
    35Monitor

    WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Execution

    HighCVSS 8.8No exploitEPSS 2%

    smackcoders · wp ultimate csv importerAug 3, 2023

  • CVE-2023-4142
    35Monitor

    WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Execution

    HighCVSS 8.8No exploitEPSS 2%

    smackcoders · wp ultimate csv importerAug 3, 2023

  • CVE-2022-3860
    35Monitor

    Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLi

    HighCVSS 8.8No exploitEPSS 1%

    smackcoders · visual email designer for woocommerceJan 2, 2023

  • CVE-2023-4140
    35Monitor

    WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalation

    HighCVSS 8.8No exploitEPSS 1%

    smackcoders · wp ultimate csv importerAug 3, 2023

  • The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.

    HighCVSS 8.8No exploitEPSS 1%

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvAug 14, 2019

  • The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.

    HighCVSS 8.8No exploitEPSS 1%

    smackcoders · ultimate exporterAug 14, 2019

  • WP Ultimate CSV Importer Plugin cross-site request forgery

    HighCVSS 8.8No exploitEPSS 0%

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvOct 5, 2023

  • CVE-2023-4139
    30Monitor

    WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listing

    HighCVSS 7.5No exploitEPSS 1%

    smackcoders · wp ultimate csv importerAug 3, 2023

  • WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure

    HighCVSS 7.5No exploitEPSS 1%

    smackcoders · export all posts\, products\, orders\, refunds \& usersNov 30, 2023

  • Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directory

    HighCVSS 7.5No exploitEPSS 0%

    smackcoders · export all posts\, products\, orders\, refunds \& usersFeb 12, 2025

  • CVE-2023-2487
    30Monitor

    WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure

    HighCVSS 7.5No exploitEPSS 0%

    smackcoders · export all posts\, products\, orders\, refunds \& usersDec 21, 2023

  • CVE-2022-1977
    28Monitor

    WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRF

    HighCVSS 7.2No exploitEPSS 1%

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvJun 27, 2022

  • CVE-2022-3243
    28Monitor

    Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLi

    HighCVSS 7.2No exploitEPSS 1%

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvOct 17, 2022

  • CVE-2013-3264
    26Monitor

    The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2

    MediumCVSS 6.4No exploitEPSS 2%

    smackcoders · wp ultimate email marketer pluginNov 5, 2013

  • The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    smackcoders · echo signSep 17, 2019

  • The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    smackcoders · echo signSep 17, 2019

  • CVE-2015-9306
    24Monitor

    The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvAug 12, 2019

  • CVE-2022-0360
    19Monitor

    WP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site Scripting

    MediumCVSS 4.8No exploitEPSS 1%

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvFeb 28, 2022

  • CVE-2013-3263
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow

    MediumCVSS 4.3No exploitEPSS 2%

    smackcoders · wp ultimate email marketer pluginNov 5, 2013

  • CVE-2024-9364
    17Monitor

    SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletion

    MediumCVSS 4.3No exploitEPSS 0%

    smackcoders · sendgridOct 18, 2024

  • CVE-2025-5692
    17Monitor

    Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actions

    MediumCVSS 4.3No exploitEPSS 0%

    smackcoders · lead form data collection to crmJul 1, 2025

  • CVE-2022-3244
    16Monitor

    Import all XML, CSV & TXT into WordPress < 6.5.8 - Missing Authorisation

    MediumCVSS 4.2No exploitEPSS 0%

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csvOct 17, 2022