Skip to content
Noroxi

warfareplugins records

6 published records for vendor warfareplugins.

Researcher profile

Entered KEV
1 · 16.7%
Weaponized
1 · 16.7%
Pre-auth RCE
1
With a fix record
16.7%
Median publish → KEV
955 days

All records

6 records
  • CVE-2019-9978
    76This week

    The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter

    MediumCVSS 6.1KEVWeaponizedEPSS 73%

    warfareplugins · social warfareMar 24, 2019

  • Social Warfare <= 3.5.2 - Remote Code Execution

    CriticalCVSS 9.8No exploitEPSS 2%

    warfareplugins · social warfareJan 17, 2024

  • Several WordPress.org Plugins <= Various Versions - Injected Backdoor

    CriticalCVSS 10.0Proof of conceptEPSS 1%

    warfareplugins · social sharing plugin – social warfareJun 25, 2024

  • CVE-2023-0402
    21Monitor

    Social Warfare <= 4.3.0 - Missing Authorization

    MediumCVSS 5.4No exploitEPSS 1%

    warfareplugins · social warfareJan 19, 2023

  • CVE-2023-4842
    21Monitor

    Social Sharing Plugin - Social Warfare <= 4.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    MediumCVSS 5.4Proof of conceptEPSS 1%

    warfareplugins · social warfareNov 7, 2023

  • CVE-2023-0403
    21Monitor

    Social Warfare <= 4.3.1 - Cross-Site Request Forgery

    MediumCVSS 5.4No exploitEPSS 0%

    warfareplugins · social warfareJan 19, 2023