warfareplugins records
6 published records for vendor warfareplugins.
Researcher profile
- Entered KEV
- 1 · 16.7%
- Weaponized
- 1 · 16.7%
- Pre-auth RCE
- 1
- With a fix record
- 16.7%
- Median publish → KEV
- 955 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-506 Embedded Malicious Code1
- CWE-862 Missing Authorization1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
76This week | CVE-2019-9978Weaponized | The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameterwarfareplugins · social warfare · CWE-79 | Medium6.1 | KEV | 72.9% | Mar 24, 2019 |
40Plan | CVE-2021-4434No exploit | Social Warfare <= 3.5.2 - Remote Code Executionwarfareplugins · social warfare · CWE-94 | Critical9.8 | — | 1.9% | Jan 17, 2024 |
40Plan | CVE-2024-6297Proof of concept | Several WordPress.org Plugins <= Various Versions - Injected Backdoorwarfareplugins · social sharing plugin – social warfare · CWE-506 | Critical10.0 | — | 1.0% | Jun 25, 2024 |
21Monitor | CVE-2023-0402No exploit | Social Warfare <= 4.3.0 - Missing Authorizationwarfareplugins · social warfare · CWE-862 | Medium5.4 | — | 0.8% | Jan 19, 2023 |
21Monitor | CVE-2023-4842Proof of concept | Social Sharing Plugin - Social Warfare <= 4.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodewarfareplugins · social warfare · CWE-79 | Medium5.4 | — | 0.6% | Nov 7, 2023 |
21Monitor | CVE-2023-0403No exploit | Social Warfare <= 4.3.1 - Cross-Site Request Forgerywarfareplugins · social warfare · CWE-352 | Medium5.4 | — | 0.4% | Jan 19, 2023 |
- CVE-2019-997876This week
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter
MediumCVSS 6.1KEVWeaponizedEPSS 73%warfareplugins · social warfareMar 24, 2019
- CVE-2021-443440Plan
Social Warfare <= 3.5.2 - Remote Code Execution
CriticalCVSS 9.8No exploitEPSS 2%warfareplugins · social warfareJan 17, 2024
- CVE-2024-629740Plan
Several WordPress.org Plugins <= Various Versions - Injected Backdoor
CriticalCVSS 10.0Proof of conceptEPSS 1%warfareplugins · social sharing plugin – social warfareJun 25, 2024
- CVE-2023-040221Monitor
Social Warfare <= 4.3.0 - Missing Authorization
MediumCVSS 5.4No exploitEPSS 1%warfareplugins · social warfareJan 19, 2023
- CVE-2023-484221Monitor
Social Sharing Plugin - Social Warfare <= 4.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4Proof of conceptEPSS 1%warfareplugins · social warfareNov 7, 2023
- CVE-2023-040321Monitor
Social Warfare <= 4.3.1 - Cross-Site Request Forgery
MediumCVSS 5.4No exploitEPSS 0%warfareplugins · social warfareJan 19, 2023