WebCodingPlace records
9 published records for vendor webcodingplace.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-269 Improper Privilege Management1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-13753No exploit | Ultimate Classified Listings <= 1.5 - Cross-Site Request Forgery to Account Takeoverwebcodingplace · ultimate classified listings · CWE-352 | High8.8 | — | 0.3% | Feb 20, 2025 |
30Monitor | CVE-2024-11952No exploit | Classic Addons – WPBakery Page Builder <= 3.0 - Authenticated (Contributor+) Limited Local PHP File Inclusionwebcodingplace · classic addons – wpbakery page builder · CWE-22 | High7.5 | — | 0.9% | Dec 4, 2024 |
30Monitor | CVE-2024-5882No exploit | Ultimate Classified Listings < 1.3 - Unauthenticated LFIwebcodingplace · ultimate classified listings · CWE-22 | High7.5 | — | 0.8% | Jul 29, 2024 |
30Monitor | CVE-2024-52448No exploit | WordPress Ultimate Classified Listings plugin <= 1.7 - Local File Inclusion vulnerabilitywebcodingplace · ultimate classified listings · CWE-22 | High7.5 | — | 0.6% | Nov 20, 2024 |
28Monitor | CVE-2024-6529Proof of concept | Ultimate Classified Listings < 1.4 - Reflected XSSwebcodingplace · ultimate classified listings · CWE-79 | High7.1 | — | 1.0% | Aug 1, 2024 |
26Monitor | CVE-2023-4239No exploit | Real Estate Manager <= 7.2 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalationwebcodingplace · real estate manager · CWE-269 | Medium6.5 | — | 0.8% | Aug 8, 2023 |
19Monitor | CVE-2024-13748No exploit | Ultimate Classified Listings <= 1.4 Authenticated (Administrator+) Stored Cross-Site Scripting via Title Parameterwebcodingplace · ultimate classified listings · CWE-79 | Medium4.8 | — | 0.2% | Feb 20, 2025 |
18Monitor | CVE-2024-5883No exploit | Ultimate Classified Listings < 1.3 - Reflected XSSwebcodingplace · ultimate classified listings · CWE-79 | Medium4.7 | — | 0.4% | Jul 29, 2024 |
17Monitor | CVE-2024-0201No exploit | Product Expiry for WooCommerce <= 2.5 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Updatewebcodingplace · product expiry for woocommerce · CWE-862 | Medium4.3 | — | 0.4% | Jan 3, 2024 |
- CVE-2024-1375335Monitor
Ultimate Classified Listings <= 1.5 - Cross-Site Request Forgery to Account Takeover
HighCVSS 8.8No exploitEPSS 0%webcodingplace · ultimate classified listingsFeb 20, 2025
- CVE-2024-1195230Monitor
Classic Addons – WPBakery Page Builder <= 3.0 - Authenticated (Contributor+) Limited Local PHP File Inclusion
HighCVSS 7.5No exploitEPSS 1%webcodingplace · classic addons – wpbakery page builderDec 4, 2024
- CVE-2024-588230Monitor
Ultimate Classified Listings < 1.3 - Unauthenticated LFI
HighCVSS 7.5No exploitEPSS 1%webcodingplace · ultimate classified listingsJul 29, 2024
- CVE-2024-5244830Monitor
WordPress Ultimate Classified Listings plugin <= 1.7 - Local File Inclusion vulnerability
HighCVSS 7.5No exploitEPSS 1%webcodingplace · ultimate classified listingsNov 20, 2024
- CVE-2024-652928Monitor
Ultimate Classified Listings < 1.4 - Reflected XSS
HighCVSS 7.1Proof of conceptEPSS 1%webcodingplace · ultimate classified listingsAug 1, 2024
- CVE-2023-423926Monitor
Real Estate Manager <= 7.2 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
MediumCVSS 6.5No exploitEPSS 1%webcodingplace · real estate managerAug 8, 2023
- CVE-2024-1374819Monitor
Ultimate Classified Listings <= 1.4 Authenticated (Administrator+) Stored Cross-Site Scripting via Title Parameter
MediumCVSS 4.8No exploitEPSS 0%webcodingplace · ultimate classified listingsFeb 20, 2025
- CVE-2024-588318Monitor
Ultimate Classified Listings < 1.3 - Reflected XSS
MediumCVSS 4.7No exploitEPSS 0%webcodingplace · ultimate classified listingsJul 29, 2024
- CVE-2024-020117Monitor
Product Expiry for WooCommerce <= 2.5 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update
MediumCVSS 4.3No exploitEPSS 0%webcodingplace · product expiry for woocommerceJan 3, 2024