Skip to content
Noroxi

Webcraftic records

6 published records for vendor webcraftic.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

6 records
  • admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import,

    HighCVSS 8.8Proof of conceptEPSS 18%

    webcraftic · woody ad snippetsSep 3, 2019

  • Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution

    CriticalCVSS 9.9Proof of conceptEPSS 3%

    themeisle · woody code snippets – insert php, css, js, and header/footer scriptsJun 15, 2024

  • admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action

    HighCVSS 7.5No exploitEPSS 2%

    webcraftic · woody ad snippetsAug 8, 2019

  • The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301expo

    MediumCVSS 6.1No exploitEPSS 1%

    webcraftic · simple 301 redirectsAug 30, 2019

  • The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a C

    MediumCVSS 6.1No exploitEPSS 1%

    webcraftic · simple 301 redirects-addon-bulk uploaderAug 29, 2019

  • The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.

    MediumCVSS 5.4No exploitEPSS 1%

    webcraftic · woody ad snippetsSep 13, 2019