webfactoryltd records
27 published records for vendor webfactoryltd.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 11.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-862 Missing Authorization5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-639 Authorization Bypass Through User-Controlled Key2
- CWE-330 Use of Insufficiently Random Values1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2020-7048Proof of concept | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the databaswebfactoryltd · wp database reset · CWE-306 | Critical9.1 | — | 22.9% | Jan 16, 2020 |
36Monitor | CVE-2020-7047No exploit | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the abilitywebfactoryltd · wp database reset · CWE-269 | High8.8 | — | 2.5% | Jan 16, 2020 |
36Monitor | CVE-2019-19915No exploit | The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delwebfactoryltd · 301 redirects · CWE-352 | Critical9.0 | — | 0.9% | Dec 19, 2019 |
35Monitor | CVE-2020-6167No exploit | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, injectwebfactoryltd · minimal coming soon \& maintenance mode · CWE-352 | High8.8 | — | 0.9% | Jan 9, 2020 |
35Monitor | CVE-2021-36908No exploit | WordPress WP Reset PRO Premium Plugin <= 5.98 - Cross-Site Request Forgery (CSRF) vulnerabilitywebfactoryltd · wp reset pro · CWE-352 | High8.8 | — | 0.7% | Nov 18, 2021 |
33Monitor | CVE-2021-36909No exploit | WordPress WP Reset PRO Premium plugin <= 5.98 - Authenticated Database Reset vulnerabilitywebfactoryltd · wp reset pro · CWE-284 | High8.1 | — | 1.9% | Nov 18, 2021 |
31Monitor | CVE-2020-6168No exploit | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable webfactoryltd · minimal coming soon \& maintenance mode · CWE-862 | High7.6 | — | 2.0% | Jan 9, 2020 |
28Monitor | CVE-2021-24142No exploit | 301 Redirects - Easy Redirect Manager < 2.51 - Authenticated SQL Injectionwebfactoryltd · 301 redirects · CWE-89 | High7.2 | — | 1.2% | Mar 18, 2021 |
28Monitor | CVE-2023-50837No exploit | WordPress Login Lockdown Plugin <= 2.06 is vulnerable to SQL Injectionwebfactoryltd · wp login lockdown · CWE-89 | High7.2 | — | 0.6% | Dec 29, 2023 |
26Monitor | CVE-2022-1583No exploit | External Links in New Window / New Tab < 1.43 - Tabnabbingwebfactoryltd · external links in new window \/ new tab · CWE-1022 | Medium6.5 | — | 1.3% | May 30, 2022 |
24Monitor | CVE-2022-1582No exploit | External Links in New Window / New Tab < 1.43 - Unauthenticated Stored Cross-Site Scriptingwebfactoryltd · external links in new window \/ new tab · CWE-79 | Medium6.1 | — | 0.8% | May 30, 2022 |
23Monitor | CVE-2023-6799No exploit | WP Reset <= 2.0 - Sensitive Information Exposure due to Insufficient Randomnesswebfactoryltd · wp reset · CWE-330 | Medium5.9 | — | 0.7% | Apr 9, 2024 |
21Monitor | CVE-2020-6166No exploit | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export webfactoryltd · minimal coming soon \& maintenance mode · CWE-276 | Medium5.4 | — | 1.1% | Jan 9, 2020 |
21Monitor | CVE-2024-1075No exploit | Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypasswebfactoryltd · minimal coming soon \& maintenance mode · CWE-639 | Medium5.3 | — | 0.7% | Feb 5, 2024 |
21Monitor | CVE-2021-24424No exploit | WP Reset < 1.90 - Authenticated Stored XSSwebfactoryltd · wp reset · CWE-79 | Medium5.4 | — | 0.6% | Jul 12, 2021 |
21Monitor | CVE-2024-5087No exploit | Minimal Coming Soon – Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Changewebfactoryltd · minimal coming soon \& maintenance mode · CWE-862 | Medium5.4 | — | 0.4% | Jun 8, 2024 |
21Monitor | CVE-2024-1340No exploit | Login Lockdown – Protect Login Form <= 2.08 - Missing Authorizationwebfactoryltd · wp login lockdown · CWE-862 | Medium5.4 | — | 0.4% | Feb 28, 2024 |
21Monitor | CVE-2023-49747No exploit | WordPress Guest Author Plugin <= 2.3 is vulnerable to Cross Site Scripting (XSS)webfactoryltd · guest author · CWE-79 | Medium5.4 | — | 0.4% | Dec 15, 2023 |
21Monitor | CVE-2025-1262No exploit | Advanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA Bypasswebfactoryltd · advanced google recaptcha · CWE-804 | Medium5.3 | — | 0.3% | Feb 25, 2025 |
19Monitor | CVE-2021-24533No exploit | Maintenance < 4.03 - Authenticated Stored XSSwebfactoryltd · maintenance · CWE-79 | Medium4.8 | — | 0.6% | Aug 23, 2021 |
19Monitor | CVE-2023-1913No exploit | Maps Widget for Google Maps <= 4.24 - Authenticated (Administrator+) Stored Cross-Site Scriptingwebfactoryltd · maps widget for google maps · CWE-79 | Medium4.8 | — | 0.4% | Apr 6, 2023 |
18Monitor | CVE-2024-1501No exploit | Database Reset <= 3.22 - Cross-Site Request Forgery to WP Reset Plugin Installationwebfactoryltd · wp database reset · CWE-352 | Medium4.7 | — | 0.3% | Feb 21, 2024 |
17Monitor | CVE-2023-3601No exploit | Simple Author Box < 2.52 - Contributor+ Arbitrary User Information Disclosure via IDORwebfactoryltd · simple author box · CWE-639 | Medium4.3 | — | 0.5% | Aug 14, 2023 |
17Monitor | CVE-2024-5770No exploit | WP Force SSL & HTTPS SSL Redirect <= 1.66 - Missing Authorization to Settings Updatewebfactoryltd · wp force ssl · CWE-862 | Medium4.3 | — | 0.3% | Jun 8, 2024 |
17Monitor | CVE-2024-4661No exploit | WP Reset <= 2.02 - Missing Authorization to License Key Modificationwebfactoryltd · wp reset · CWE-862 | Medium4.3 | — | 0.3% | Jun 8, 2024 |
- CVE-2020-704843Plan
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the databas
CriticalCVSS 9.1Proof of conceptEPSS 23%webfactoryltd · wp database resetJan 16, 2020
- CVE-2020-704736Monitor
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability
HighCVSS 8.8No exploitEPSS 2%webfactoryltd · wp database resetJan 16, 2020
- CVE-2019-1991536Monitor
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, del
CriticalCVSS 9.0No exploitEPSS 1%webfactoryltd · 301 redirectsDec 19, 2019
- CVE-2020-616735Monitor
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject
HighCVSS 8.8No exploitEPSS 1%webfactoryltd · minimal coming soon \& maintenance modeJan 9, 2020
- CVE-2021-3690835Monitor
WordPress WP Reset PRO Premium Plugin <= 5.98 - Cross-Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 1%webfactoryltd · wp reset proNov 18, 2021
- CVE-2021-3690933Monitor
WordPress WP Reset PRO Premium plugin <= 5.98 - Authenticated Database Reset vulnerability
HighCVSS 8.1No exploitEPSS 2%webfactoryltd · wp reset proNov 18, 2021
- CVE-2020-616831Monitor
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable
HighCVSS 7.6No exploitEPSS 2%webfactoryltd · minimal coming soon \& maintenance modeJan 9, 2020
- CVE-2021-2414228Monitor
301 Redirects - Easy Redirect Manager < 2.51 - Authenticated SQL Injection
HighCVSS 7.2No exploitEPSS 1%webfactoryltd · 301 redirectsMar 18, 2021
- CVE-2023-5083728Monitor
WordPress Login Lockdown Plugin <= 2.06 is vulnerable to SQL Injection
HighCVSS 7.2No exploitEPSS 1%webfactoryltd · wp login lockdownDec 29, 2023
- CVE-2022-158326Monitor
External Links in New Window / New Tab < 1.43 - Tabnabbing
MediumCVSS 6.5No exploitEPSS 1%webfactoryltd · external links in new window \/ new tabMay 30, 2022
- CVE-2022-158224Monitor
External Links in New Window / New Tab < 1.43 - Unauthenticated Stored Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%webfactoryltd · external links in new window \/ new tabMay 30, 2022
- CVE-2023-679923Monitor
WP Reset <= 2.0 - Sensitive Information Exposure due to Insufficient Randomness
MediumCVSS 5.9No exploitEPSS 1%webfactoryltd · wp resetApr 9, 2024
- CVE-2020-616621Monitor
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export
MediumCVSS 5.4No exploitEPSS 1%webfactoryltd · minimal coming soon \& maintenance modeJan 9, 2020
- CVE-2024-107521Monitor
Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypass
MediumCVSS 5.3No exploitEPSS 1%webfactoryltd · minimal coming soon \& maintenance modeFeb 5, 2024
- CVE-2021-2442421Monitor
WP Reset < 1.90 - Authenticated Stored XSS
MediumCVSS 5.4No exploitEPSS 1%webfactoryltd · wp resetJul 12, 2021
- CVE-2024-508721Monitor
Minimal Coming Soon – Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Change
MediumCVSS 5.4No exploitEPSS 0%webfactoryltd · minimal coming soon \& maintenance modeJun 8, 2024
- CVE-2024-134021Monitor
Login Lockdown – Protect Login Form <= 2.08 - Missing Authorization
MediumCVSS 5.4No exploitEPSS 0%webfactoryltd · wp login lockdownFeb 28, 2024
- CVE-2023-4974721Monitor
WordPress Guest Author Plugin <= 2.3 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%webfactoryltd · guest authorDec 15, 2023
- CVE-2025-126221Monitor
Advanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA Bypass
MediumCVSS 5.3No exploitEPSS 0%webfactoryltd · advanced google recaptchaFeb 25, 2025
- CVE-2021-2453319Monitor
Maintenance < 4.03 - Authenticated Stored XSS
MediumCVSS 4.8No exploitEPSS 1%webfactoryltd · maintenanceAug 23, 2021
- CVE-2023-191319Monitor
Maps Widget for Google Maps <= 4.24 - Authenticated (Administrator+) Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 0%webfactoryltd · maps widget for google mapsApr 6, 2023
- CVE-2024-150118Monitor
Database Reset <= 3.22 - Cross-Site Request Forgery to WP Reset Plugin Installation
MediumCVSS 4.7No exploitEPSS 0%webfactoryltd · wp database resetFeb 21, 2024
- CVE-2023-360117Monitor
Simple Author Box < 2.52 - Contributor+ Arbitrary User Information Disclosure via IDOR
MediumCVSS 4.3No exploitEPSS 1%webfactoryltd · simple author boxAug 14, 2023
- CVE-2024-577017Monitor
WP Force SSL & HTTPS SSL Redirect <= 1.66 - Missing Authorization to Settings Update
MediumCVSS 4.3No exploitEPSS 0%webfactoryltd · wp force sslJun 8, 2024
- CVE-2024-466117Monitor
WP Reset <= 2.02 - Missing Authorization to License Key Modification
MediumCVSS 4.3No exploitEPSS 0%webfactoryltd · wp resetJun 8, 2024