Skip to content
Noroxi

webfactoryltd records

27 published records for vendor webfactoryltd.

All records

27 records
  • The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the databas

    CriticalCVSS 9.1Proof of conceptEPSS 23%

    webfactoryltd · wp database resetJan 16, 2020

  • CVE-2020-7047
    36Monitor

    The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability

    HighCVSS 8.8No exploitEPSS 2%

    webfactoryltd · wp database resetJan 16, 2020

  • The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, del

    CriticalCVSS 9.0No exploitEPSS 1%

    webfactoryltd · 301 redirectsDec 19, 2019

  • CVE-2020-6167
    35Monitor

    A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject

    HighCVSS 8.8No exploitEPSS 1%

    webfactoryltd · minimal coming soon \& maintenance modeJan 9, 2020

  • WordPress WP Reset PRO Premium Plugin <= 5.98 - Cross-Site Request Forgery (CSRF) vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    webfactoryltd · wp reset proNov 18, 2021

  • WordPress WP Reset PRO Premium plugin <= 5.98 - Authenticated Database Reset vulnerability

    HighCVSS 8.1No exploitEPSS 2%

    webfactoryltd · wp reset proNov 18, 2021

  • CVE-2020-6168
    31Monitor

    A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable

    HighCVSS 7.6No exploitEPSS 2%

    webfactoryltd · minimal coming soon \& maintenance modeJan 9, 2020

  • 301 Redirects - Easy Redirect Manager < 2.51 - Authenticated SQL Injection

    HighCVSS 7.2No exploitEPSS 1%

    webfactoryltd · 301 redirectsMar 18, 2021

  • WordPress Login Lockdown Plugin <= 2.06 is vulnerable to SQL Injection

    HighCVSS 7.2No exploitEPSS 1%

    webfactoryltd · wp login lockdownDec 29, 2023

  • CVE-2022-1583
    26Monitor

    External Links in New Window / New Tab < 1.43 - Tabnabbing

    MediumCVSS 6.5No exploitEPSS 1%

    webfactoryltd · external links in new window \/ new tabMay 30, 2022

  • CVE-2022-1582
    24Monitor

    External Links in New Window / New Tab < 1.43 - Unauthenticated Stored Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    webfactoryltd · external links in new window \/ new tabMay 30, 2022

  • CVE-2023-6799
    23Monitor

    WP Reset <= 2.0 - Sensitive Information Exposure due to Insufficient Randomness

    MediumCVSS 5.9No exploitEPSS 1%

    webfactoryltd · wp resetApr 9, 2024

  • CVE-2020-6166
    21Monitor

    A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export

    MediumCVSS 5.4No exploitEPSS 1%

    webfactoryltd · minimal coming soon \& maintenance modeJan 9, 2020

  • CVE-2024-1075
    21Monitor

    Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypass

    MediumCVSS 5.3No exploitEPSS 1%

    webfactoryltd · minimal coming soon \& maintenance modeFeb 5, 2024

  • WP Reset < 1.90 - Authenticated Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    webfactoryltd · wp resetJul 12, 2021

  • CVE-2024-5087
    21Monitor

    Minimal Coming Soon – Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Change

    MediumCVSS 5.4No exploitEPSS 0%

    webfactoryltd · minimal coming soon \& maintenance modeJun 8, 2024

  • CVE-2024-1340
    21Monitor

    Login Lockdown – Protect Login Form <= 2.08 - Missing Authorization

    MediumCVSS 5.4No exploitEPSS 0%

    webfactoryltd · wp login lockdownFeb 28, 2024

  • WordPress Guest Author Plugin <= 2.3 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    webfactoryltd · guest authorDec 15, 2023

  • CVE-2025-1262
    21Monitor

    Advanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA Bypass

    MediumCVSS 5.3No exploitEPSS 0%

    webfactoryltd · advanced google recaptchaFeb 25, 2025

  • Maintenance < 4.03 - Authenticated Stored XSS

    MediumCVSS 4.8No exploitEPSS 1%

    webfactoryltd · maintenanceAug 23, 2021

  • CVE-2023-1913
    19Monitor

    Maps Widget for Google Maps <= 4.24 - Authenticated (Administrator+) Stored Cross-Site Scripting

    MediumCVSS 4.8No exploitEPSS 0%

    webfactoryltd · maps widget for google mapsApr 6, 2023

  • CVE-2024-1501
    18Monitor

    Database Reset <= 3.22 - Cross-Site Request Forgery to WP Reset Plugin Installation

    MediumCVSS 4.7No exploitEPSS 0%

    webfactoryltd · wp database resetFeb 21, 2024

  • CVE-2023-3601
    17Monitor

    Simple Author Box < 2.52 - Contributor+ Arbitrary User Information Disclosure via IDOR

    MediumCVSS 4.3No exploitEPSS 1%

    webfactoryltd · simple author boxAug 14, 2023

  • CVE-2024-5770
    17Monitor

    WP Force SSL & HTTPS SSL Redirect <= 1.66 - Missing Authorization to Settings Update

    MediumCVSS 4.3No exploitEPSS 0%

    webfactoryltd · wp force sslJun 8, 2024

  • CVE-2024-4661
    17Monitor

    WP Reset <= 2.02 - Missing Authorization to License Key Modification

    MediumCVSS 4.3No exploitEPSS 0%

    webfactoryltd · wp resetJun 8, 2024