WPBrigade records
10 published records for vendor wpbrigade.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 20%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-15872No exploit | The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.wpbrigade · loginpress · CWE-89 | Critical9.8 | — | 2.2% | Sep 3, 2019 |
24Monitor | CVE-2022-0347No exploit | LoginPress < 1.5.12 - Reflected Cross-Site Scriptingwpbrigade · loginpress · CWE-79 | Medium6.1 | — | 0.8% | Mar 7, 2022 |
21Monitor | CVE-2021-24486No exploit | Simple Social Media Share Buttons < 3.2.3 - Contributor+ Stored XSSwpbrigade · simple social media share buttons · CWE-79 | Medium5.4 | — | 0.6% | Aug 23, 2021 |
21Monitor | CVE-2023-5845No exploit | Simple Social Buttons < 5.1.1 - Unauthenticated Password Protected Post Accesswpbrigade · simple social buttons · CWE-287 | Medium5.3 | — | 0.6% | Nov 27, 2023 |
21Monitor | CVE-2022-4625No exploit | Login Logout Menu < 1.4.0 - Contributor+ Stored XSS in Shortcodewpbrigade · login logout menu · CWE-79 | Medium5.4 | — | 0.5% | Jan 23, 2023 |
21Monitor | CVE-2022-41839No exploit | WordPress LoginPress plugin <= 1.6.2 - Broken Access Control vulnerabilitywpbrigade · loginpress · CWE-264 | Medium5.3 | — | 0.5% | Nov 18, 2022 |
21Monitor | CVE-2022-4622No exploit | Login Logout Menu <= 1.3.3 - Contributor+ Stored XSS in Shortcodewpbrigade · login logout menu · CWE-79 | Medium5.4 | — | 0.5% | Feb 21, 2023 |
19Monitor | CVE-2021-24656No exploit | Simple Social Media Share Buttons < 3.2.4 - Authenticated Stored Cross-Site Scriptingwpbrigade · simple social buttons · CWE-79 | Medium4.8 | — | 0.6% | Oct 11, 2021 |
19Monitor | CVE-2024-13610No exploit | Simple Social Media Share Buttons < 6.0.0 - Admin+ Stored XSSwpbrigade · simple social buttons · CWE-79 | Medium4.8 | — | 0.3% | Apr 15, 2025 |
17Monitor | CVE-2019-15871No exploit | The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.wpbrigade · loginpress · CWE-862 | Medium4.3 | — | 0.9% | Sep 3, 2019 |
- CVE-2019-1587240Plan
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
CriticalCVSS 9.8No exploitEPSS 2%wpbrigade · loginpressSep 3, 2019
- CVE-2022-034724Monitor
LoginPress < 1.5.12 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%wpbrigade · loginpressMar 7, 2022
- CVE-2021-2448621Monitor
Simple Social Media Share Buttons < 3.2.3 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%wpbrigade · simple social media share buttonsAug 23, 2021
- CVE-2023-584521Monitor
Simple Social Buttons < 5.1.1 - Unauthenticated Password Protected Post Access
MediumCVSS 5.3No exploitEPSS 1%wpbrigade · simple social buttonsNov 27, 2023
- CVE-2022-462521Monitor
Login Logout Menu < 1.4.0 - Contributor+ Stored XSS in Shortcode
MediumCVSS 5.4No exploitEPSS 1%wpbrigade · login logout menuJan 23, 2023
- CVE-2022-4183921Monitor
WordPress LoginPress plugin <= 1.6.2 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 1%wpbrigade · loginpressNov 18, 2022
- CVE-2022-462221Monitor
Login Logout Menu <= 1.3.3 - Contributor+ Stored XSS in Shortcode
MediumCVSS 5.4No exploitEPSS 0%wpbrigade · login logout menuFeb 21, 2023
- CVE-2021-2465619Monitor
Simple Social Media Share Buttons < 3.2.4 - Authenticated Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 1%wpbrigade · simple social buttonsOct 11, 2021
- CVE-2024-1361019Monitor
Simple Social Media Share Buttons < 6.0.0 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%wpbrigade · simple social buttonsApr 15, 2025
- CVE-2019-1587117Monitor
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
MediumCVSS 4.3No exploitEPSS 1%wpbrigade · loginpressSep 3, 2019