Skip to content
Noroxi

wpchill records

47 published records for vendor wpchill.

All records

47 records
  • WordPress Download Monitor plugin <= 4.4.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerability

    MediumCVSS 4.8No exploitEPSS 84%

    wpchill · download monitorJan 28, 2022

  • WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure

    HighCVSS 7.5Proof of conceptEPSS 38%

    wpchill · download monitorJan 8, 2024

  • WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Upload

    HighCVSS 8.8No exploitEPSS 1%

    wpchill · download monitorDec 20, 2023

  • Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Upload

    HighCVSS 8.8No exploitEPSS 1%

    wpchill · modula image galleryJan 8, 2025

  • WordPress Strong Testimonials plugin <= 3.1.16 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    wpchill · strong testimonialsNov 1, 2024

  • WordPress Htaccess File Editor plugin <= 1.0.18 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    wpchill · htaccess file editorNov 1, 2024

  • WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Cross-Site Request Forgery (CSRF) vulnerabilities

    HighCVSS 8.8No exploitEPSS 0%

    wpchill · gallery photoblocksAug 23, 2022

  • WordPress Strong Testimonials Plugin <= 3.1.10 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wpchill · strong testimonialsJan 5, 2024

  • Download Monitor < 4.4.5 - Admin+ SQL Injection

    HighCVSS 7.2Proof of conceptEPSS 17%

    wpchill · download monitorJan 3, 2022

  • CVE-2022-4972
    30Monitor

    Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Export

    HighCVSS 7.5No exploitEPSS 0%

    wpchill · download monitorOct 16, 2024

  • Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

    HighCVSS 7.5No exploitEPSS 0%

    wpchill · passsterJan 7, 2025

  • Check & Log Email < 1.0.3 - Admin+ SQL Injections

    HighCVSS 7.2No exploitEPSS 1%

    wpchill · check \& log emailOct 25, 2021

  • Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion

    HighCVSS 7.2No exploitEPSS 1%

    wpchill · modula image galleryDec 2, 2025

  • WordPress Download Monitor theme <= 4.9.4 - Auth. SQL Injection vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    wpchill · download monitorMar 29, 2024

  • WordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerability

    MediumCVSS 6.8No exploitEPSS 1%

    wpchill · download monitorJan 28, 2022

  • CVE-2024-3710
    27Monitor

    Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSS

    MediumCVSS 6.8No exploitEPSS 0%

    wpchill · image photo gallery final tiles gridJul 13, 2024

  • Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition

    MediumCVSS 6.6No exploitEPSS 1%

    wpchill · modula image galleryDec 2, 2025

  • CVE-2020-8549
    25Monitor

    Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stea

    MediumCVSS 6.1No exploitEPSS 2%

    wpchill · strong testimonialsFeb 3, 2020

  • CVE-2022-1547
    24Monitor

    Check & Log email < 1.0.6 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    wpchill · check \& log emailMay 23, 2022

  • Check & Log Email < 1.0.4 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    wpchill · check \& log emailNov 29, 2021

  • WordPress KB Support plugin <= 1.5.5 - Multiple Unauth. Stored Cross-Site Scripting (XSS) vulnerabilities

    MediumCVSS 6.1No exploitEPSS 1%

    wpchill · kb supportApr 15, 2022

  • CVE-2022-1054
    22Monitor

    RSVP and Event Management < 2.7.8 - Unauthenticated Entries Export

    MediumCVSS 5.3Proof of conceptEPSS 4%

    wpchill · rsvp and event managementApr 18, 2022

  • CVE-2020-9003
    21Monitor

    A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress.

    MediumCVSS 5.4No exploitEPSS 1%

    wpchill · modula image galleryFeb 20, 2020

  • WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities

    MediumCVSS 5.4No exploitEPSS 1%

    wpchill · gallery photoblocksSep 9, 2022

  • WordPress plugin Download Monitor <= 4.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 1%

    wpchill · download monitorJan 14, 2022