wpchill records
47 published records for vendor wpchill.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 27.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-862 Missing Authorization4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-434 Unrestricted Upload of File with Dangerous Type3
The weakness classes this vendor ships most often: where to look.
CWEAll records
47 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2021-23174No exploit | WordPress Download Monitor plugin <= 4.4.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilitywpchill · download monitor · CWE-79 | Medium4.8 | — | 83.9% | Jan 28, 2022 |
41Plan | CVE-2022-45354Proof of concept | WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposurewpchill · download monitor · CWE-200 | High7.5 | — | 38.1% | Jan 8, 2024 |
35Monitor | CVE-2023-34007No exploit | WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Uploadwpchill · download monitor · CWE-434 | High8.8 | — | 0.9% | Dec 20, 2023 |
35Monitor | CVE-2024-12853No exploit | Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Uploadwpchill · modula image gallery · CWE-434 | High8.8 | — | 0.9% | Jan 8, 2025 |
35Monitor | CVE-2024-47362No exploit | WordPress Strong Testimonials plugin <= 3.1.16 - Broken Access Control vulnerabilitywpchill · strong testimonials · CWE-862 | High8.8 | — | 0.4% | Nov 1, 2024 |
35Monitor | CVE-2024-49256No exploit | WordPress Htaccess File Editor plugin <= 1.0.18 - Broken Access Control vulnerabilitywpchill · htaccess file editor · CWE-863 | High8.8 | — | 0.4% | Nov 1, 2024 |
35Monitor | CVE-2022-36292No exploit | WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Cross-Site Request Forgery (CSRF) vulnerabilitieswpchill · gallery photoblocks · CWE-352 | High8.8 | — | 0.4% | Aug 23, 2022 |
35Monitor | CVE-2023-52123No exploit | WordPress Strong Testimonials Plugin <= 3.1.10 is vulnerable to Cross Site Request Forgery (CSRF)wpchill · strong testimonials · CWE-352 | High8.8 | — | 0.2% | Jan 5, 2024 |
33Monitor | CVE-2021-24786Proof of concept | Download Monitor < 4.4.5 - Admin+ SQL Injectionwpchill · download monitor · CWE-89 | High7.2 | — | 17.3% | Jan 3, 2022 |
30Monitor | CVE-2022-4972No exploit | Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Exportwpchill · download monitor · CWE-862 | High7.5 | — | 0.5% | Oct 16, 2024 |
30Monitor | CVE-2024-11282No exploit | Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposurewpchill · passster · CWE-200 | High7.5 | — | 0.4% | Jan 7, 2025 |
28Monitor | CVE-2021-24774No exploit | Check & Log Email < 1.0.3 - Admin+ SQL Injectionswpchill · check \& log email · CWE-89 | High7.2 | — | 1.3% | Oct 25, 2021 |
28Monitor | CVE-2025-13645No exploit | Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletionwpchill · modula image gallery · CWE-22 | High7.2 | — | 1.0% | Dec 2, 2025 |
28Monitor | CVE-2024-30501No exploit | WordPress Download Monitor theme <= 4.9.4 - Auth. SQL Injection vulnerabilitywpchill · download monitor · CWE-89 | High7.2 | — | 0.6% | Mar 29, 2024 |
27Monitor | CVE-2021-31567No exploit | WordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerabilitywpchill · download monitor · CWE-200 | Medium6.8 | — | 1.4% | Jan 28, 2022 |
27Monitor | CVE-2024-3710No exploit | Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSSwpchill · image photo gallery final tiles grid · CWE-79 | Medium6.8 | — | 0.5% | Jul 13, 2024 |
26Monitor | CVE-2025-13646No exploit | Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Conditionwpchill · modula image gallery · CWE-434 | Medium6.6 | — | 0.8% | Dec 2, 2025 |
25Monitor | CVE-2020-8549No exploit | Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as steawpchill · strong testimonials · CWE-79 | Medium6.1 | — | 1.9% | Feb 3, 2020 |
24Monitor | CVE-2022-1547No exploit | Check & Log email < 1.0.6 - Reflected Cross-Site Scriptingwpchill · check \& log email · CWE-79 | Medium6.1 | — | 0.8% | May 23, 2022 |
24Monitor | CVE-2021-24908No exploit | Check & Log Email < 1.0.4 - Reflected Cross-Site Scriptingwpchill · check \& log email · CWE-79 | Medium6.1 | — | 0.8% | Nov 29, 2021 |
24Monitor | CVE-2022-27852No exploit | WordPress KB Support plugin <= 1.5.5 - Multiple Unauth. Stored Cross-Site Scripting (XSS) vulnerabilitieswpchill · kb support · CWE-79 | Medium6.1 | — | 0.7% | Apr 15, 2022 |
22Monitor | CVE-2022-1054Proof of concept | RSVP and Event Management < 2.7.8 - Unauthenticated Entries Exportwpchill · rsvp and event management · CWE-862 | Medium5.3 | — | 4.2% | Apr 18, 2022 |
21Monitor | CVE-2020-9003No exploit | A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress.wpchill · modula image gallery · CWE-79 | Medium5.4 | — | 1.0% | Feb 20, 2020 |
21Monitor | CVE-2022-37407No exploit | WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitieswpchill · gallery photoblocks · CWE-79 | Medium5.4 | — | 0.6% | Sep 9, 2022 |
21Monitor | CVE-2021-36920No exploit | WordPress plugin Download Monitor <= 4.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilitywpchill · download monitor · CWE-79 | Medium5.4 | — | 0.6% | Jan 14, 2022 |
- CVE-2021-2317444Plan
WordPress Download Monitor plugin <= 4.4.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 84%wpchill · download monitorJan 28, 2022
- CVE-2022-4535441Plan
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
HighCVSS 7.5Proof of conceptEPSS 38%wpchill · download monitorJan 8, 2024
- CVE-2023-3400735Monitor
WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%wpchill · download monitorDec 20, 2023
- CVE-2024-1285335Monitor
Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%wpchill · modula image galleryJan 8, 2025
- CVE-2024-4736235Monitor
WordPress Strong Testimonials plugin <= 3.1.16 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%wpchill · strong testimonialsNov 1, 2024
- CVE-2024-4925635Monitor
WordPress Htaccess File Editor plugin <= 1.0.18 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%wpchill · htaccess file editorNov 1, 2024
- CVE-2022-3629235Monitor
WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Cross-Site Request Forgery (CSRF) vulnerabilities
HighCVSS 8.8No exploitEPSS 0%wpchill · gallery photoblocksAug 23, 2022
- CVE-2023-5212335Monitor
WordPress Strong Testimonials Plugin <= 3.1.10 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wpchill · strong testimonialsJan 5, 2024
- CVE-2021-2478633Monitor
Download Monitor < 4.4.5 - Admin+ SQL Injection
HighCVSS 7.2Proof of conceptEPSS 17%wpchill · download monitorJan 3, 2022
- CVE-2022-497230Monitor
Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Export
HighCVSS 7.5No exploitEPSS 0%wpchill · download monitorOct 16, 2024
- CVE-2024-1128230Monitor
Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
HighCVSS 7.5No exploitEPSS 0%wpchill · passsterJan 7, 2025
- CVE-2021-2477428Monitor
Check & Log Email < 1.0.3 - Admin+ SQL Injections
HighCVSS 7.2No exploitEPSS 1%wpchill · check \& log emailOct 25, 2021
- CVE-2025-1364528Monitor
Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion
HighCVSS 7.2No exploitEPSS 1%wpchill · modula image galleryDec 2, 2025
- CVE-2024-3050128Monitor
WordPress Download Monitor theme <= 4.9.4 - Auth. SQL Injection vulnerability
HighCVSS 7.2No exploitEPSS 1%wpchill · download monitorMar 29, 2024
- CVE-2021-3156727Monitor
WordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerability
MediumCVSS 6.8No exploitEPSS 1%wpchill · download monitorJan 28, 2022
- CVE-2024-371027Monitor
Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSS
MediumCVSS 6.8No exploitEPSS 0%wpchill · image photo gallery final tiles gridJul 13, 2024
- CVE-2025-1364626Monitor
Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition
MediumCVSS 6.6No exploitEPSS 1%wpchill · modula image galleryDec 2, 2025
- CVE-2020-854925Monitor
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stea
MediumCVSS 6.1No exploitEPSS 2%wpchill · strong testimonialsFeb 3, 2020
- CVE-2022-154724Monitor
Check & Log email < 1.0.6 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%wpchill · check \& log emailMay 23, 2022
- CVE-2021-2490824Monitor
Check & Log Email < 1.0.4 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%wpchill · check \& log emailNov 29, 2021
- CVE-2022-2785224Monitor
WordPress KB Support plugin <= 1.5.5 - Multiple Unauth. Stored Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 6.1No exploitEPSS 1%wpchill · kb supportApr 15, 2022
- CVE-2022-105422Monitor
RSVP and Event Management < 2.7.8 - Unauthenticated Entries Export
MediumCVSS 5.3Proof of conceptEPSS 4%wpchill · rsvp and event managementApr 18, 2022
- CVE-2020-900321Monitor
A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress.
MediumCVSS 5.4No exploitEPSS 1%wpchill · modula image galleryFeb 20, 2020
- CVE-2022-3740721Monitor
WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 5.4No exploitEPSS 1%wpchill · gallery photoblocksSep 9, 2022
- CVE-2021-3692021Monitor
WordPress plugin Download Monitor <= 4.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 1%wpchill · download monitorJan 14, 2022