Skip to content
Noroxi

WPDeveloper records

137 published records for vendor wpdeveloper.

All records

137 records
  • CVE-2024-1698
    62This week

    NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection

    CriticalCVSS 9.8Proof of conceptEPSS 78%

    wpdeveloper · notificationxFeb 27, 2024

  • CVE-2023-32243
    62This week

    WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation

    CriticalCVSS 9.8Proof of conceptEPSS 76%

    wpdeveloper · essential addons for elementorMay 12, 2023

  • Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusion

    CriticalCVSS 9.8Proof of conceptEPSS 51%

    wpdeveloper · essential blocksJan 15, 2024

  • NotificationX < 2.3.9 - Unauthenticated Blind SQL Injection

    CriticalCVSS 9.8Proof of conceptEPSS 34%

    wpdeveloper · notificationxMar 7, 2022

  • ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation

    HighCVSS 8.8Proof of conceptEPSS 17%

    wpdeveloper · reviewxJun 6, 2023

  • Essential Addons for Elementor < 5.0.5 - Unauthenticated LFI

    CriticalCVSS 9.8No exploitEPSS 2%

    wpdeveloper · essential addons for elementorFeb 1, 2022

  • CVE-2023-4402
    39Monitor

    Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via products

    CriticalCVSS 9.8No exploitEPSS 1%

    wpdeveloper · essential blocksOct 20, 2023

  • WordPress ReviewX Plugin <= 1.6.7 is vulnerable to CSV Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    wpdeveloper · reviewxNov 7, 2023

  • WordPress EmbedPress plugin <= 4.0.9 - Local File Inclusion vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    wpdeveloper · embedpressAug 19, 2024

  • WordPress ReviewX plugin <= 1.6.28 - Broken Access Control vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    wpdeveloper · reviewxNov 1, 2024

  • WordPress EmbedPress plugin <= 3.9.8 - Broken Access Control vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    wpdeveloper · embedpressJun 9, 2024

  • Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Arbitrary Plugin Activation

    HighCVSS 8.8Proof of conceptEPSS 3%

    wpdeveloper · simple 301 redirectsJun 14, 2021

  • WordPress BetterDocs plugin <= 3.3.3 - Unauthenticated PHP Object Injection vulnerability

    CriticalCVSS 9.0No exploitEPSS 1%

    wpdeveloper · betterdocsMar 28, 2024

  • Simple 301 Redirects by BetterLinks - 2.0.0-2.0.3 - Arbitrary Plugin Installation

    HighCVSS 8.8No exploitEPSS 1%

    wpdeveloper · simple 301 redirectsJun 14, 2021

  • Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Export

    HighCVSS 8.8No exploitEPSS 1%

    wpdeveloper · simple 301 redirectsJun 14, 2021

  • Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Import

    HighCVSS 8.8No exploitEPSS 1%

    wpdeveloper · simple 301 redirectsJun 14, 2021

  • The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterVal

    HighCVSS 8.8No exploitEPSS 1%

    wpdeveloper · reviewxFeb 23, 2023

  • WordPress Essential Addons for Elementor plugin <= 5.8.8 - Contributor+ Privilege Escalation vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    wpdeveloper · essential addons for elementorMay 17, 2024

  • CVE-2024-3018
    35Monitor

    Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword

    HighCVSS 8.8No exploitEPSS 1%

    wpdeveloper · essential addons for elementorMar 30, 2024

  • The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.

    HighCVSS 8.8No exploitEPSS 1%

    wpdeveloper · twitter cards metaAug 12, 2019

  • WordPress Essential Blocks plugin <= 4.2.0 - Multiple Contributor+ Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    wpdeveloper · essential blocksDec 9, 2024

  • WordPress Essential Blocks plugin <= 4.2.0 - Multiple Subscriber+ Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    wpdeveloper · essential blocksDec 9, 2024

  • WordPress BetterDocs plugin <= 3.5.8 - Local File Inclusion vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    wpdeveloper · betterdocsAug 13, 2024

  • CVE-2021-4447
    35Monitor

    Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalation

    HighCVSS 8.8No exploitEPSS 0%

    wpdeveloper · essential addons for elementorOct 16, 2024

  • WordPress EmbedPress plugin <= 4.0.4 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    wpdeveloper · embedpressNov 1, 2024