WPDeveloper records
137 published records for vendor wpdeveloper.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 32.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')75
- CWE-862 Missing Authorization29
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-502 Deserialization of Untrusted Data4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
The weakness classes this vendor ships most often: where to look.
CWEAll records
137 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2024-1698Proof of concept | NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injectionwpdeveloper · notificationx · CWE-89 | Critical9.8 | — | 77.6% | Feb 27, 2024 |
62This week | CVE-2023-32243Proof of concept | WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalationwpdeveloper · essential addons for elementor · CWE-287 | Critical9.8 | — | 75.5% | May 12, 2023 |
54Plan | CVE-2023-6623Proof of concept | Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusionwpdeveloper · essential blocks · CWE-22 | Critical9.8 | — | 50.7% | Jan 15, 2024 |
49Plan | CVE-2022-0349Proof of concept | NotificationX < 2.3.9 - Unauthenticated Blind SQL Injectionwpdeveloper · notificationx · CWE-89 | Critical9.8 | — | 34.4% | Mar 7, 2022 |
40Plan | CVE-2023-2833Proof of concept | ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalationwpdeveloper · reviewx · CWE-269 | High8.8 | — | 17.5% | Jun 6, 2023 |
40Plan | CVE-2022-0320No exploit | Essential Addons for Elementor < 5.0.5 - Unauthenticated LFIwpdeveloper · essential addons for elementor · CWE-22 | Critical9.8 | — | 2.0% | Feb 1, 2022 |
39Monitor | CVE-2023-4402No exploit | Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via productswpdeveloper · essential blocks · CWE-502 | Critical9.8 | — | 1.5% | Oct 20, 2023 |
39Monitor | CVE-2022-46809No exploit | WordPress ReviewX Plugin <= 1.6.7 is vulnerable to CSV Injectionwpdeveloper · reviewx · CWE-1236 | Critical9.8 | — | 0.8% | Nov 7, 2023 |
39Monitor | CVE-2024-43328No exploit | WordPress EmbedPress plugin <= 4.0.9 - Local File Inclusion vulnerabilitywpdeveloper · embedpress · CWE-22 | Critical9.8 | — | 0.5% | Aug 19, 2024 |
39Monitor | CVE-2024-43323No exploit | WordPress ReviewX plugin <= 1.6.28 - Broken Access Control vulnerabilitywpdeveloper · reviewx · CWE-862 | Critical9.8 | — | 0.5% | Nov 1, 2024 |
39Monitor | CVE-2024-31284No exploit | WordPress EmbedPress plugin <= 3.9.8 - Broken Access Control vulnerabilitywpdeveloper · embedpress · CWE-862 | Critical9.8 | — | 0.4% | Jun 9, 2024 |
36Monitor | CVE-2021-24356Proof of concept | Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Arbitrary Plugin Activationwpdeveloper · simple 301 redirects · CWE-862 | High8.8 | — | 2.6% | Jun 14, 2021 |
36Monitor | CVE-2024-30226No exploit | WordPress BetterDocs plugin <= 3.3.3 - Unauthenticated PHP Object Injection vulnerabilitywpdeveloper · betterdocs · CWE-502 | Critical9.0 | — | 0.9% | Mar 28, 2024 |
35Monitor | CVE-2021-24354No exploit | Simple 301 Redirects by BetterLinks - 2.0.0-2.0.3 - Arbitrary Plugin Installationwpdeveloper · simple 301 redirects · CWE-862 | High8.8 | — | 1.5% | Jun 14, 2021 |
35Monitor | CVE-2021-24352No exploit | Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Exportwpdeveloper · simple 301 redirects · CWE-862 | High8.8 | — | 1.2% | Jun 14, 2021 |
35Monitor | CVE-2021-24353No exploit | Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Importwpdeveloper · simple 301 redirects · CWE-862 | High8.8 | — | 1.1% | Jun 14, 2021 |
35Monitor | CVE-2023-26325No exploit | The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValwpdeveloper · reviewx · CWE-89 | High8.8 | — | 0.9% | Feb 23, 2023 |
35Monitor | CVE-2023-41955No exploit | WordPress Essential Addons for Elementor plugin <= 5.8.8 - Contributor+ Privilege Escalation vulnerabilitywpdeveloper · essential addons for elementor · CWE-269 | High8.8 | — | 0.8% | May 17, 2024 |
35Monitor | CVE-2024-3018No exploit | Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpasswordwpdeveloper · essential addons for elementor · CWE-502 | High8.8 | — | 0.8% | Mar 30, 2024 |
35Monitor | CVE-2017-18504No exploit | The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.wpdeveloper · twitter cards meta · CWE-352 | High8.8 | — | 0.7% | Aug 12, 2019 |
35Monitor | CVE-2023-51359No exploit | WordPress Essential Blocks plugin <= 4.2.0 - Multiple Contributor+ Broken Access Control vulnerabilitywpdeveloper · essential blocks · CWE-862 | High8.8 | — | 0.6% | Dec 9, 2024 |
35Monitor | CVE-2023-51360No exploit | WordPress Essential Blocks plugin <= 4.2.0 - Multiple Subscriber+ Broken Access Control vulnerabilitywpdeveloper · essential blocks · CWE-862 | High8.8 | — | 0.6% | Dec 9, 2024 |
35Monitor | CVE-2024-43129No exploit | WordPress BetterDocs plugin <= 3.5.8 - Local File Inclusion vulnerabilitywpdeveloper · betterdocs · CWE-22 | High8.8 | — | 0.6% | Aug 13, 2024 |
35Monitor | CVE-2021-4447No exploit | Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalationwpdeveloper · essential addons for elementor · CWE-862 | High8.8 | — | 0.5% | Oct 16, 2024 |
35Monitor | CVE-2024-38707No exploit | WordPress EmbedPress plugin <= 4.0.4 - Broken Access Control vulnerabilitywpdeveloper · embedpress · CWE-862 | High8.8 | — | 0.4% | Nov 1, 2024 |
- CVE-2024-169862This week
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 78%wpdeveloper · notificationxFeb 27, 2024
- CVE-2023-3224362This week
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
CriticalCVSS 9.8Proof of conceptEPSS 76%wpdeveloper · essential addons for elementorMay 12, 2023
- CVE-2023-662354Plan
Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusion
CriticalCVSS 9.8Proof of conceptEPSS 51%wpdeveloper · essential blocksJan 15, 2024
- CVE-2022-034949Plan
NotificationX < 2.3.9 - Unauthenticated Blind SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 34%wpdeveloper · notificationxMar 7, 2022
- CVE-2023-283340Plan
ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
HighCVSS 8.8Proof of conceptEPSS 17%wpdeveloper · reviewxJun 6, 2023
- CVE-2022-032040Plan
Essential Addons for Elementor < 5.0.5 - Unauthenticated LFI
CriticalCVSS 9.8No exploitEPSS 2%wpdeveloper · essential addons for elementorFeb 1, 2022
- CVE-2023-440239Monitor
Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via products
CriticalCVSS 9.8No exploitEPSS 1%wpdeveloper · essential blocksOct 20, 2023
- CVE-2022-4680939Monitor
WordPress ReviewX Plugin <= 1.6.7 is vulnerable to CSV Injection
CriticalCVSS 9.8No exploitEPSS 1%wpdeveloper · reviewxNov 7, 2023
- CVE-2024-4332839Monitor
WordPress EmbedPress plugin <= 4.0.9 - Local File Inclusion vulnerability
CriticalCVSS 9.8No exploitEPSS 0%wpdeveloper · embedpressAug 19, 2024
- CVE-2024-4332339Monitor
WordPress ReviewX plugin <= 1.6.28 - Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 0%wpdeveloper · reviewxNov 1, 2024
- CVE-2024-3128439Monitor
WordPress EmbedPress plugin <= 3.9.8 - Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 0%wpdeveloper · embedpressJun 9, 2024
- CVE-2021-2435636Monitor
Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Arbitrary Plugin Activation
HighCVSS 8.8Proof of conceptEPSS 3%wpdeveloper · simple 301 redirectsJun 14, 2021
- CVE-2024-3022636Monitor
WordPress BetterDocs plugin <= 3.3.3 - Unauthenticated PHP Object Injection vulnerability
CriticalCVSS 9.0No exploitEPSS 1%wpdeveloper · betterdocsMar 28, 2024
- CVE-2021-2435435Monitor
Simple 301 Redirects by BetterLinks - 2.0.0-2.0.3 - Arbitrary Plugin Installation
HighCVSS 8.8No exploitEPSS 1%wpdeveloper · simple 301 redirectsJun 14, 2021
- CVE-2021-2435235Monitor
Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Export
HighCVSS 8.8No exploitEPSS 1%wpdeveloper · simple 301 redirectsJun 14, 2021
- CVE-2021-2435335Monitor
Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Import
HighCVSS 8.8No exploitEPSS 1%wpdeveloper · simple 301 redirectsJun 14, 2021
- CVE-2023-2632535Monitor
The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterVal
HighCVSS 8.8No exploitEPSS 1%wpdeveloper · reviewxFeb 23, 2023
- CVE-2023-4195535Monitor
WordPress Essential Addons for Elementor plugin <= 5.8.8 - Contributor+ Privilege Escalation vulnerability
HighCVSS 8.8No exploitEPSS 1%wpdeveloper · essential addons for elementorMay 17, 2024
- CVE-2024-301835Monitor
Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword
HighCVSS 8.8No exploitEPSS 1%wpdeveloper · essential addons for elementorMar 30, 2024
- CVE-2017-1850435Monitor
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
HighCVSS 8.8No exploitEPSS 1%wpdeveloper · twitter cards metaAug 12, 2019
- CVE-2023-5135935Monitor
WordPress Essential Blocks plugin <= 4.2.0 - Multiple Contributor+ Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 1%wpdeveloper · essential blocksDec 9, 2024
- CVE-2023-5136035Monitor
WordPress Essential Blocks plugin <= 4.2.0 - Multiple Subscriber+ Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 1%wpdeveloper · essential blocksDec 9, 2024
- CVE-2024-4312935Monitor
WordPress BetterDocs plugin <= 3.5.8 - Local File Inclusion vulnerability
HighCVSS 8.8No exploitEPSS 1%wpdeveloper · betterdocsAug 13, 2024
- CVE-2021-444735Monitor
Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalation
HighCVSS 8.8No exploitEPSS 0%wpdeveloper · essential addons for elementorOct 16, 2024
- CVE-2024-3870735Monitor
WordPress EmbedPress plugin <= 4.0.4 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%wpdeveloper · embedpressNov 1, 2024