Skip to content
Noroxi

Wpmet records

69 published records for vendor wpmet.

All records

69 records
  • GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload

    CriticalCVSS 9.8Proof of conceptEPSS 10%

    ataurr · gutenkit – page builder blocks, patterns, and templates for gutenberg block editorOct 11, 2024

  • WP Fundraising Donation and Crowdfunding Platform < 1.5.0 - Unauthenticated SQLi

    CriticalCVSS 9.8Proof of conceptEPSS 8%

    wpmet · fundengineJun 8, 2022

  • CVE-2023-0714
    39Monitor

    Metform Elementor Contact Form Builder <= 3.2.4 - Unauthenticated Double-Extension Arbitrary File Upload

    CriticalCVSS 9.8No exploitEPSS 1%

    wpmet · metform elementor contact form builderAug 17, 2024

  • WordPress Metform Elementor Contact Form Builder plugin <= 3.4.0 - Broken Access Control vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    wpmet · metform elementor contact form builderDec 9, 2024

  • CVE-2024-4404
    38Monitor

    ElementsKit PRO <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery

    CriticalCVSS 9.6No exploitEPSS 0%

    wpmet · elementskitJun 14, 2024

  • CVE-2024-2047
    35Monitor

    ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in render_raw

    HighCVSS 8.8No exploitEPSS 1%

    wpmet · elements kit elementor addonsMar 30, 2024

  • CVE-2024-3499
    35Monitor

    ElementsKit Elementor addons <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module

    HighCVSS 8.8No exploitEPSS 1%

    wpmet · elements kit elementor addonsMay 2, 2024

  • CVE-2024-3500
    35Monitor

    ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Local File Inclusion via Price Menu, Hotspot, and Advanced Toggle Widgets

    HighCVSS 8.8No exploitEPSS 1%

    wpmet · elementskitMay 2, 2024

  • WordPress MetForm plugin <= 3.8.3 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    wpmet · metform elementor contact form builderMay 6, 2024

  • CVE-2024-6698
    35Monitor

    FundEngine – Donation and Crowdfunding Platform <= 1.7.0 - Authenticated (Subscriber+) Privilege Escalation

    HighCVSS 8.8No exploitEPSS 0%

    wpmet · fundengineAug 1, 2024

  • WordPress Wp Ultimate Review Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wpmet · wp ultimate reviewNov 12, 2023

  • WordPress ShopEngine Plugin <= 4.1.1 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wpmet · shopengineMay 25, 2023

  • WordPress Wp Ultimate Review Plugin <= 2.2.4 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wpmet · wp ultimate reviewOct 22, 2023

  • CVE-2023-0084
    33Monitor

    Metform Elementor Contact Form Builder <= 3.1.2 - Unauthenticated Stored Cross-Site Scripting

    MediumCVSS 6.1Proof of conceptEPSS 29%

    wpmet · metform elementor contact form builderMar 2, 2023

  • CVE-2022-1442
    33Monitor

    Metform Elementor Contact Form Builder <= 2.1.3 - Sensitive Information Disclosure

    HighCVSS 7.5Proof of conceptEPSS 9%

    wpmet · metform elementor contact form builderMay 10, 2022

  • CVE-2023-0721
    31Monitor

    Metform Elementor Contact Form Builder <= 3.3.0 - Unauthenticated CSV Injection

    HighCVSS 7.8No exploitEPSS 1%

    wpmet · metform elementor contact form builderJun 9, 2023

  • CVE-2024-4266
    30Monitor

    MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information Exposure

    HighCVSS 7.5No exploitEPSS 1%

    wpmet · metform elementor contact form builderJun 11, 2024

  • WordPress Wp Ultimate Review plugin <= 2.3.6 - IP limit Bypass vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    wpmet · wp ultimate reviewMay 17, 2024

  • WordPress WP Ultimate Review plugin <= 2.2.5 - Insecure Direct Object References (IDOR) vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    wpmet · wp ultimate reviewApr 19, 2024

  • WordPress WP Ultimate Review plugin <= 2.2.5 - Broken Access Control on Review vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    wpmet · wp ultimate reviewApr 22, 2024

  • CVE-2023-0688
    26Monitor

    Metform Elementor Contact Form Builder <= 3.3.1 - Authenticated (Subscriber+) Information Disclosure via mf_thankyou shortcode

    MediumCVSS 6.5No exploitEPSS 1%

    wpmet · metform elementor contact form builderJun 9, 2023

  • WordPress ElementsKit Pro plugin <= 3.6.0 - Local File Inclusion vulnerability

    MediumCVSS 6.5No exploitEPSS 1%

    wpmet · elementskitSep 22, 2024

  • WordPress Wp Social Plugin <= 1.9.0 is vulnerable to Sensitive Data Exposure

    MediumCVSS 6.5No exploitEPSS 1%

    wpmet · wp social login and register social counterJan 19, 2024

  • CVE-2023-0085
    21Monitor

    Metform Elementor Contact Form Builder <= 3.2.1 - reCaptcha Protection Bypass

    MediumCVSS 5.3No exploitEPSS 1%

    wpmet · metform elementor contact form builderMar 2, 2023

  • CVE-2023-1843
    21Monitor

    Metform Elementor Contact Form Builder <= 3.3.0 - Missing Authorization

    MediumCVSS 5.3No exploitEPSS 1%

    wpmet · metform elementor contact form builderJun 9, 2023