Wpmet records
69 published records for vendor wpmet.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 23.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')28
- CWE-862 Missing Authorization11
- CWE-639 Authorization Bypass Through User-Controlled Key7
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
69 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2024-9234Proof of concept | GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Uploadataurr · gutenkit – page builder blocks, patterns, and templates for gutenberg block editor · CWE-862 | Critical9.8 | — | 10.4% | Oct 11, 2024 |
41Plan | CVE-2022-0788Proof of concept | WP Fundraising Donation and Crowdfunding Platform < 1.5.0 - Unauthenticated SQLiwpmet · fundengine · CWE-89 | Critical9.8 | — | 7.9% | Jun 8, 2022 |
39Monitor | CVE-2023-0714No exploit | Metform Elementor Contact Form Builder <= 3.2.4 - Unauthenticated Double-Extension Arbitrary File Uploadwpmet · metform elementor contact form builder · CWE-434 | Critical9.8 | — | 1.0% | Aug 17, 2024 |
39Monitor | CVE-2023-50903No exploit | WordPress Metform Elementor Contact Form Builder plugin <= 3.4.0 - Broken Access Control vulnerabilitywpmet · metform elementor contact form builder · CWE-862 | Critical9.8 | — | 0.6% | Dec 9, 2024 |
38Monitor | CVE-2024-4404No exploit | ElementsKit PRO <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgerywpmet · elementskit · CWE-918 | Critical9.6 | — | 0.3% | Jun 14, 2024 |
35Monitor | CVE-2024-2047No exploit | ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in render_rawwpmet · elements kit elementor addons · CWE-98 | High8.8 | — | 1.5% | Mar 30, 2024 |
35Monitor | CVE-2024-3499No exploit | ElementsKit Elementor addons <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Modulewpmet · elements kit elementor addons · CWE-98 | High8.8 | — | 1.1% | May 2, 2024 |
35Monitor | CVE-2024-3500No exploit | ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Local File Inclusion via Price Menu, Hotspot, and Advanced Toggle Widgetswpmet · elementskit · CWE-98 | High8.8 | — | 1.1% | May 2, 2024 |
35Monitor | CVE-2024-33570No exploit | WordPress MetForm plugin <= 3.8.3 - Broken Access Control vulnerabilitywpmet · metform elementor contact form builder · CWE-862 | High8.8 | — | 0.4% | May 6, 2024 |
35Monitor | CVE-2024-6698No exploit | FundEngine – Donation and Crowdfunding Platform <= 1.7.0 - Authenticated (Subscriber+) Privilege Escalationwpmet · fundengine · CWE-862 | High8.8 | — | 0.4% | Aug 1, 2024 |
35Monitor | CVE-2023-28987No exploit | WordPress Wp Ultimate Review Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)wpmet · wp ultimate review · CWE-352 | High8.8 | — | 0.3% | Nov 12, 2023 |
35Monitor | CVE-2022-45371No exploit | WordPress ShopEngine Plugin <= 4.1.1 is vulnerable to Cross Site Request Forgery (CSRF)wpmet · shopengine · CWE-352 | High8.8 | — | 0.2% | May 25, 2023 |
35Monitor | CVE-2023-46085No exploit | WordPress Wp Ultimate Review Plugin <= 2.2.4 is vulnerable to Cross Site Request Forgery (CSRF)wpmet · wp ultimate review · CWE-352 | High8.8 | — | 0.2% | Oct 22, 2023 |
33Monitor | CVE-2023-0084Proof of concept | Metform Elementor Contact Form Builder <= 3.1.2 - Unauthenticated Stored Cross-Site Scriptingwpmet · metform elementor contact form builder · CWE-79 | Medium6.1 | — | 28.6% | Mar 2, 2023 |
33Monitor | CVE-2022-1442Proof of concept | Metform Elementor Contact Form Builder <= 2.1.3 - Sensitive Information Disclosurewpmet · metform elementor contact form builder · CWE-862 | High7.5 | — | 8.8% | May 10, 2022 |
31Monitor | CVE-2023-0721No exploit | Metform Elementor Contact Form Builder <= 3.3.0 - Unauthenticated CSV Injectionwpmet · metform elementor contact form builder · CWE-1236 | High7.8 | — | 0.7% | Jun 9, 2023 |
30Monitor | CVE-2024-4266No exploit | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information Exposurewpmet · metform elementor contact form builder · CWE-200 | High7.5 | — | 0.5% | Jun 11, 2024 |
30Monitor | CVE-2024-21746No exploit | WordPress Wp Ultimate Review plugin <= 2.3.6 - IP limit Bypass vulnerabilitywpmet · wp ultimate review · CWE-290 | High7.5 | — | 0.5% | May 17, 2024 |
30Monitor | CVE-2024-32683No exploit | WordPress WP Ultimate Review plugin <= 2.2.5 - Insecure Direct Object References (IDOR) vulnerabilitywpmet · wp ultimate review · CWE-639 | High7.5 | — | 0.5% | Apr 19, 2024 |
30Monitor | CVE-2024-32684No exploit | WordPress WP Ultimate Review plugin <= 2.2.5 - Broken Access Control on Review vulnerabilitywpmet · wp ultimate review · CWE-862 | High7.5 | — | 0.4% | Apr 22, 2024 |
26Monitor | CVE-2023-0688No exploit | Metform Elementor Contact Form Builder <= 3.3.1 - Authenticated (Subscriber+) Information Disclosure via mf_thankyou shortcodewpmet · metform elementor contact form builder · CWE-639 | Medium6.5 | — | 0.7% | Jun 9, 2023 |
26Monitor | CVE-2024-43996No exploit | WordPress ElementsKit Pro plugin <= 3.6.0 - Local File Inclusion vulnerabilitywpmet · elementskit · CWE-22 | Medium6.5 | — | 0.6% | Sep 22, 2024 |
26Monitor | CVE-2022-47160No exploit | WordPress Wp Social Plugin <= 1.9.0 is vulnerable to Sensitive Data Exposurewpmet · wp social login and register social counter · CWE-200 | Medium6.5 | — | 0.6% | Jan 19, 2024 |
21Monitor | CVE-2023-0085No exploit | Metform Elementor Contact Form Builder <= 3.2.1 - reCaptcha Protection Bypasswpmet · metform elementor contact form builder · CWE-693 | Medium5.3 | — | 0.7% | Mar 2, 2023 |
21Monitor | CVE-2023-1843No exploit | Metform Elementor Contact Form Builder <= 3.3.0 - Missing Authorizationwpmet · metform elementor contact form builder · CWE-862 | Medium5.3 | — | 0.6% | Jun 9, 2023 |
- CVE-2024-923442Plan
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.8Proof of conceptEPSS 10%ataurr · gutenkit – page builder blocks, patterns, and templates for gutenberg block editorOct 11, 2024
- CVE-2022-078841Plan
WP Fundraising Donation and Crowdfunding Platform < 1.5.0 - Unauthenticated SQLi
CriticalCVSS 9.8Proof of conceptEPSS 8%wpmet · fundengineJun 8, 2022
- CVE-2023-071439Monitor
Metform Elementor Contact Form Builder <= 3.2.4 - Unauthenticated Double-Extension Arbitrary File Upload
CriticalCVSS 9.8No exploitEPSS 1%wpmet · metform elementor contact form builderAug 17, 2024
- CVE-2023-5090339Monitor
WordPress Metform Elementor Contact Form Builder plugin <= 3.4.0 - Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 1%wpmet · metform elementor contact form builderDec 9, 2024
- CVE-2024-440438Monitor
ElementsKit PRO <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery
CriticalCVSS 9.6No exploitEPSS 0%wpmet · elementskitJun 14, 2024
- CVE-2024-204735Monitor
ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in render_raw
HighCVSS 8.8No exploitEPSS 1%wpmet · elements kit elementor addonsMar 30, 2024
- CVE-2024-349935Monitor
ElementsKit Elementor addons <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module
HighCVSS 8.8No exploitEPSS 1%wpmet · elements kit elementor addonsMay 2, 2024
- CVE-2024-350035Monitor
ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Local File Inclusion via Price Menu, Hotspot, and Advanced Toggle Widgets
HighCVSS 8.8No exploitEPSS 1%wpmet · elementskitMay 2, 2024
- CVE-2024-3357035Monitor
WordPress MetForm plugin <= 3.8.3 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%wpmet · metform elementor contact form builderMay 6, 2024
- CVE-2024-669835Monitor
FundEngine – Donation and Crowdfunding Platform <= 1.7.0 - Authenticated (Subscriber+) Privilege Escalation
HighCVSS 8.8No exploitEPSS 0%wpmet · fundengineAug 1, 2024
- CVE-2023-2898735Monitor
WordPress Wp Ultimate Review Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wpmet · wp ultimate reviewNov 12, 2023
- CVE-2022-4537135Monitor
WordPress ShopEngine Plugin <= 4.1.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wpmet · shopengineMay 25, 2023
- CVE-2023-4608535Monitor
WordPress Wp Ultimate Review Plugin <= 2.2.4 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wpmet · wp ultimate reviewOct 22, 2023
- CVE-2023-008433Monitor
Metform Elementor Contact Form Builder <= 3.1.2 - Unauthenticated Stored Cross-Site Scripting
MediumCVSS 6.1Proof of conceptEPSS 29%wpmet · metform elementor contact form builderMar 2, 2023
- CVE-2022-144233Monitor
Metform Elementor Contact Form Builder <= 2.1.3 - Sensitive Information Disclosure
HighCVSS 7.5Proof of conceptEPSS 9%wpmet · metform elementor contact form builderMay 10, 2022
- CVE-2023-072131Monitor
Metform Elementor Contact Form Builder <= 3.3.0 - Unauthenticated CSV Injection
HighCVSS 7.8No exploitEPSS 1%wpmet · metform elementor contact form builderJun 9, 2023
- CVE-2024-426630Monitor
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information Exposure
HighCVSS 7.5No exploitEPSS 1%wpmet · metform elementor contact form builderJun 11, 2024
- CVE-2024-2174630Monitor
WordPress Wp Ultimate Review plugin <= 2.3.6 - IP limit Bypass vulnerability
HighCVSS 7.5No exploitEPSS 0%wpmet · wp ultimate reviewMay 17, 2024
- CVE-2024-3268330Monitor
WordPress WP Ultimate Review plugin <= 2.2.5 - Insecure Direct Object References (IDOR) vulnerability
HighCVSS 7.5No exploitEPSS 0%wpmet · wp ultimate reviewApr 19, 2024
- CVE-2024-3268430Monitor
WordPress WP Ultimate Review plugin <= 2.2.5 - Broken Access Control on Review vulnerability
HighCVSS 7.5No exploitEPSS 0%wpmet · wp ultimate reviewApr 22, 2024
- CVE-2023-068826Monitor
Metform Elementor Contact Form Builder <= 3.3.1 - Authenticated (Subscriber+) Information Disclosure via mf_thankyou shortcode
MediumCVSS 6.5No exploitEPSS 1%wpmet · metform elementor contact form builderJun 9, 2023
- CVE-2024-4399626Monitor
WordPress ElementsKit Pro plugin <= 3.6.0 - Local File Inclusion vulnerability
MediumCVSS 6.5No exploitEPSS 1%wpmet · elementskitSep 22, 2024
- CVE-2022-4716026Monitor
WordPress Wp Social Plugin <= 1.9.0 is vulnerable to Sensitive Data Exposure
MediumCVSS 6.5No exploitEPSS 1%wpmet · wp social login and register social counterJan 19, 2024
- CVE-2023-008521Monitor
Metform Elementor Contact Form Builder <= 3.2.1 - reCaptcha Protection Bypass
MediumCVSS 5.3No exploitEPSS 1%wpmet · metform elementor contact form builderMar 2, 2023
- CVE-2023-184321Monitor
Metform Elementor Contact Form Builder <= 3.3.0 - Missing Authorization
MediumCVSS 5.3No exploitEPSS 1%wpmet · metform elementor contact form builderJun 9, 2023