xwp records
5 published records for vendor xwp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2021-24772No exploit | Stream < 3.8.2 - Admin+ SQL Injectionxwp · stream · CWE-89 | High8.8 | — | 1.6% | Nov 17, 2021 |
35Monitor | CVE-2024-7423No exploit | Stream <= 4.0.1 - Cross-Site Request Forgery to Arbitrary Options Updatexwp · stream · CWE-352 | High8.8 | — | 0.3% | Sep 13, 2024 |
35Monitor | CVE-2022-43490No exploit | WordPress Stream Plugin <= 3.9.2 is vulnerable to Cross Site Request Forgery (CSRF)xwp · stream · CWE-352 | High8.8 | — | 0.3% | May 25, 2023 |
26Monitor | CVE-2022-4384No exploit | Stream < 3.9.2 - Subscriber+ Alert Creationxwp · stream · CWE-862 | Medium6.5 | — | 0.9% | Feb 6, 2023 |
26Monitor | CVE-2022-43450No exploit | WordPress Stream Plugin <= 3.9.2 is vulnerable to Insecure Direct Object References (IDOR)xwp · stream · CWE-639 | Medium6.5 | — | 0.7% | Dec 19, 2023 |
- CVE-2021-2477235Monitor
Stream < 3.8.2 - Admin+ SQL Injection
HighCVSS 8.8No exploitEPSS 2%xwp · streamNov 17, 2021
- CVE-2024-742335Monitor
Stream <= 4.0.1 - Cross-Site Request Forgery to Arbitrary Options Update
HighCVSS 8.8No exploitEPSS 0%xwp · streamSep 13, 2024
- CVE-2022-4349035Monitor
WordPress Stream Plugin <= 3.9.2 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%xwp · streamMay 25, 2023
- CVE-2022-438426Monitor
Stream < 3.9.2 - Subscriber+ Alert Creation
MediumCVSS 6.5No exploitEPSS 1%xwp · streamFeb 6, 2023
- CVE-2022-4345026Monitor
WordPress Stream Plugin <= 3.9.2 is vulnerable to Insecure Direct Object References (IDOR)
MediumCVSS 6.5No exploitEPSS 1%xwp · streamDec 19, 2023