Перейти к содержимому
Noroxi

wesley

325 записей с упоминанием · 9 за 12 месяцев · 0 в CISA KEV

Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.

Записи с упоминанием

Исследователи
  • CVE-2026-5149
    26Наблюдать

    RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    rometheme · rtmkit16 июн. 2026 г.

  • CVE-2026-3018
    30Наблюдать

    Newsletters <= 4.13 - Unauthenticated SQL Injection via wpmlsubscriber_id Parameter

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    contrid · newsletters10 июн. 2026 г.

  • CVE-2026-5032
    31Наблюдать

    W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    boldgrid · w3 total cache2 апр. 2026 г.

  • CVE-2025-13910
    24Наблюдать

    WP-WebAuthn <= 1.3.4 - Unauthenticated Stored Cross-Site Scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    axton · wp-webauthn21 мар. 2026 г.

  • CVE-2025-14002
    32Наблюдать

    WPCOM Member <= 1.7.16 - Authentication Bypass via Weak OTP

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    whyun · wpcom member16 дек. 2025 г.

  • CVE-2025-8593
    35Наблюдать

    GSheetConnector For Gravity Forms <= 1.3.27 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    westerndeal · gsheetconnector for gravity forms – send gravity forms entries to google sheets in real-time11 окт. 2025 г.

  • CVE-2025-8606
    9Наблюдать

    GSheetConnector For Gravity Forms <= 1.3.23 - Cross-Site Request Forgery to Arbitrary Plugin Activation/Deactivation

    НизкаяCVSS 2,4Эксплойта нетEPSS 0 %

    westerndeal · gsheetconnector for gravity forms – send gravity forms entries to google sheets in real-time11 окт. 2025 г.

  • CVE-2025-7634
    39Наблюдать

    WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Unauthenticated Local File Inclusion

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    wptravelengine · wp travel engine – tour booking plugin – tour operator software9 окт. 2025 г.

  • CVE-2025-7526
    39Наблюдать

    WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Authenticated (Subscriber+) Arbitrary File Deletion via File Renaming

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    wptravelengine · wp travel engine – tour booking plugin – tour operator software9 окт. 2025 г.

  • CVE-2025-7052
    35Наблюдать

    LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    latepoint · latepoint – calendar booking plugin for appointments and events30 сент. 2025 г.

  • CVE-2025-7038
    32Наблюдать

    LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    latepoint · latepoint – calendar booking plugin for appointments and events30 сент. 2025 г.

  • CVE-2025-8487
    21Наблюдать

    Kubio AI Page Builder <= 2.6.3 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    extendthemes · kubio ai page builder19 сент. 2025 г.

  • CVE-2025-8565
    32Наблюдать

    Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.4.3 - Missing Authorization to Authenticated (Contributor+) Arbitr

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    wplegalpages · privacy policy generator – wplp legal pages18 сент. 2025 г.

  • CVE-2025-8446
    17Наблюдать

    Blaze Demo Importer <= 1.0.12 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    blazethemes · blaze demo importer16 сент. 2025 г.

  • CVE-2025-8481
    17Наблюдать

    Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid <= 1.1.7 - Cross-Site Request Forgery

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    mdimran41 · blog designer for elementor – post slider, post carousel, post grid11 сент. 2025 г.

  • CVE-2025-8479
    17Наблюдать

    Zoho Flow <= 2.14.1 - Cross-Site Request Forgery

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    zohoflow · zoho flow – integrate 100+ plugins with 1000+ business apps, no-code workflow automation11 сент. 2025 г.

  • CVE-2025-8147
    17Наблюдать

    LWSCache <= 2.8.5 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation via lwscache_activatePlugin Function

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    aurelienlws · lwscache29 авг. 2025 г.

  • CVE-2024-13807
    30Наблюдать

    Xagio SEO <= 7.1.0.5 - Unauthenticated Sensitive Information Exposure via Unprotected Back-Up Files

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    xagio · xagio seo – ai powered seo28 авг. 2025 г.

  • CVE-2024-9648
    24Наблюдать

    WP ULike Pro <= 1.9.3 - Unauthenticated Limited Arbitrary File Upload

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    wp ulike · wp ulike pro28 авг. 2025 г.

  • CVE-2025-8102
    21Наблюдать

    Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    smub · easy digital downloads – ecommerce payments and subscriptions made easy20 авг. 2025 г.

  • CVE-2025-7654
    35Наблюдать

    Multiple Plugins By FunnelKit <= (Various Versions) - Authenticated (Contributor+) Sensitive Information Exposure to Privilege Escalation via Woofunnel Library

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    amans2k · funnelkit automations – email marketing automation and crm for wordpress & woocommerce19 авг. 2025 г.

  • CVE-2025-8357
    17Наблюдать

    Media Library Assistant <= 3.27 - Authenticated (Author+) Limited File Deletion

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    dglingren · media library assistant19 авг. 2025 г.

  • CVE-2025-8680
    17Наблюдать

    B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Server-Side Request Forgery

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    bplugins · bslider – create responsive image, post, product, and video sliders14 авг. 2025 г.

  • CVE-2025-8676
    17Наблюдать

    B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Sensitive Information Exposure

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    bplugins · bslider – create responsive image, post, product, and video sliders14 авг. 2025 г.

  • CVE-2025-8418
    35Наблюдать

    B Slider- Gutenberg Slider Block for WP <= 1.1.30 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Plugin Installation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bplugins · bslider – create responsive image, post, product, and video sliders12 авг. 2025 г.