wesley
325 записей с упоминанием · 9 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
26Наблюдать | CVE-2026-5149Эксплойта нет | RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameterrometheme · rtmkit · CWE-863 | Средняя6,5 | — | 0,4 % | 16 июн. 2026 г. |
30Наблюдать | CVE-2026-3018Proof of concept | Newsletters <= 4.13 - Unauthenticated SQL Injection via wpmlsubscriber_id Parametercontrid · newsletters · CWE-89 | Высокая7,5 | — | 1,5 % | 10 июн. 2026 г. |
31Наблюдать | CVE-2026-5032Proof of concept | W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Headerboldgrid · w3 total cache · CWE-200 | Высокая7,5 | — | 2,7 % | 2 апр. 2026 г. |
24Наблюдать | CVE-2025-13910Эксплойта нет | WP-WebAuthn <= 1.3.4 - Unauthenticated Stored Cross-Site Scriptingaxton · wp-webauthn · CWE-79 | Средняя6,1 | — | 0,3 % | 21 мар. 2026 г. |
32Наблюдать | CVE-2025-14002Эксплойта нет | WPCOM Member <= 1.7.16 - Authentication Bypass via Weak OTPwhyun · wpcom member · CWE-287 | Высокая8,1 | — | 0,5 % | 16 дек. 2025 г. |
35Наблюдать | CVE-2025-8593Эксплойта нет | GSheetConnector For Gravity Forms <= 1.3.27 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installationwesterndeal · gsheetconnector for gravity forms – send gravity forms entries to google sheets in real-time · CWE-862 | Высокая8,8 | — | 0,4 % | 11 окт. 2025 г. |
9Наблюдать | CVE-2025-8606Эксплойта нет | GSheetConnector For Gravity Forms <= 1.3.23 - Cross-Site Request Forgery to Arbitrary Plugin Activation/Deactivationwesterndeal · gsheetconnector for gravity forms – send gravity forms entries to google sheets in real-time · CWE-352 | Низкая2,4 | — | 0,2 % | 11 окт. 2025 г. |
39Наблюдать | CVE-2025-7634Эксплойта нет | WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Unauthenticated Local File Inclusionwptravelengine · wp travel engine – tour booking plugin – tour operator software · CWE-98 | Критическая9,8 | — | 0,8 % | 9 окт. 2025 г. |
39Наблюдать | CVE-2025-7526Эксплойта нет | WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Authenticated (Subscriber+) Arbitrary File Deletion via File Renamingwptravelengine · wp travel engine – tour booking plugin – tour operator software · CWE-22 | Критическая9,8 | — | 0,9 % | 9 окт. 2025 г. |
35Наблюдать | CVE-2025-7052Эксплойта нет | LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Functionlatepoint · latepoint – calendar booking plugin for appointments and events · CWE-352 | Высокая8,8 | — | 0,2 % | 30 сент. 2025 г. |
32Наблюдать | CVE-2025-7038Эксплойта нет | LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Functionlatepoint · latepoint – calendar booking plugin for appointments and events · CWE-288 | Высокая8,2 | — | 0,4 % | 30 сент. 2025 г. |
21Наблюдать | CVE-2025-8487Эксплойта нет | Kubio AI Page Builder <= 2.6.3 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installationextendthemes · kubio ai page builder · CWE-862 | Средняя5,4 | — | 0,3 % | 19 сент. 2025 г. |
32Наблюдать | CVE-2025-8565Эксплойта нет | Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.4.3 - Missing Authorization to Authenticated (Contributor+) Arbitrwplegalpages · privacy policy generator – wplp legal pages · CWE-862 | Высокая8,1 | — | 0,3 % | 18 сент. 2025 г. |
17Наблюдать | CVE-2025-8446Эксплойта нет | Blaze Demo Importer <= 1.0.12 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installblazethemes · blaze demo importer · CWE-862 | Средняя4,3 | — | 0,2 % | 16 сент. 2025 г. |
17Наблюдать | CVE-2025-8481Эксплойта нет | Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid <= 1.1.7 - Cross-Site Request Forgerymdimran41 · blog designer for elementor – post slider, post carousel, post grid · CWE-352 | Средняя4,3 | — | 0,1 % | 11 сент. 2025 г. |
17Наблюдать | CVE-2025-8479Эксплойта нет | Zoho Flow <= 2.14.1 - Cross-Site Request Forgeryzohoflow · zoho flow – integrate 100+ plugins with 1000+ business apps, no-code workflow automation · CWE-352 | Средняя4,3 | — | 0,2 % | 11 сент. 2025 г. |
17Наблюдать | CVE-2025-8147Эксплойта нет | LWSCache <= 2.8.5 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation via lwscache_activatePlugin Functionaurelienlws · lwscache · CWE-285 | Средняя4,3 | — | 0,2 % | 29 авг. 2025 г. |
30Наблюдать | CVE-2024-13807Эксплойта нет | Xagio SEO <= 7.1.0.5 - Unauthenticated Sensitive Information Exposure via Unprotected Back-Up Filesxagio · xagio seo – ai powered seo · CWE-200 | Высокая7,5 | — | 0,4 % | 28 авг. 2025 г. |
24Наблюдать | CVE-2024-9648Эксплойта нет | WP ULike Pro <= 1.9.3 - Unauthenticated Limited Arbitrary File Uploadwp ulike · wp ulike pro · CWE-434 | Средняя6,1 | — | 0,2 % | 28 авг. 2025 г. |
21Наблюдать | CVE-2025-8102Эксплойта нет | Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functionssmub · easy digital downloads – ecommerce payments and subscriptions made easy · CWE-352 | Средняя5,4 | — | 0,2 % | 20 авг. 2025 г. |
35Наблюдать | CVE-2025-7654Эксплойта нет | Multiple Plugins By FunnelKit <= (Various Versions) - Authenticated (Contributor+) Sensitive Information Exposure to Privilege Escalation via Woofunnel Libraryamans2k · funnelkit automations – email marketing automation and crm for wordpress & woocommerce · CWE-200 | Высокая8,8 | — | 0,6 % | 19 авг. 2025 г. |
17Наблюдать | CVE-2025-8357Эксплойта нет | Media Library Assistant <= 3.27 - Authenticated (Author+) Limited File Deletiondglingren · media library assistant · CWE-862 | Средняя4,3 | — | 0,3 % | 19 авг. 2025 г. |
17Наблюдать | CVE-2025-8680Эксплойта нет | B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Server-Side Request Forgerybplugins · bslider – create responsive image, post, product, and video sliders · CWE-918 | Средняя4,3 | — | 0,4 % | 14 авг. 2025 г. |
17Наблюдать | CVE-2025-8676Эксплойта нет | B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Sensitive Information Exposurebplugins · bslider – create responsive image, post, product, and video sliders · CWE-200 | Средняя4,3 | — | 0,4 % | 14 авг. 2025 г. |
35Наблюдать | CVE-2025-8418Эксплойта нет | B Slider- Gutenberg Slider Block for WP <= 1.1.30 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Plugin Installationbplugins · bslider – create responsive image, post, product, and video sliders · CWE-862 | Высокая8,8 | — | 0,6 % | 12 авг. 2025 г. |
- CVE-2026-514926Наблюдать
RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter
СредняяCVSS 6,5Эксплойта нетEPSS 0 %rometheme · rtmkit16 июн. 2026 г.
- CVE-2026-301830Наблюдать
Newsletters <= 4.13 - Unauthenticated SQL Injection via wpmlsubscriber_id Parameter
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %contrid · newsletters10 июн. 2026 г.
- CVE-2026-503231Наблюдать
W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %boldgrid · w3 total cache2 апр. 2026 г.
- CVE-2025-1391024Наблюдать
WP-WebAuthn <= 1.3.4 - Unauthenticated Stored Cross-Site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 0 %axton · wp-webauthn21 мар. 2026 г.
- CVE-2025-1400232Наблюдать
WPCOM Member <= 1.7.16 - Authentication Bypass via Weak OTP
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %whyun · wpcom member16 дек. 2025 г.
- CVE-2025-859335Наблюдать
GSheetConnector For Gravity Forms <= 1.3.27 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %westerndeal · gsheetconnector for gravity forms – send gravity forms entries to google sheets in real-time11 окт. 2025 г.
- CVE-2025-86069Наблюдать
GSheetConnector For Gravity Forms <= 1.3.23 - Cross-Site Request Forgery to Arbitrary Plugin Activation/Deactivation
НизкаяCVSS 2,4Эксплойта нетEPSS 0 %westerndeal · gsheetconnector for gravity forms – send gravity forms entries to google sheets in real-time11 окт. 2025 г.
- CVE-2025-763439Наблюдать
WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Unauthenticated Local File Inclusion
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wptravelengine · wp travel engine – tour booking plugin – tour operator software9 окт. 2025 г.
- CVE-2025-752639Наблюдать
WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Authenticated (Subscriber+) Arbitrary File Deletion via File Renaming
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wptravelengine · wp travel engine – tour booking plugin – tour operator software9 окт. 2025 г.
- CVE-2025-705235Наблюдать
LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %latepoint · latepoint – calendar booking plugin for appointments and events30 сент. 2025 г.
- CVE-2025-703832Наблюдать
LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %latepoint · latepoint – calendar booking plugin for appointments and events30 сент. 2025 г.
- CVE-2025-848721Наблюдать
Kubio AI Page Builder <= 2.6.3 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation
СредняяCVSS 5,4Эксплойта нетEPSS 0 %extendthemes · kubio ai page builder19 сент. 2025 г.
- CVE-2025-856532Наблюдать
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.4.3 - Missing Authorization to Authenticated (Contributor+) Arbitr
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %wplegalpages · privacy policy generator – wplp legal pages18 сент. 2025 г.
- CVE-2025-844617Наблюдать
Blaze Demo Importer <= 1.0.12 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install
СредняяCVSS 4,3Эксплойта нетEPSS 0 %blazethemes · blaze demo importer16 сент. 2025 г.
- CVE-2025-848117Наблюдать
Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid <= 1.1.7 - Cross-Site Request Forgery
СредняяCVSS 4,3Эксплойта нетEPSS 0 %mdimran41 · blog designer for elementor – post slider, post carousel, post grid11 сент. 2025 г.
- CVE-2025-847917Наблюдать
Zoho Flow <= 2.14.1 - Cross-Site Request Forgery
СредняяCVSS 4,3Эксплойта нетEPSS 0 %zohoflow · zoho flow – integrate 100+ plugins with 1000+ business apps, no-code workflow automation11 сент. 2025 г.
- CVE-2025-814717Наблюдать
LWSCache <= 2.8.5 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation via lwscache_activatePlugin Function
СредняяCVSS 4,3Эксплойта нетEPSS 0 %aurelienlws · lwscache29 авг. 2025 г.
- CVE-2024-1380730Наблюдать
Xagio SEO <= 7.1.0.5 - Unauthenticated Sensitive Information Exposure via Unprotected Back-Up Files
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %xagio · xagio seo – ai powered seo28 авг. 2025 г.
- CVE-2024-964824Наблюдать
WP ULike Pro <= 1.9.3 - Unauthenticated Limited Arbitrary File Upload
СредняяCVSS 6,1Эксплойта нетEPSS 0 %wp ulike · wp ulike pro28 авг. 2025 г.
- CVE-2025-810221Наблюдать
Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions
СредняяCVSS 5,4Эксплойта нетEPSS 0 %smub · easy digital downloads – ecommerce payments and subscriptions made easy20 авг. 2025 г.
- CVE-2025-765435Наблюдать
Multiple Plugins By FunnelKit <= (Various Versions) - Authenticated (Contributor+) Sensitive Information Exposure to Privilege Escalation via Woofunnel Library
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %amans2k · funnelkit automations – email marketing automation and crm for wordpress & woocommerce19 авг. 2025 г.
- CVE-2025-835717Наблюдать
Media Library Assistant <= 3.27 - Authenticated (Author+) Limited File Deletion
СредняяCVSS 4,3Эксплойта нетEPSS 0 %dglingren · media library assistant19 авг. 2025 г.
- CVE-2025-868017Наблюдать
B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Server-Side Request Forgery
СредняяCVSS 4,3Эксплойта нетEPSS 0 %bplugins · bslider – create responsive image, post, product, and video sliders14 авг. 2025 г.
- CVE-2025-867617Наблюдать
B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Sensitive Information Exposure
СредняяCVSS 4,3Эксплойта нетEPSS 0 %bplugins · bslider – create responsive image, post, product, and video sliders14 авг. 2025 г.
- CVE-2025-841835Наблюдать
B Slider- Gutenberg Slider Block for WP <= 1.1.30 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Plugin Installation
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bplugins · bslider – create responsive image, post, product, and video sliders12 авг. 2025 г.