Перейти к содержимому
Noroxi

Записи smackcoders

24 опубликованных записей вендора smackcoders.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
4,2 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

24 записей
  • CVE-2016-11000
    40В плане

    The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    smackcoders · ultimate exporter20 сент. 2019 г.

  • CVE-2024-43965
    40В плане

    WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    smackcoders · sendgrid29 авг. 2024 г.

  • CVE-2023-4141
    35Наблюдать

    WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Execution

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    smackcoders · wp ultimate csv importer3 авг. 2023 г.

  • CVE-2023-4142
    35Наблюдать

    WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Execution

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    smackcoders · wp ultimate csv importer3 авг. 2023 г.

  • CVE-2022-3860
    35Наблюдать

    Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLi

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    smackcoders · visual email designer for woocommerce2 янв. 2023 г.

  • CVE-2023-4140
    35Наблюдать

    WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    smackcoders · wp ultimate csv importer3 авг. 2023 г.

  • CVE-2018-20967
    35Наблюдать

    The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv14 авг. 2019 г.

  • CVE-2018-20968
    35Наблюдать

    The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    smackcoders · ultimate exporter14 авг. 2019 г.

  • CVE-2015-10125
    35Наблюдать

    WP Ultimate CSV Importer Plugin cross-site request forgery

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv5 окт. 2023 г.

  • CVE-2023-4139
    30Наблюдать

    WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listing

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    smackcoders · wp ultimate csv importer3 авг. 2023 г.

  • CVE-2023-45066
    30Наблюдать

    WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    smackcoders · export all posts\, products\, orders\, refunds \& users30 нояб. 2023 г.

  • CVE-2024-12315
    30Наблюдать

    Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directory

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    smackcoders · export all posts\, products\, orders\, refunds \& users12 февр. 2025 г.

  • CVE-2023-2487
    30Наблюдать

    WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    smackcoders · export all posts\, products\, orders\, refunds \& users21 дек. 2023 г.

  • CVE-2022-1977
    28Наблюдать

    WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRF

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv27 июн. 2022 г.

  • CVE-2022-3243
    28Наблюдать

    Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLi

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv17 окт. 2022 г.

  • CVE-2013-3264
    26Наблюдать

    The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2

    СредняяCVSS 6,4Эксплойта нетEPSS 2 %

    smackcoders · wp ultimate email marketer plugin5 нояб. 2013 г.

  • CVE-2016-10985
    24Наблюдать

    The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    smackcoders · echo sign17 сент. 2019 г.

  • CVE-2016-10984
    24Наблюдать

    The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    smackcoders · echo sign17 сент. 2019 г.

  • CVE-2015-9306
    24Наблюдать

    The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv12 авг. 2019 г.

  • CVE-2022-0360
    19Наблюдать

    WP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site Scripting

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv28 февр. 2022 г.

  • CVE-2013-3263
    17Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    smackcoders · wp ultimate email marketer plugin5 нояб. 2013 г.

  • CVE-2024-9364
    17Наблюдать

    SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletion

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    smackcoders · sendgrid18 окт. 2024 г.

  • CVE-2025-5692
    17Наблюдать

    Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actions

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    smackcoders · lead form data collection to crm1 июл. 2025 г.

  • CVE-2022-3244
    16Наблюдать

    Import all XML, CSV & TXT into WordPress < 6.5.8 - Missing Authorisation

    СредняяCVSS 4,2Эксплойта нетEPSS 0 %

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv17 окт. 2022 г.