Записи wpwebinfotech
9 опубликованных записей вендора wpwebinfotech.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 22,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-862 Missing Authorization3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2024-6756Эксплойта нет | Social Auto Poster <= 5.3.14 - Authenticated (Contributor+) Arbitrary File Uploadwpwebinfotech · social auto poster · CWE-434 | Высокая8,8 | — | 0,8 % | 23 июл. 2024 г. |
35Наблюдать | CVE-2024-49272Эксплойта нет | WordPress Social Auto Poster plugin <= 5.3.15 - Cross Site Request Forgery (CSRF) vulnerabilitywpwebinfotech · social auto poster · CWE-352 | Высокая8,8 | — | 0,2 % | 20 окт. 2024 г. |
30Наблюдать | CVE-2024-6750Эксплойта нет | Social Auto Poster <= 5.3.14 - Missing Authorization via Multiple Functionswpwebinfotech · social auto poster · CWE-862 | Высокая7,5 | — | 0,3 % | 23 июл. 2024 г. |
26Наблюдать | CVE-2024-6751Эксплойта нет | Social Auto Poster <= 5.3.14 - Cross-Site Request Forgery via Multiple Functionswpwebinfotech · social auto poster · CWE-352 | Средняя6,5 | — | 0,2 % | 23 июл. 2024 г. |
24Наблюдать | CVE-2024-6753Proof of concept | Social Auto Poster <= 5.3.14 - Unauthenticated Stored Cross-Site Scriptingwpwebinfotech · social auto poster · CWE-79 | Средняя6,1 | — | 0,8 % | 23 июл. 2024 г. |
24Наблюдать | CVE-2024-47369Эксплойта нет | WordPress Social Auto Poster plugin <= 5.3.15 - Reflected Cross Site Scripting (XSS) vulnerabilitywpwebinfotech · social auto poster · CWE-79 | Средняя6,1 | — | 0,3 % | 5 окт. 2024 г. |
21Наблюдать | CVE-2024-6755Эксплойта нет | Social Auto Poster <= 5.3.14 - Missing Authorization to Unauthenticated Arbitrary Post Deletionwpwebinfotech · social auto poster · CWE-862 | Средняя5,3 | — | 0,3 % | 23 июл. 2024 г. |
21Наблюдать | CVE-2024-6752Эксплойта нет | Social Auto Poster <= 5.3.14 - Authenticated (Subscriber+) Stored Cross-Site Scriptingwpwebinfotech · social auto poster · CWE-79 | Средняя5,4 | — | 0,3 % | 23 июл. 2024 г. |
17Наблюдать | CVE-2024-6754Эксплойта нет | Social Auto Poster <= 5.3.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update via wpw_auto_poster_update_tweet_templatewpwebinfotech · social auto poster · CWE-862 | Средняя4,3 | — | 0,3 % | 23 июл. 2024 г. |
- CVE-2024-675635Наблюдать
Social Auto Poster <= 5.3.14 - Authenticated (Contributor+) Arbitrary File Upload
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wpwebinfotech · social auto poster23 июл. 2024 г.
- CVE-2024-4927235Наблюдать
WordPress Social Auto Poster plugin <= 5.3.15 - Cross Site Request Forgery (CSRF) vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wpwebinfotech · social auto poster20 окт. 2024 г.
- CVE-2024-675030Наблюдать
Social Auto Poster <= 5.3.14 - Missing Authorization via Multiple Functions
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %wpwebinfotech · social auto poster23 июл. 2024 г.
- CVE-2024-675126Наблюдать
Social Auto Poster <= 5.3.14 - Cross-Site Request Forgery via Multiple Functions
СредняяCVSS 6,5Эксплойта нетEPSS 0 %wpwebinfotech · social auto poster23 июл. 2024 г.
- CVE-2024-675324Наблюдать
Social Auto Poster <= 5.3.14 - Unauthenticated Stored Cross-Site Scripting
СредняяCVSS 6,1Proof of conceptEPSS 1 %wpwebinfotech · social auto poster23 июл. 2024 г.
- CVE-2024-4736924Наблюдать
WordPress Social Auto Poster plugin <= 5.3.15 - Reflected Cross Site Scripting (XSS) vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 0 %wpwebinfotech · social auto poster5 окт. 2024 г.
- CVE-2024-675521Наблюдать
Social Auto Poster <= 5.3.14 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
СредняяCVSS 5,3Эксплойта нетEPSS 0 %wpwebinfotech · social auto poster23 июл. 2024 г.
- CVE-2024-675221Наблюдать
Social Auto Poster <= 5.3.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 0 %wpwebinfotech · social auto poster23 июл. 2024 г.
- CVE-2024-675417Наблюдать
Social Auto Poster <= 5.3.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update via wpw_auto_poster_update_tweet_template
СредняяCVSS 4,3Эксплойта нетEPSS 0 %wpwebinfotech · social auto poster23 июл. 2024 г.