Mitchell
Patchstack Bug Bounty Program
10 kredili kayıt · son 12 ayda 10 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
25İzleyin | CVE-2026-13770İstismar yok | AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handlerappmysite · appmysite – wordpress & woocommerce mobile app builder (no-code android & ios app maker) · CWE-79 | Orta6,4 | — | %0,2 | 19 Eyl 2026 |
25İzleyin | CVE-2026-14855İstismar yok | RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Actionthemewant · rt mega menu – mega menu builder for elementor & gutenberg · CWE-79 | Orta6,4 | — | %0,2 | 17 Eyl 2026 |
30İzleyin | CVE-2026-12000İstismar yok | Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST APIcyberlord92 · page and post restriction · CWE-862 | Yüksek7,5 | — | %0,7 | 5 Ağu 2026 |
30İzleyin | CVE-2026-66473İstismar yok | WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerabilityxendit · xendit payment · CWE-862 | Yüksek7,5 | — | %0,3 | 27 Tem 2026 |
30İzleyin | CVE-2026-59534İstismar yok | WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerabilityaurovrata venet · post my cf7 form · CWE-862 | Yüksek7,5 | — | %0,3 | 27 Tem 2026 |
30İzleyin | CVE-2026-59554İstismar yok | WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerabilityziina · ziina · CWE-1390 | Yüksek7,5 | — | %0,4 | 23 Tem 2026 |
26İzleyin | CVE-2026-57419İstismar yok | WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerabilityfahad mahmood · stock locations for woocommerce · CWE-862 | Orta6,5 | — | %0,3 | 13 Tem 2026 |
17İzleyin | CVE-2026-12103İstismar yok | Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Actionsubratamal · wallet for woocommerce · CWE-862 | Orta4,3 | — | %0,5 | 11 Tem 2026 |
30İzleyin | CVE-2026-14249İstismar yok | Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameteremarket-design · request a quote – quote forms for any wordpress site · CWE-74 | Yüksek7,5 | — | %0,6 | 2 Tem 2026 |
30İzleyin | CVE-2026-49061İstismar yok | WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerabilitywpclever · wpc product options for woocommerce · CWE-22 | Yüksek7,5 | — | %0,5 | 15 Haz 2026 |
- CVE-2026-1377025İzleyin
AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handler
OrtaCVSS 6,4İstismar yokEPSS %0appmysite · appmysite – wordpress & woocommerce mobile app builder (no-code android & ios app maker)19 Eyl 2026
- CVE-2026-1485525İzleyin
RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Action
OrtaCVSS 6,4İstismar yokEPSS %0themewant · rt mega menu – mega menu builder for elementor & gutenberg17 Eyl 2026
- CVE-2026-1200030İzleyin
Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API
YüksekCVSS 7,5İstismar yokEPSS %1cyberlord92 · page and post restriction5 Ağu 2026
- CVE-2026-6647330İzleyin
WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0xendit · xendit payment27 Tem 2026
- CVE-2026-5953430İzleyin
WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0aurovrata venet · post my cf7 form27 Tem 2026
- CVE-2026-5955430İzleyin
WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0ziina · ziina23 Tem 2026
- CVE-2026-5741926İzleyin
WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0fahad mahmood · stock locations for woocommerce13 Tem 2026
- CVE-2026-1210317İzleyin
Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
OrtaCVSS 4,3İstismar yokEPSS %0subratamal · wallet for woocommerce11 Tem 2026
- CVE-2026-1424930İzleyin
Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter
YüksekCVSS 7,5İstismar yokEPSS %1emarket-design · request a quote – quote forms for any wordpress site2 Tem 2026
- CVE-2026-4906130İzleyin
WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1wpclever · wpc product options for woocommerce15 Haz 2026