NumeX
Patchstack Bug Bounty Program
51 kredili kayıt · son 12 ayda 50 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2026-15291İstismar yok | Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposurethemeatelier · chathelp – click to chat button, woocommerce chat to order & floating chat form · CWE-862 | Yüksek7,5 | — | %0,7 | 10 Tem 2026 |
25İzleyin | CVE-2025-68049İstismar yok | WordPress bunny.net plugin <= 2.3.6 - Broken Access Control vulnerabilitybunny.net · bunny.net · CWE-862 | Orta6,3 | — | %0,2 | 15 Haz 2026 |
17İzleyin | CVE-2025-14481İstismar yok | Yoast SEO <= 26.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'post_id' Parameteryoast · yoast seo – advanced seo with real-time guidance and built-in ai · CWE-862 | Orta4,3 | — | %0,3 | 27 May 2026 |
21İzleyin | CVE-2026-39657İstismar yok | WordPress leadlovers forms plugin <= 1.0.2 - Broken Access Control vulnerabilityleadlovers · leadlovers forms · CWE-862 | Orta5,3 | — | %0,3 | 8 Nis 2026 |
39İzleyin | CVE-2026-32523İstismar yok | WordPress WPJAM Basic plugin <= 6.9.2 - Arbitrary File Upload vulnerabilitydenishua · wpjam basic · CWE-434 | Kritik9,9 | — | %0,5 | 25 Mar 2026 |
36İzleyin | CVE-2026-25447İstismar yok | WordPress Widget Wrangler plugin <= 2.3.9 - Remote Code Execution (RCE) vulnerabilityjonathan daggerhart · widget wrangler · CWE-94 | Kritik9,1 | — | %0,5 | 25 Mar 2026 |
26İzleyin | CVE-2026-24987İstismar yok | WordPress WP System Log plugin <= 1.2.7 - Broken Access Control vulnerabilityactivity-log.com · wp system log · CWE-862 | Orta6,5 | — | %0,4 | 25 Mar 2026 |
30İzleyin | CVE-2026-22448İstismar yok | WordPress PitchPrint plugin <= 11.1.2 - Arbitrary File Deletion vulnerabilityflexcubed · pitchprint · CWE-22 | Yüksek7,5 | — | %0,6 | 25 Mar 2026 |
36İzleyin | CVE-2026-27067İstismar yok | WordPress Mobile App Editor plugin <= 1.3.1 - Arbitrary File Upload vulnerabilitysyarif · mobile app editor · CWE-434 | Kritik9,1 | — | %0,5 | 19 Mar 2026 |
21İzleyin | CVE-2026-32410İstismar yok | WordPress WBW Currency Switcher for WooCommerce plugin <= 2.2.5 - Broken Access Control vulnerabilitywbw plugins · wbw currency switcher for woocommerce · CWE-862 | Orta5,3 | — | %0,3 | 13 Mar 2026 |
37İzleyin | CVE-2026-24956İstismar yok | WordPress Download Manager Addons for Elementor plugin <= 1.3.0 - SQL Injection vulnerabilityshahjada · download manager addons for elementor · CWE-89 | Kritik9,3 | — | %0,2 | 20 Şub 2026 |
30İzleyin | CVE-2026-24950İstismar yok | WordPress Authorsy plugin <= 1.0.6 - Insecure Direct Object References (IDOR) vulnerabilitythemeplugs · authorsy · CWE-639 | Yüksek7,5 | — | %0,3 | 20 Şub 2026 |
30İzleyin | CVE-2025-68834İstismar yok | WordPress Sync Master Sheet – Product Sync with Google Sheet for WooCommerce plugin <= 1.1.3 - Broken Access Control vulnerabilitysaiful islam · sync master sheet – product sync with google sheet for woocommerce · CWE-862 | Yüksek7,5 | — | %0,3 | 20 Şub 2026 |
30İzleyin | CVE-2025-68051İstismar yok | WordPress Shiprocket plugin <= 2.0.8 - Insecure Direct Object References (IDOR) vulnerabilityshiprocket · shiprocket · CWE-639 | Yüksek7,5 | — | %0,3 | 20 Şub 2026 |
26İzleyin | CVE-2025-68050İstismar yok | WordPress Leadpages plugin <= 1.1.3 - Broken Access Control vulnerabilityleadpages · leadpages · CWE-862 | Orta6,5 | — | %0,2 | 20 Şub 2026 |
30İzleyin | CVE-2025-68048İstismar yok | WordPress NextMove Lite plugin <= 2.23.0 - Broken Access Control vulnerabilityxlplugins · nextmove lite · CWE-862 | Yüksek7,5 | — | %0,3 | 20 Şub 2026 |
29İzleyin | CVE-2025-68043Kavram kanıtı | WordPress LottieFiles plugin <= 3.0.0 - Broken Access Control vulnerabilitylottiefiles · lottiefiles · CWE-862 | Yüksek7,3 | — | %0,6 | 20 Şub 2026 |
29İzleyin | CVE-2025-68022İstismar yok | WordPress Plugin BlueX for WooCommerce plugin <= 3.1.6 - Broken Access Control vulnerabilitysoporteblue · plugin bluex for woocommerce · CWE-862 | Yüksek7,3 | — | %0,3 | 20 Şub 2026 |
26İzleyin | CVE-2025-68021İstismar yok | WordPress ConveyThis plugin <= 269.9 - Broken Access Control vulnerabilityconveythis · conveythis · CWE-862 | Orta6,5 | — | %0,3 | 20 Şub 2026 |
30İzleyin | CVE-2025-67974İstismar yok | WordPress WPLegalPages plugin <= 3.5.4 - Broken Access Control vulnerabilitywp legal pages · wplegalpages · CWE-862 | Yüksek7,5 | — | %0,3 | 20 Şub 2026 |
26İzleyin | CVE-2025-67969İstismar yok | WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.5.1 - Broken Access Control vulnerabilityknitpay · upi qr code payment gateway for woocommerce · CWE-862 | Orta6,5 | — | %0,3 | 20 Şub 2026 |
26İzleyin | CVE-2026-23545İstismar yok | WordPress Aruba HiSpeed Cache plugin <= 3.0.4 - Broken Access Control vulnerabilityaruba.it dev · aruba hispeed cache · CWE-862 | Orta6,5 | — | %0,2 | 19 Şub 2026 |
17İzleyin | CVE-2026-24947İstismar yok | WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vulnerabilityla-studio · la-studio element kit for elementor · CWE-862 | Orta4,3 | — | %0,2 | 3 Şub 2026 |
23İzleyin | CVE-2026-22388İstismar yok | WordPress Owl Carousel WP plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerabilityimran emu · owl carousel wp · CWE-79 | Orta5,9 | — | %0,3 | 22 Oca 2026 |
30İzleyin | CVE-2025-68882İstismar yok | WordPress Scalenut plugin <= 1.1.5 - Broken Access Control vulnerabilityscalenut · scalenut · CWE-862 | Yüksek7,5 | — | %0,3 | 22 Oca 2026 |
- CVE-2026-1529130İzleyin
Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure
YüksekCVSS 7,5İstismar yokEPSS %1themeatelier · chathelp – click to chat button, woocommerce chat to order & floating chat form10 Tem 2026
- CVE-2025-6804925İzleyin
WordPress bunny.net plugin <= 2.3.6 - Broken Access Control vulnerability
OrtaCVSS 6,3İstismar yokEPSS %0bunny.net · bunny.net15 Haz 2026
- CVE-2025-1448117İzleyin
Yoast SEO <= 26.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'post_id' Parameter
OrtaCVSS 4,3İstismar yokEPSS %0yoast · yoast seo – advanced seo with real-time guidance and built-in ai27 May 2026
- CVE-2026-3965721İzleyin
WordPress leadlovers forms plugin <= 1.0.2 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0leadlovers · leadlovers forms8 Nis 2026
- CVE-2026-3252339İzleyin
WordPress WPJAM Basic plugin <= 6.9.2 - Arbitrary File Upload vulnerability
KritikCVSS 9,9İstismar yokEPSS %0denishua · wpjam basic25 Mar 2026
- CVE-2026-2544736İzleyin
WordPress Widget Wrangler plugin <= 2.3.9 - Remote Code Execution (RCE) vulnerability
KritikCVSS 9,1İstismar yokEPSS %1jonathan daggerhart · widget wrangler25 Mar 2026
- CVE-2026-2498726İzleyin
WordPress WP System Log plugin <= 1.2.7 - Broken Access Control vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0activity-log.com · wp system log25 Mar 2026
- CVE-2026-2244830İzleyin
WordPress PitchPrint plugin <= 11.1.2 - Arbitrary File Deletion vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1flexcubed · pitchprint25 Mar 2026
- CVE-2026-2706736İzleyin
WordPress Mobile App Editor plugin <= 1.3.1 - Arbitrary File Upload vulnerability
KritikCVSS 9,1İstismar yokEPSS %0syarif · mobile app editor19 Mar 2026
- CVE-2026-3241021İzleyin
WordPress WBW Currency Switcher for WooCommerce plugin <= 2.2.5 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0wbw plugins · wbw currency switcher for woocommerce13 Mar 2026
- CVE-2026-2495637İzleyin
WordPress Download Manager Addons for Elementor plugin <= 1.3.0 - SQL Injection vulnerability
KritikCVSS 9,3İstismar yokEPSS %0shahjada · download manager addons for elementor20 Şub 2026
- CVE-2026-2495030İzleyin
WordPress Authorsy plugin <= 1.0.6 - Insecure Direct Object References (IDOR) vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0themeplugs · authorsy20 Şub 2026
- CVE-2025-6883430İzleyin
WordPress Sync Master Sheet – Product Sync with Google Sheet for WooCommerce plugin <= 1.1.3 - Broken Access Control vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0saiful islam · sync master sheet – product sync with google sheet for woocommerce20 Şub 2026
- CVE-2025-6805130İzleyin
WordPress Shiprocket plugin <= 2.0.8 - Insecure Direct Object References (IDOR) vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0shiprocket · shiprocket20 Şub 2026
- CVE-2025-6805026İzleyin
WordPress Leadpages plugin <= 1.1.3 - Broken Access Control vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0leadpages · leadpages20 Şub 2026
- CVE-2025-6804830İzleyin
WordPress NextMove Lite plugin <= 2.23.0 - Broken Access Control vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0xlplugins · nextmove lite20 Şub 2026
- CVE-2025-6804329İzleyin
WordPress LottieFiles plugin <= 3.0.0 - Broken Access Control vulnerability
YüksekCVSS 7,3Kavram kanıtıEPSS %1lottiefiles · lottiefiles20 Şub 2026
- CVE-2025-6802229İzleyin
WordPress Plugin BlueX for WooCommerce plugin <= 3.1.6 - Broken Access Control vulnerability
YüksekCVSS 7,3İstismar yokEPSS %0soporteblue · plugin bluex for woocommerce20 Şub 2026
- CVE-2025-6802126İzleyin
WordPress ConveyThis plugin <= 269.9 - Broken Access Control vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0conveythis · conveythis20 Şub 2026
- CVE-2025-6797430İzleyin
WordPress WPLegalPages plugin <= 3.5.4 - Broken Access Control vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0wp legal pages · wplegalpages20 Şub 2026
- CVE-2025-6796926İzleyin
WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.5.1 - Broken Access Control vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0knitpay · upi qr code payment gateway for woocommerce20 Şub 2026
- CVE-2026-2354526İzleyin
WordPress Aruba HiSpeed Cache plugin <= 3.0.4 - Broken Access Control vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0aruba.it dev · aruba hispeed cache19 Şub 2026
- CVE-2026-2494717İzleyin
WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vulnerability
OrtaCVSS 4,3İstismar yokEPSS %0la-studio · la-studio element kit for elementor3 Şub 2026
- CVE-2026-2238823İzleyin
WordPress Owl Carousel WP plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 5,9İstismar yokEPSS %0imran emu · owl carousel wp22 Oca 2026
- CVE-2025-6888230İzleyin
WordPress Scalenut plugin <= 1.1.5 - Broken Access Control vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0scalenut · scalenut22 Oca 2026