strangerstudios kayıtları
strangerstudios üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3,8
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %38,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-639 Authorization Bypass Through User-Controlled Key2
- CWE-862 Missing Authorization2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
67Bu hafta | CVE-2023-23488Silahlaştırılmış | The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parastrangerstudios · paid memberships pro · CWE-89 | Kritik9,8 | — | %92,5 | 20 Oca 2023 |
64Bu hafta | CVE-2021-25114Kavram kanıtı | Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injectionstrangerstudios · paid memberships pro · CWE-89 | Kritik9,8 | — | %81,8 | 7 Şub 2022 |
53Planlayın | CVE-2023-0631İstismar yok | Paid Memberships Pro < 2.9.12 - Subscriber+ SQL Injectionstrangerstudios · paid memberships pro · CWE-89 | Yüksek8,8 | — | %60,5 | 20 Mar 2023 |
50Planlayın | CVE-2023-6187İstismar yok | Paid Memberships Pro <= 2.12.3 - Authenticated (Subscriber+) Arbitrary File Uploadstrangerstudios · paid memberships pro · CWE-434 | Yüksek8,8 | — | %51,3 | 17 Kas 2023 |
41Planlayın | CVE-2022-4830İstismar yok | Paid Memberships Pro < 2.9.9 - Contributor+ Stored XSS via Shortcodestrangerstudios · paid memberships pro · CWE-79 | Orta5,4 | — | %65,0 | 13 Şub 2023 |
39İzleyin | CVE-2024-37277İstismar yok | WordPress Paid Memberships Pro plugin <= 3.0.4 - Insecure Direct Object References (IDOR) vulnerabilitystrangerstudios · paid memberships pro · CWE-639 | Kritik9,8 | — | %0,7 | 1 Kas 2024 |
36İzleyin | CVE-2021-20678İstismar yok | SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary Sstrangerstudios · paid memberships pro · CWE-89 | Yüksek8,8 | — | %2,0 | 17 Mar 2021 |
35İzleyin | CVE-2023-39990İstismar yok | WordPress Paid Memberships Pro plugin <= 1.2.3 - Broken Access Control vulnerabilitystrangerstudios · paid memberships pro · CWE-862 | Yüksek8,8 | — | %0,5 | 19 Haz 2024 |
35İzleyin | CVE-2023-28419İstismar yok | WordPress Force First and Last Name as Display Name Plugin <= 1.2 is vulnerable to Cross Site Request Forgery (CSRF)strangerstudios · force display name · CWE-352 | Yüksek8,8 | — | %0,4 | 12 Kas 2023 |
35İzleyin | CVE-2024-32794İstismar yok | WordPress Paid Memberships Pro plugin <= 2.12.10 - Cross Site Request Forgery (CSRF) vulnerabilitystrangerstudios · paid memberships pro · CWE-352 | Yüksek8,8 | — | %0,2 | 24 Nis 2024 |
35İzleyin | CVE-2024-32793İstismar yok | WordPress Paid Memberships Pro plugin <= 2.12.10 - Cross Site Request Forgery (CSRF) vulnerabilitystrangerstudios · paid memberships pro · CWE-352 | Yüksek8,8 | — | %0,2 | 24 Nis 2024 |
28İzleyin | CVE-2020-5579İstismar yok | SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary Sstrangerstudios · paid memberships pro · CWE-89 | Yüksek7,2 | — | %1,2 | 20 May 2020 |
28İzleyin | CVE-2024-37486İstismar yok | WordPress Paid Memberships Pro plugin <= 3.0.5 - Authenticated SQL Injection vulnerabilitystrangerstudios · paid memberships pro · CWE-89 | Yüksek7,2 | — | %0,7 | 9 Tem 2024 |
26İzleyin | CVE-2024-1287İstismar yok | Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQListrangerstudios · paid memberships pro · CWE-202 | Orta6,5 | — | %0,5 | 30 Tem 2024 |
25İzleyin | CVE-2014-8801Kavram kanıtı | Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attacstrangerstudios · paid memberships pro · CWE-22 | Orta5,0 | — | %18,0 | 28 Kas 2014 |
25İzleyin | CVE-2015-5532İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attstrangerstudios · paid memberships pro · CWE-79 | Orta6,1 | — | %2,1 | 23 Eki 2017 |
25İzleyin | CVE-2021-24979Kavram kanıtı | Paid Memberships Pro < 2.6.6 - Reflected Cross-Site Scriptingstrangerstudios · paid memberships pro · CWE-79 | Orta6,1 | — | %1,9 | 27 Ara 2021 |
21İzleyin | CVE-2024-0624Kavram kanıtı | Paid Memberships Pro <= 2.12.7 - Cross-Site Request Forgery to Level Orders Updatestrangerstudios · paid memberships pro · CWE-352 | Orta5,3 | — | %1,0 | 24 Oca 2024 |
21İzleyin | CVE-2023-6855İstismar yok | Paid Memberships Pro <= 2.12.5 - Missing Authorization via APIstrangerstudios · paid memberships pro · CWE-862 | Orta5,3 | — | %0,5 | 11 Oca 2024 |
21İzleyin | CVE-2023-5237İstismar yok | Memberlite Shortcodes < 1.3.9 - Contributor+ Stored XSS via Shortcodestrangerstudios · memberlite shortcodes · CWE-79 | Orta5,4 | — | %0,4 | 31 Eki 2023 |
21İzleyin | CVE-2024-1407İstismar yok | Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery to Membership Modificationstrangerstudios · paid memberships pro · CWE-352 | Orta5,4 | — | %0,2 | 19 Haz 2024 |
19İzleyin | CVE-2024-1286İstismar yok | Paid Memberships Pro - Membership Maps Add On < 0.7 - Contributor+ Sensitive Information Disclosurestrangerstudios · paid memberships pro · CWE-639 | Orta4,9 | — | %0,6 | 30 Tem 2024 |
17İzleyin | CVE-2024-0588Kavram kanıtı | Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgerystrangerstudios · paid memberships pro · CWE-352 | Orta4,3 | — | %0,9 | 9 Nis 2024 |
17İzleyin | CVE-2024-1279İstismar yok | Paid Memberships Pro < 2.12.9 - Contributor+ Arbitrary User Custom Field Disclosurestrangerstudios · paid memberships pro · CWE-284 | Orta4,3 | — | %0,5 | 11 Mar 2024 |
17İzleyin | CVE-2020-36754İstismar yok | Paid Memberships Pro <= 2.4.2 - Cross-Site Request Forgery Bypassstrangerstudios · paid memberships pro · CWE-352 | Orta4,3 | — | %0,4 | 20 Eki 2023 |
- CVE-2023-2348867Bu hafta
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' para
KritikCVSS 9,8SilahlaştırılmışEPSS %92strangerstudios · paid memberships pro20 Oca 2023
- CVE-2021-2511464Bu hafta
Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection
KritikCVSS 9,8Kavram kanıtıEPSS %82strangerstudios · paid memberships pro7 Şub 2022
- CVE-2023-063153Planlayın
Paid Memberships Pro < 2.9.12 - Subscriber+ SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %60strangerstudios · paid memberships pro20 Mar 2023
- CVE-2023-618750Planlayın
Paid Memberships Pro <= 2.12.3 - Authenticated (Subscriber+) Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %51strangerstudios · paid memberships pro17 Kas 2023
- CVE-2022-483041Planlayın
Paid Memberships Pro < 2.9.9 - Contributor+ Stored XSS via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %65strangerstudios · paid memberships pro13 Şub 2023
- CVE-2024-3727739İzleyin
WordPress Paid Memberships Pro plugin <= 3.0.4 - Insecure Direct Object References (IDOR) vulnerability
KritikCVSS 9,8İstismar yokEPSS %1strangerstudios · paid memberships pro1 Kas 2024
- CVE-2021-2067836İzleyin
SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary S
YüksekCVSS 8,8İstismar yokEPSS %2strangerstudios · paid memberships pro17 Mar 2021
- CVE-2023-3999035İzleyin
WordPress Paid Memberships Pro plugin <= 1.2.3 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0strangerstudios · paid memberships pro19 Haz 2024
- CVE-2023-2841935İzleyin
WordPress Force First and Last Name as Display Name Plugin <= 1.2 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0strangerstudios · force display name12 Kas 2023
- CVE-2024-3279435İzleyin
WordPress Paid Memberships Pro plugin <= 2.12.10 - Cross Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0strangerstudios · paid memberships pro24 Nis 2024
- CVE-2024-3279335İzleyin
WordPress Paid Memberships Pro plugin <= 2.12.10 - Cross Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0strangerstudios · paid memberships pro24 Nis 2024
- CVE-2020-557928İzleyin
SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary S
YüksekCVSS 7,2İstismar yokEPSS %1strangerstudios · paid memberships pro20 May 2020
- CVE-2024-3748628İzleyin
WordPress Paid Memberships Pro plugin <= 3.0.5 - Authenticated SQL Injection vulnerability
YüksekCVSS 7,2İstismar yokEPSS %1strangerstudios · paid memberships pro9 Tem 2024
- CVE-2024-128726İzleyin
Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi
OrtaCVSS 6,5İstismar yokEPSS %1strangerstudios · paid memberships pro30 Tem 2024
- CVE-2014-880125İzleyin
Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attac
OrtaCVSS 5,0Kavram kanıtıEPSS %18strangerstudios · paid memberships pro28 Kas 2014
- CVE-2015-553225İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote att
OrtaCVSS 6,1İstismar yokEPSS %2strangerstudios · paid memberships pro23 Eki 2017
- CVE-2021-2497925İzleyin
Paid Memberships Pro < 2.6.6 - Reflected Cross-Site Scripting
OrtaCVSS 6,1Kavram kanıtıEPSS %2strangerstudios · paid memberships pro27 Ara 2021
- CVE-2024-062421İzleyin
Paid Memberships Pro <= 2.12.7 - Cross-Site Request Forgery to Level Orders Update
OrtaCVSS 5,3Kavram kanıtıEPSS %1strangerstudios · paid memberships pro24 Oca 2024
- CVE-2023-685521İzleyin
Paid Memberships Pro <= 2.12.5 - Missing Authorization via API
OrtaCVSS 5,3İstismar yokEPSS %1strangerstudios · paid memberships pro11 Oca 2024
- CVE-2023-523721İzleyin
Memberlite Shortcodes < 1.3.9 - Contributor+ Stored XSS via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0strangerstudios · memberlite shortcodes31 Eki 2023
- CVE-2024-140721İzleyin
Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery to Membership Modification
OrtaCVSS 5,4İstismar yokEPSS %0strangerstudios · paid memberships pro19 Haz 2024
- CVE-2024-128619İzleyin
Paid Memberships Pro - Membership Maps Add On < 0.7 - Contributor+ Sensitive Information Disclosure
OrtaCVSS 4,9İstismar yokEPSS %1strangerstudios · paid memberships pro30 Tem 2024
- CVE-2024-058817İzleyin
Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery
OrtaCVSS 4,3Kavram kanıtıEPSS %1strangerstudios · paid memberships pro9 Nis 2024
- CVE-2024-127917İzleyin
Paid Memberships Pro < 2.12.9 - Contributor+ Arbitrary User Custom Field Disclosure
OrtaCVSS 4,3İstismar yokEPSS %1strangerstudios · paid memberships pro11 Mar 2024
- CVE-2020-3675417İzleyin
Paid Memberships Pro <= 2.4.2 - Cross-Site Request Forgery Bypass
OrtaCVSS 4,3İstismar yokEPSS %0strangerstudios · paid memberships pro20 Eki 2023