ThemeinProgress kayıtları
themeinprogress üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2022-42884İstismar yok | WordPress WIP Custom Login Plugin <= 1.2.7 is vulnerable to Broken Access Controlthemeinprogress · wip custom login · CWE-862 | Yüksek8,8 | — | %0,4 | 17 Oca 2024 |
35İzleyin | CVE-2023-33313İstismar yok | WordPress WIP Custom Login Plugin <= 1.2.9 is vulnerable to Cross Site Request Forgery (CSRF)themeinprogress · wip custom login · CWE-352 | Yüksek8,8 | — | %0,3 | 28 May 2023 |
25İzleyin | CVE-2020-17362Kavram kanıtı | search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.themeinprogress · nova lite · CWE-79 | Orta6,1 | — | %2,9 | 12 Ağu 2020 |
24İzleyin | CVE-2023-2813Kavram kanıtı | Multiple Themes - Reflected XSSajaydsouza · connections reloaded · CWE-79 | Orta6,1 | — | %1,0 | 4 Eyl 2023 |
- CVE-2022-4288435İzleyin
WordPress WIP Custom Login Plugin <= 1.2.7 is vulnerable to Broken Access Control
YüksekCVSS 8,8İstismar yokEPSS %0themeinprogress · wip custom login17 Oca 2024
- CVE-2023-3331335İzleyin
WordPress WIP Custom Login Plugin <= 1.2.9 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0themeinprogress · wip custom login28 May 2023
- CVE-2020-1736225İzleyin
search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.
OrtaCVSS 6,1Kavram kanıtıEPSS %3themeinprogress · nova lite12 Ağu 2020
- CVE-2023-281324İzleyin
Multiple Themes - Reflected XSS
OrtaCVSS 6,1Kavram kanıtıEPSS %1ajaydsouza · connections reloaded4 Eyl 2023