wpdeveloper kayıtları
wpdeveloper üreticisine ait 137 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %32,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')75
- CWE-862 Missing Authorization29
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-502 Deserialization of Untrusted Data4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
137 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2024-1698Kavram kanıtı | NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injectionwpdeveloper · notificationx · CWE-89 | Kritik9,8 | — | %77,6 | 27 Şub 2024 |
62Bu hafta | CVE-2023-32243Kavram kanıtı | WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalationwpdeveloper · essential addons for elementor · CWE-287 | Kritik9,8 | — | %75,5 | 12 May 2023 |
54Planlayın | CVE-2023-6623Kavram kanıtı | Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusionwpdeveloper · essential blocks · CWE-22 | Kritik9,8 | — | %50,7 | 15 Oca 2024 |
49Planlayın | CVE-2022-0349Kavram kanıtı | NotificationX < 2.3.9 - Unauthenticated Blind SQL Injectionwpdeveloper · notificationx · CWE-89 | Kritik9,8 | — | %34,4 | 7 Mar 2022 |
40Planlayın | CVE-2023-2833Kavram kanıtı | ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalationwpdeveloper · reviewx · CWE-269 | Yüksek8,8 | — | %17,5 | 6 Haz 2023 |
40Planlayın | CVE-2022-0320İstismar yok | Essential Addons for Elementor < 5.0.5 - Unauthenticated LFIwpdeveloper · essential addons for elementor · CWE-22 | Kritik9,8 | — | %2,0 | 1 Şub 2022 |
39İzleyin | CVE-2023-4402İstismar yok | Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via productswpdeveloper · essential blocks · CWE-502 | Kritik9,8 | — | %1,5 | 20 Eki 2023 |
39İzleyin | CVE-2022-46809İstismar yok | WordPress ReviewX Plugin <= 1.6.7 is vulnerable to CSV Injectionwpdeveloper · reviewx · CWE-1236 | Kritik9,8 | — | %0,8 | 7 Kas 2023 |
39İzleyin | CVE-2024-43328İstismar yok | WordPress EmbedPress plugin <= 4.0.9 - Local File Inclusion vulnerabilitywpdeveloper · embedpress · CWE-22 | Kritik9,8 | — | %0,5 | 19 Ağu 2024 |
39İzleyin | CVE-2024-43323İstismar yok | WordPress ReviewX plugin <= 1.6.28 - Broken Access Control vulnerabilitywpdeveloper · reviewx · CWE-862 | Kritik9,8 | — | %0,5 | 1 Kas 2024 |
39İzleyin | CVE-2024-31284İstismar yok | WordPress EmbedPress plugin <= 3.9.8 - Broken Access Control vulnerabilitywpdeveloper · embedpress · CWE-862 | Kritik9,8 | — | %0,4 | 9 Haz 2024 |
36İzleyin | CVE-2021-24356Kavram kanıtı | Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Arbitrary Plugin Activationwpdeveloper · simple 301 redirects · CWE-862 | Yüksek8,8 | — | %2,6 | 14 Haz 2021 |
36İzleyin | CVE-2024-30226İstismar yok | WordPress BetterDocs plugin <= 3.3.3 - Unauthenticated PHP Object Injection vulnerabilitywpdeveloper · betterdocs · CWE-502 | Kritik9,0 | — | %0,9 | 28 Mar 2024 |
35İzleyin | CVE-2021-24354İstismar yok | Simple 301 Redirects by BetterLinks - 2.0.0-2.0.3 - Arbitrary Plugin Installationwpdeveloper · simple 301 redirects · CWE-862 | Yüksek8,8 | — | %1,5 | 14 Haz 2021 |
35İzleyin | CVE-2021-24352İstismar yok | Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Exportwpdeveloper · simple 301 redirects · CWE-862 | Yüksek8,8 | — | %1,2 | 14 Haz 2021 |
35İzleyin | CVE-2021-24353İstismar yok | Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Importwpdeveloper · simple 301 redirects · CWE-862 | Yüksek8,8 | — | %1,1 | 14 Haz 2021 |
35İzleyin | CVE-2023-26325İstismar yok | The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValwpdeveloper · reviewx · CWE-89 | Yüksek8,8 | — | %0,9 | 23 Şub 2023 |
35İzleyin | CVE-2023-41955İstismar yok | WordPress Essential Addons for Elementor plugin <= 5.8.8 - Contributor+ Privilege Escalation vulnerabilitywpdeveloper · essential addons for elementor · CWE-269 | Yüksek8,8 | — | %0,8 | 17 May 2024 |
35İzleyin | CVE-2024-3018İstismar yok | Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpasswordwpdeveloper · essential addons for elementor · CWE-502 | Yüksek8,8 | — | %0,8 | 30 Mar 2024 |
35İzleyin | CVE-2017-18504İstismar yok | The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.wpdeveloper · twitter cards meta · CWE-352 | Yüksek8,8 | — | %0,7 | 12 Ağu 2019 |
35İzleyin | CVE-2023-51359İstismar yok | WordPress Essential Blocks plugin <= 4.2.0 - Multiple Contributor+ Broken Access Control vulnerabilitywpdeveloper · essential blocks · CWE-862 | Yüksek8,8 | — | %0,6 | 9 Ara 2024 |
35İzleyin | CVE-2023-51360İstismar yok | WordPress Essential Blocks plugin <= 4.2.0 - Multiple Subscriber+ Broken Access Control vulnerabilitywpdeveloper · essential blocks · CWE-862 | Yüksek8,8 | — | %0,6 | 9 Ara 2024 |
35İzleyin | CVE-2024-43129İstismar yok | WordPress BetterDocs plugin <= 3.5.8 - Local File Inclusion vulnerabilitywpdeveloper · betterdocs · CWE-22 | Yüksek8,8 | — | %0,6 | 13 Ağu 2024 |
35İzleyin | CVE-2021-4447İstismar yok | Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalationwpdeveloper · essential addons for elementor · CWE-862 | Yüksek8,8 | — | %0,5 | 16 Eki 2024 |
35İzleyin | CVE-2024-38707İstismar yok | WordPress EmbedPress plugin <= 4.0.4 - Broken Access Control vulnerabilitywpdeveloper · embedpress · CWE-862 | Yüksek8,8 | — | %0,4 | 1 Kas 2024 |
- CVE-2024-169862Bu hafta
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
KritikCVSS 9,8Kavram kanıtıEPSS %78wpdeveloper · notificationx27 Şub 2024
- CVE-2023-3224362Bu hafta
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
KritikCVSS 9,8Kavram kanıtıEPSS %76wpdeveloper · essential addons for elementor12 May 2023
- CVE-2023-662354Planlayın
Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusion
KritikCVSS 9,8Kavram kanıtıEPSS %51wpdeveloper · essential blocks15 Oca 2024
- CVE-2022-034949Planlayın
NotificationX < 2.3.9 - Unauthenticated Blind SQL Injection
KritikCVSS 9,8Kavram kanıtıEPSS %34wpdeveloper · notificationx7 Mar 2022
- CVE-2023-283340Planlayın
ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
YüksekCVSS 8,8Kavram kanıtıEPSS %17wpdeveloper · reviewx6 Haz 2023
- CVE-2022-032040Planlayın
Essential Addons for Elementor < 5.0.5 - Unauthenticated LFI
KritikCVSS 9,8İstismar yokEPSS %2wpdeveloper · essential addons for elementor1 Şub 2022
- CVE-2023-440239İzleyin
Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via products
KritikCVSS 9,8İstismar yokEPSS %1wpdeveloper · essential blocks20 Eki 2023
- CVE-2022-4680939İzleyin
WordPress ReviewX Plugin <= 1.6.7 is vulnerable to CSV Injection
KritikCVSS 9,8İstismar yokEPSS %1wpdeveloper · reviewx7 Kas 2023
- CVE-2024-4332839İzleyin
WordPress EmbedPress plugin <= 4.0.9 - Local File Inclusion vulnerability
KritikCVSS 9,8İstismar yokEPSS %0wpdeveloper · embedpress19 Ağu 2024
- CVE-2024-4332339İzleyin
WordPress ReviewX plugin <= 1.6.28 - Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %0wpdeveloper · reviewx1 Kas 2024
- CVE-2024-3128439İzleyin
WordPress EmbedPress plugin <= 3.9.8 - Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %0wpdeveloper · embedpress9 Haz 2024
- CVE-2021-2435636İzleyin
Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Arbitrary Plugin Activation
YüksekCVSS 8,8Kavram kanıtıEPSS %3wpdeveloper · simple 301 redirects14 Haz 2021
- CVE-2024-3022636İzleyin
WordPress BetterDocs plugin <= 3.3.3 - Unauthenticated PHP Object Injection vulnerability
KritikCVSS 9,0İstismar yokEPSS %1wpdeveloper · betterdocs28 Mar 2024
- CVE-2021-2435435İzleyin
Simple 301 Redirects by BetterLinks - 2.0.0-2.0.3 - Arbitrary Plugin Installation
YüksekCVSS 8,8İstismar yokEPSS %1wpdeveloper · simple 301 redirects14 Haz 2021
- CVE-2021-2435235İzleyin
Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Export
YüksekCVSS 8,8İstismar yokEPSS %1wpdeveloper · simple 301 redirects14 Haz 2021
- CVE-2021-2435335İzleyin
Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Import
YüksekCVSS 8,8İstismar yokEPSS %1wpdeveloper · simple 301 redirects14 Haz 2021
- CVE-2023-2632535İzleyin
The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterVal
YüksekCVSS 8,8İstismar yokEPSS %1wpdeveloper · reviewx23 Şub 2023
- CVE-2023-4195535İzleyin
WordPress Essential Addons for Elementor plugin <= 5.8.8 - Contributor+ Privilege Escalation vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1wpdeveloper · essential addons for elementor17 May 2024
- CVE-2024-301835İzleyin
Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword
YüksekCVSS 8,8İstismar yokEPSS %1wpdeveloper · essential addons for elementor30 Mar 2024
- CVE-2017-1850435İzleyin
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1wpdeveloper · twitter cards meta12 Ağu 2019
- CVE-2023-5135935İzleyin
WordPress Essential Blocks plugin <= 4.2.0 - Multiple Contributor+ Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1wpdeveloper · essential blocks9 Ara 2024
- CVE-2023-5136035İzleyin
WordPress Essential Blocks plugin <= 4.2.0 - Multiple Subscriber+ Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1wpdeveloper · essential blocks9 Ara 2024
- CVE-2024-4312935İzleyin
WordPress BetterDocs plugin <= 3.5.8 - Local File Inclusion vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1wpdeveloper · betterdocs13 Ağu 2024
- CVE-2021-444735İzleyin
Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalation
YüksekCVSS 8,8İstismar yokEPSS %0wpdeveloper · essential addons for elementor16 Eki 2024
- CVE-2024-3870735İzleyin
WordPress EmbedPress plugin <= 4.0.4 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0wpdeveloper · embedpress1 Kas 2024