WPFactory kayıtları
wpfactory üreticisine ait 29 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %31
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-862 Missing Authorization2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-287 Improper Authentication1
- CWE-330 Use of Insufficiently Random Values1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
29 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-31276İstismar yok | WordPress Products, Order & Customers Export for WooCommerce plugin <= 2.0.8 - Broken Access Control vulnerabilitywpfactory · products\, order \& customers export for woocommerce · CWE-862 | Kritik9,8 | — | %0,4 | 9 Haz 2024 |
37İzleyin | CVE-2024-49305İstismar yok | WordPress Customer Email Verification for WooCommerce plugin <= 2.8.10 - SQL Injection vulnerabilitywpfactory · email verification for woocommerce · CWE-89 | Kritik9,3 | — | %0,4 | 17 Eki 2024 |
32İzleyin | CVE-2024-4185İstismar yok | Customer Email Verification for WooCommerce <= 2.7.4 - Email Verification and Authentication Bypass due to Insufficient Randomnesswpcodefactory · customer email verification for woocommerce · CWE-330 | Yüksek8,1 | — | %0,9 | 30 Nis 2024 |
30İzleyin | CVE-2024-13528İstismar yok | Customer Email Verification for WooCommerce <= 2.9.5 - Authentication Bypass via Shortcodewpfactory · customer email verification for woocommerce · CWE-287 | Yüksek7,5 | — | %0,5 | 12 Şub 2025 |
28İzleyin | CVE-2024-34370Kavram kanıtı | WordPress EAN for WooCommerce plugin <= 4.8.9 - Arbitrary Option Update to Privilege Escalation vulnerabilitywpfactory · ean for woocommerce · CWE-269 | Yüksek7,2 | — | %1,1 | 17 May 2024 |
26İzleyin | CVE-2024-35162İstismar yok | Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6.wpfactory llc · download plugins and themes from dashboard · CWE-22 | Orta6,5 | — | %0,7 | 22 May 2024 |
26İzleyin | CVE-2024-13525İstismar yok | Customer Email Verification for WooCommerce <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposurewpfactory · customer email verification for woocommerce · CWE-200 | Orta6,5 | — | %0,4 | 15 Şub 2025 |
26İzleyin | CVE-2024-13774İstismar yok | Wishlist for WooCommerce: Multi Wishlists Per Customer <= 3.1.7 - Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Namewpfactory · wishlist for woocommerce · CWE-352 | Orta6,5 | — | %0,2 | 7 Mar 2025 |
24İzleyin | CVE-2019-17239İstismar yok | includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple wpfactory · download plugins and themes from dashboard · CWE-79 | Orta6,1 | — | %0,9 | 7 Eki 2019 |
24İzleyin | CVE-2024-10519İstismar yok | Wishlist for WooCommerce: Multi Wishlists Per Customer PRO 3.0.8 - 3.1.2 - Reflected Cross-Site Scripting via wtab Parameterwpfactory · wishlist for woocommerce · CWE-79 | Orta6,1 | — | %0,5 | 23 Kas 2024 |
24İzleyin | CVE-2024-9377İstismar yok | Products, Order & Customers Export for WooCommerce <= 2.0.15 - Reflected Cross-Site Scriptingwpfactory · products\, order \& customers export for woocommerce · CWE-79 | Orta6,1 | — | %0,4 | 9 Eki 2024 |
24İzleyin | CVE-2024-8788İstismar yok | EU/UK VAT Manager for WooCommerce <= 2.12.12 - Reflected Cross-Site Scriptingwpfactory · eu\/uk vat manager for woocommerce · CWE-79 | Orta6,1 | — | %0,4 | 27 Eyl 2024 |
24İzleyin | CVE-2023-47547İstismar yok | WordPress Products, Order & Customers Export for WooCommerce Plugin <= 2.0.7 is vulnerable to Cross Site Scripting (XSS)wpfactory · products\, order \& customers export for woocommerce · CWE-79 | Orta6,1 | — | %0,4 | 14 Kas 2023 |
24İzleyin | CVE-2024-8656İstismar yok | WPFactory Helper <= 1.7.0 - Reflected Cross-Site Scriptingwpfactory · wpfactory helper · CWE-79 | Orta6,1 | — | %0,4 | 13 Eyl 2024 |
24İzleyin | CVE-2023-36689İstismar yok | WordPress WPFactory Helper Plugin <= 1.5.2 is vulnerable to Cross Site Scripting (XSS)wpfactory · wpfactory helper · CWE-79 | Orta6,1 | — | %0,4 | 5 Ağu 2023 |
24İzleyin | CVE-2024-0821İstismar yok | Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce <= 3.2.8 - Reflected Cross-Site Scriptingwpfactory · cost of goods for woocommerce · CWE-79 | Orta6,1 | — | %0,4 | 28 Şub 2024 |
24İzleyin | CVE-2024-9384İstismar yok | Quantity Dynamic Pricing & Bulk Discounts for WooCommerce <= 3.8.0 - Reflected Cross-Site Scriptingwpfactory · quantity dynamic pricing \& bulk discounts for woocommerce · CWE-79 | Orta6,1 | — | %0,4 | 4 Eki 2024 |
24İzleyin | CVE-2024-9205İstismar yok | Maximum Products per User for WooCommerce <= 4.2.8 - Reflected Cross-Site Scriptingwpfactory · maximum products per user for woocommerce · CWE-79 | Orta6,1 | — | %0,4 | 9 Eki 2024 |
24İzleyin | CVE-2024-44061İstismar yok | WordPress EU/UK VAT Manager for WooCommerce plugin <= 2.12.14 - CSRF to Cross Site Scripting (XSS) vulnerabilitywpfactory · eu\/uk vat manager for woocommerce · CWE-79 | Orta6,1 | — | %0,3 | 20 Eki 2024 |
21İzleyin | CVE-2023-0062İstismar yok | EAN for WooCommerce < 4.4.3 - Contributor+ Stored XSSwpfactory · ean for woocommerce · CWE-79 | Orta5,4 | — | %0,6 | 6 Şub 2023 |
21İzleyin | CVE-2024-9189İstismar yok | EU/UK VAT Manager for WooCommerce <= 2.12.12 - Missing Authorizationwpfactory · eu\/uk vat manager for woocommerce · CWE-862 | Orta5,3 | — | %0,5 | 27 Eyl 2024 |
21İzleyin | CVE-2023-51399İstismar yok | WordPress Back Button Widget Plugin <= 1.6.3 is vulnerable to Cross Site Scripting (XSS)wpfactory · back button widget · CWE-79 | Orta5,4 | — | %0,3 | 29 Ara 2023 |
21İzleyin | CVE-2023-6892İstismar yok | EAN for WooCommerce <= 4.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via alg_wc_ean_product_meta Shortcodewpfactory · ean for woocommerce · CWE-79 | Orta5,4 | — | %0,3 | 18 Nis 2024 |
21İzleyin | CVE-2025-48254İstismar yok | WordPress Change Add to Cart Button Text for WooCommerce plugin <= 2.2.2 - Cross Site Scripting (XSS) Vulnerabilitywpfactory · change add to cart button text for woocommerce · CWE-79 | Orta5,4 | — | %0,3 | 19 May 2025 |
21İzleyin | CVE-2025-48252İstismar yok | WordPress Back Button Widget plugin <= 1.6.8 - Cross Site Scripting (XSS) Vulnerabilitywpfactory · back button widget · CWE-79 | Orta5,4 | — | %0,3 | 19 May 2025 |
- CVE-2024-3127639İzleyin
WordPress Products, Order & Customers Export for WooCommerce plugin <= 2.0.8 - Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %0wpfactory · products\, order \& customers export for woocommerce9 Haz 2024
- CVE-2024-4930537İzleyin
WordPress Customer Email Verification for WooCommerce plugin <= 2.8.10 - SQL Injection vulnerability
KritikCVSS 9,3İstismar yokEPSS %0wpfactory · email verification for woocommerce17 Eki 2024
- CVE-2024-418532İzleyin
Customer Email Verification for WooCommerce <= 2.7.4 - Email Verification and Authentication Bypass due to Insufficient Randomness
YüksekCVSS 8,1İstismar yokEPSS %1wpcodefactory · customer email verification for woocommerce30 Nis 2024
- CVE-2024-1352830İzleyin
Customer Email Verification for WooCommerce <= 2.9.5 - Authentication Bypass via Shortcode
YüksekCVSS 7,5İstismar yokEPSS %0wpfactory · customer email verification for woocommerce12 Şub 2025
- CVE-2024-3437028İzleyin
WordPress EAN for WooCommerce plugin <= 4.8.9 - Arbitrary Option Update to Privilege Escalation vulnerability
YüksekCVSS 7,2Kavram kanıtıEPSS %1wpfactory · ean for woocommerce17 May 2024
- CVE-2024-3516226İzleyin
Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6.
OrtaCVSS 6,5İstismar yokEPSS %1wpfactory llc · download plugins and themes from dashboard22 May 2024
- CVE-2024-1352526İzleyin
Customer Email Verification for WooCommerce <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure
OrtaCVSS 6,5İstismar yokEPSS %0wpfactory · customer email verification for woocommerce15 Şub 2025
- CVE-2024-1377426İzleyin
Wishlist for WooCommerce: Multi Wishlists Per Customer <= 3.1.7 - Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name
OrtaCVSS 6,5İstismar yokEPSS %0wpfactory · wishlist for woocommerce7 Mar 2025
- CVE-2019-1723924İzleyin
includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple
OrtaCVSS 6,1İstismar yokEPSS %1wpfactory · download plugins and themes from dashboard7 Eki 2019
- CVE-2024-1051924İzleyin
Wishlist for WooCommerce: Multi Wishlists Per Customer PRO 3.0.8 - 3.1.2 - Reflected Cross-Site Scripting via wtab Parameter
OrtaCVSS 6,1İstismar yokEPSS %1wpfactory · wishlist for woocommerce23 Kas 2024
- CVE-2024-937724İzleyin
Products, Order & Customers Export for WooCommerce <= 2.0.15 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0wpfactory · products\, order \& customers export for woocommerce9 Eki 2024
- CVE-2024-878824İzleyin
EU/UK VAT Manager for WooCommerce <= 2.12.12 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0wpfactory · eu\/uk vat manager for woocommerce27 Eyl 2024
- CVE-2023-4754724İzleyin
WordPress Products, Order & Customers Export for WooCommerce Plugin <= 2.0.7 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %0wpfactory · products\, order \& customers export for woocommerce14 Kas 2023
- CVE-2024-865624İzleyin
WPFactory Helper <= 1.7.0 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0wpfactory · wpfactory helper13 Eyl 2024
- CVE-2023-3668924İzleyin
WordPress WPFactory Helper Plugin <= 1.5.2 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %0wpfactory · wpfactory helper5 Ağu 2023
- CVE-2024-082124İzleyin
Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce <= 3.2.8 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0wpfactory · cost of goods for woocommerce28 Şub 2024
- CVE-2024-938424İzleyin
Quantity Dynamic Pricing & Bulk Discounts for WooCommerce <= 3.8.0 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0wpfactory · quantity dynamic pricing \& bulk discounts for woocommerce4 Eki 2024
- CVE-2024-920524İzleyin
Maximum Products per User for WooCommerce <= 4.2.8 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0wpfactory · maximum products per user for woocommerce9 Eki 2024
- CVE-2024-4406124İzleyin
WordPress EU/UK VAT Manager for WooCommerce plugin <= 2.12.14 - CSRF to Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0wpfactory · eu\/uk vat manager for woocommerce20 Eki 2024
- CVE-2023-006221İzleyin
EAN for WooCommerce < 4.4.3 - Contributor+ Stored XSS
OrtaCVSS 5,4İstismar yokEPSS %1wpfactory · ean for woocommerce6 Şub 2023
- CVE-2024-918921İzleyin
EU/UK VAT Manager for WooCommerce <= 2.12.12 - Missing Authorization
OrtaCVSS 5,3İstismar yokEPSS %0wpfactory · eu\/uk vat manager for woocommerce27 Eyl 2024
- CVE-2023-5139921İzleyin
WordPress Back Button Widget Plugin <= 1.6.3 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %0wpfactory · back button widget29 Ara 2023
- CVE-2023-689221İzleyin
EAN for WooCommerce <= 4.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via alg_wc_ean_product_meta Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0wpfactory · ean for woocommerce18 Nis 2024
- CVE-2025-4825421İzleyin
WordPress Change Add to Cart Button Text for WooCommerce plugin <= 2.2.2 - Cross Site Scripting (XSS) Vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0wpfactory · change add to cart button text for woocommerce19 May 2025
- CVE-2025-4825221İzleyin
WordPress Back Button Widget plugin <= 1.6.8 - Cross Site Scripting (XSS) Vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0wpfactory · back button widget19 May 2025