Brandon James Roldan (tomorrowisnew)

38
All Time Ranking
75
All Time Discoveries

Showing 1-20 of 75 Vulnerabilities

Title CVE ID CVSS Vector Date
WP Google Analytics Events <= 2.8.0 - Reflected Cross-Site Scripting CVE-2024-32145 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 12, 2024
UsersWP <= 1.2.4 - Cross-Site Request Forgery CVE-2024-31936 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 10, 2024
Simple Post Notes <= 1.7.6 - Cross-Site Request Forgery CVE-2024-31935 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 10, 2024
Page Builder: Live Composer <= 1.5.35 - Cross-Site Request Forgery CVE-2024-31933 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 10, 2024
Inline Related Posts <= 3.3.1 - Cross-Site Request Forgery CVE-2024-31426 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 10, 2024
Post Views Counter <= 1.4.4 - Cross-Site Request Forgery via save_bulk_post_views() CVE-2024-31264 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 5, 2024
Easy Social Feed <= 6.5.6 - Cross-Site Request Forgery CVE-2024-30526 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N March 29, 2024
Simple Revisions Delete <= 1.5.3 - Cross-Site Request Forgery CVE-2024-30482 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N March 28, 2024
Contact Form 7 – PayPal & Stripe Add-on <= 2.0 - Reflected Cross-Site Scripting CVE-2024-29130 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N March 16, 2024
Awesome Support <= 6.1.6 - Insufficient Authorization via wpas_can_delete_attachments() CVE-2024-24716 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N March 12, 2024
WordPress Manutenção <= 1.0.6 - IP Spoofing to Maintenance Mode Bypass CVE-2024-22139 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N January 10, 2024
MailerLite – WooCommerce integration <= 2.0.8 - Cross-Site Request Forgery via Multiple AJAX Functions CVE-2023-52223 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L January 8, 2024
Malware Scanner <= 4.7.1 - IP Spoofing CVE-2023-52176 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N December 29, 2023
Strong Testimonials <= 3.1.10 - Cross-Site Request Forgery CVE-2023-52123 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N December 28, 2023
Icegram <= 3.1.18 - Cross-Site Request Forgery via save_campaign_preview CVE-2023-52119 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N December 28, 2023
NEX-Forms – Ultimate Form Builder <= 8.5.2 - Cross-Site Request Forgery CVE-2023-52120 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N December 28, 2023
Simple Job Board <= 2.10.6 - Cross-Site Request Forgery CVE-2023-52122 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N December 28, 2023
White Label <= 2.9.0 - Cross-Site Request Forgery via white_label_reset_wl_admins CVE-2023-52128 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N December 28, 2023
WPC Product Bundles for WooCommerce <= 7.3.1 - Cross-Site Request Forgery CVE-2023-52127 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N December 28, 2023
Affiliates Manager <= 2.9.31 - Cross-Site Request Forgery via multiple AJAX actions CVE-2023-52130 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N December 28, 2023

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation