Brandon James Roldan (tomorrowisnew)

43
All Time Ranking
80
All Time Discoveries

Showing 1-20 of 80 Vulnerabilities

Title CVE ID CVSS Vector Date
MainWP Child Reports <= 2.1.1 - Cross-Site Request Forgery CVE-2024-33680 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 26, 2024
FameTheme Demo Importer <= 1.1.5 - Cross-Site Request Forgery CVE-2024-33679 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 26, 2024
Royal Elementor Addons <= 1.3.93 - Unauthenticated IP Spoofing CVE-2024-32786 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N April 22, 2024
Giveaways and Contests by RafflePress <= 1.12.7 - Unauthenticated IP Spoofing CVE-2024-32827 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N April 22, 2024
Zero Spam <= 5.5.6 - Spam Protection Bypass CVE-2024-32521 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N April 15, 2024
WP Google Analytics Events <= 2.8.0 - Reflected Cross-Site Scripting CVE-2024-32145 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 12, 2024
Inline Related Posts <= 3.3.1 - Cross-Site Request Forgery CVE-2024-31426 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 10, 2024
Page Builder: Live Composer <= 1.5.35 - Cross-Site Request Forgery CVE-2024-31933 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 10, 2024
Simple Post Notes <= 1.7.6 - Cross-Site Request Forgery CVE-2024-31935 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 10, 2024
UsersWP <= 1.2.4 - Cross-Site Request Forgery CVE-2024-31936 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 10, 2024
Post Views Counter <= 1.4.4 - Cross-Site Request Forgery via save_bulk_post_views() CVE-2024-31264 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N April 5, 2024
Easy Social Feed <= 6.5.6 - Cross-Site Request Forgery CVE-2024-30526 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N March 29, 2024
Simple Revisions Delete <= 1.5.3 - Cross-Site Request Forgery CVE-2024-30482 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N March 28, 2024
Contact Form 7 – PayPal & Stripe Add-on <= 2.0 - Reflected Cross-Site Scripting CVE-2024-29130 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N March 16, 2024
Awesome Support <= 6.1.6 - Insufficient Authorization via wpas_can_delete_attachments() CVE-2024-24716 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N March 12, 2024
WordPress Manutenção <= 1.0.6 - IP Spoofing to Maintenance Mode Bypass CVE-2024-22139 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N January 10, 2024
MailerLite – WooCommerce integration <= 2.0.8 - Cross-Site Request Forgery via Multiple AJAX Functions CVE-2023-52223 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L January 8, 2024
Malware Scanner <= 4.7.1 - IP Spoofing CVE-2023-52176 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N December 29, 2023
NEX-Forms – Ultimate Form Builder <= 8.5.2 - Cross-Site Request Forgery CVE-2023-52120 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N December 28, 2023
Strong Testimonials <= 3.1.10 - Cross-Site Request Forgery CVE-2023-52123 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N December 28, 2023

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation