Chloe Chamberland

Organization: Wordfence

16
All Time Ranking
136
All Time Discoveries

About

Threat Intelligence Lead @Wordfence

Masters of Cybersecurity and Information Assurance OSCP, OSWP, OSWE, CISSP, CEH, ECSA, Security+, CySA+, PenTest+, CASP+, SSCP, eWPT, eWPTx, AWS Security Speciality

When not breaking things, I enjoy coffee, travel, donuts, and nature.

Wordfence Vulnerability Researcher
Wordfence Vulnerability Researcher
November 8, 2023

Showing 21-40 of 136 Vulnerabilities

Title CVE ID CVSS Vector Date
WP Shamsi <= 4.1.0 - Missing Authorization to Arbitrary Plugin Deactivation CVE-2022-4555 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L November 28, 2022
Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File Deletion CVE-2022-2431 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H July 27, 2022
SiteGround Security <= 1.2.5 - Authorization Weakness to Authentication Bypass CVE-2022-0993 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H April 7, 2022
SiteGround Security <= 1.2.5 - Authentication Bypass via 2FA Setup CVE-2022-0992 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 6, 2022
Total Upkeep <= 1.14.13 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure CVE-2022-4932 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N February 24, 2022
Photoswipe Masonry Gallery <= 1.2.14 Stored Cross-Site Scripting CVE-2022-0750 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N February 24, 2022
Profile Builder - User Profile & User Registration Forms <= 3.6.1 - Cross-Site Scripting via site_url Parameter CVE-2022-0653 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N February 17, 2022
WP HTML Mail <= 3.0.9 - Missing Authorization on Rest Route CVE-2022-0218 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L January 19, 2022
Side Cart Woocommerce (Ajax) <= 2.0 - Cross-Site Request Forgery to Arbitrary Options Update CVE-2022-0215 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H January 13, 2022
Login/Signup Popup <= 2.2 - Cross-Site Request Forgery to Arbitrary Options Update CVE-2022-0215 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H January 13, 2022
Waitlist Woocommerce ( Back in stock notifier ) <= 2.5.1 - Cross-Site Request Forgery to Arbitrary Options Update CVE-2022-0215 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H January 13, 2022
Post Grid <= 2.1.12 - Contributor+ SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H December 15, 2021
RegistrationMagic <= 5.0.1.7 - Authentication Bypass CVE-2021-4073 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H December 8, 2021
Variation Swatches for WooCommerce <= 2.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVE-2021-42367 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N December 1, 2021
Preview E-Mails for WooCommerce <= 1.6.8 - Reflected Cross-Site Scripting CVE-2021-42363 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N November 18, 2021
OptinMonster <= 2.6.4 - Unprotected REST-API Endpoints CVE-2021-39341 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N November 1, 2021
Sassy Social Share 3.3.23 - Object Injection CVE-2021-39321 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H October 21, 2021
Envato Elements <= 2.0.10 & Template Kit <= 1.0.13 - Authenticated (Contributor+) Arbitrary File Upload CVE-2021-4330 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H October 21, 2021
AccessPress Themes and Plugin <= Various Versions - Authenticated (Subscriber+) Arbitrary File Upload CVE-2021-39317 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H October 6, 2021
Ninja Forms <= 3.5.7 - Unprotected REST-API to Sensitive Information Disclosure CVE-2021-34647 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N September 22, 2021

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation