Jerome Bruandet

Vulnerabilities Discovered:

211
All Time Discoveries
0
Discoveries since Aug 24, 2023

Showing 1-20 of 211 vulnerabilities

Title CVE ID CVSS Vector Date
B2BKing <= 4.6.00 - Missing Authorization to Authenticated(Subscriber+) Price Modification CVE-2023-3125 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N June 3, 2023
B2BKing <= 4.6.00 - Missing Authorization to Authenticated(Subscriber+) Information Disclosure CVE-2023-3126 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N June 3, 2023
Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option CVE-2023-3124 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H March 28, 2023
FlyingPress <= 3.9.6 - Missing Authorization CVE-2022-4948 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N November 28, 2022
Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation CVE-2022-4950 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H April 4, 2022
AdSanity < 1.8.2 - Authenticated Arbitrary File Upload CVE-2022-4949 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H January 25, 2022
WordPress Popular Posts <= 5.3.2 - Authenticated Arbitrary File Upload CVE-2021-42362 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H November 12, 2021
uListing <= 1.6.6 - Unauthenticated SQL Injection CVE-2021-4340 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H October 28, 2021
JobSearch WP Job Board < = 1.8.1 - Missing Authorization on jobsearch_update_job_import_schedule_call() function CVE-2021-4364 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N October 5, 2021
JobSearch WP Job Board <= 1.8.1 - Missing Authorization to Arbitrary Options Update CVE-2021-4361 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H October 5, 2021
JobSearch WP Job Board <= 1.8.1 - Missing Authorization to Settings Change CVE-2021-4352 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N October 5, 2021
WP DSGVO Tools (GDPR) <= 3.1.23 - Unauthenticated Stored Cross-Site Scripting CVE-2021-4358 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N September 24, 2021
WooCommerce Multi Currency <= 2.1.17 - Missing Authorization CVE-2021-4379 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N September 13, 2021
WooCommerce Multi Currency <= 2.1.17 - Missing Authorization CVE-2021-4376 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N September 13, 2021
Multiple XforWooCommerce Add-On Plugins (Various Versions) - Missing Authorization CVE-2021-4337 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H September 7, 2021
Pinterest Automatic <= 4.14.3 - Unuathenticated Arbitrary Options Update CVE-2021-4380 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H September 6, 2021
WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update CVE-2021-4374 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H September 6, 2021
WooCommerce Dynamic Pricing and Discounts <= 2.4.1 - Stored Cross-Site Scripting CVE-2021-4372 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N August 31, 2021
WooCommerce Dynamic Pricing and Discounts <= 2.4.1 - Unauthenticated Settings Import/Export CVE-2021-4353 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N August 31, 2021
WP-Backgrounds Lite <= 2.3 - Cross-Site Request Forgery Bypass CVE-2021-4419 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N August 16, 2021

Share this researcher's vulnerability discoveries

All the threat data shared in this database is powered by Wordfence Intelligence Enterprise.
Interested in integrating this data into your platform or network?
Contact us now to discuss API access to our Wordfence Intelligence Enterprise Data Feeds.

Inquire Now

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation