Julio Potier

104
All Time Ranking
23
All Time Discoveries

Showing 1-20 of 23 Vulnerabilities

Title CVE ID CVSS Vector Date
tarteaucitron.js – Cookies legislation & GDPR <= 1.5.4 - Cross-Site Request Forgery to Cross-Site Scripting CVE-2021-36887 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H December 9, 2021
iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 - Hidden Login Bypass 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N April 22, 2021
Newspaper <= 10.3.3 - Reflected Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N June 3, 2020
WP Frontend Profile <= 1.2.1 - Cross-Site Request Forgery 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H May 19, 2020
Contextual Adminbar Color <= 0.2 - Stored Cross-Site Scripting 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N January 17, 2020
WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via Referer Header CVE-2019-15826 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N July 23, 2019
WPS Limit Login < 1.4.6.1 - Cross-Site Request Forgery 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H July 23, 2019
WPS Limit Login < 1.4.6.1 - Authorization Bypass via IP Spoofing 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 23, 2019
WPS Limit Login < 1.4.6.1 - Stored Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N July 23, 2019
WPS Cleaner <= 1.4.4 - Missing Authorization Checks 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L July 23, 2019
WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via 'action=confirmaction' CVE-2019-15823 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N July 23, 2019
WPS Bidouille <= 1.12.2 - Multiple Cross-Site Request Forgery 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H July 23, 2019
WPS Cleaner <= 1.4.4 - Arbitrary Media File Disclosure 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N July 23, 2019
WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via 'action=rp' CVE-2019-15825 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N July 23, 2019
WPS Child Theme Generator < 1.2 - Directory Traversal CVE-2019-15822 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 23, 2019
Register IPs <= 1.8.0 - Unauthenticated Stored Cross-Site Scripting 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L May 14, 2019
Smash Balloon Social Photo Feed <= 1.11.3 - Cross-Site Request Forgery to Back-Up Deletion 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H March 5, 2019
WP Hide & Security Enhancer <= 1.3.9.2 - Arbitrary File Download 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N July 21, 2017
iThemes Security <= 5.3.5 - Missing Capabilities Check 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L April 25, 2016
BJ Lazy Load < 1.0 - Remote File Inclusion via TimThumb CVE-2015-9415 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H September 2, 2015

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation