Julio Potier

106
All Time Ranking
23
All Time Discoveries

Showing 1-20 of 23 Vulnerabilities

Title CVE ID CVSS Vector Date
WPS Child Theme Generator < 1.2 - Directory Traversal CVE-2019-15822 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 23, 2019
WPS Limit Login < 1.4.6.1 - Authorization Bypass via IP Spoofing 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 23, 2019
BJ Lazy Load < 1.0 - Remote File Inclusion via TimThumb CVE-2015-9415 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H September 2, 2015
WordPress Sentinel < 1.0.1 - SQL Injection CVE-2011-5224 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H December 14, 2011
tarteaucitron.js – Cookies legislation & GDPR <= 1.5.4 - Cross-Site Request Forgery to Cross-Site Scripting CVE-2021-36887 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H December 9, 2021
WP Frontend Profile <= 1.2.1 - Cross-Site Request Forgery 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H May 19, 2020
WPS Limit Login < 1.4.6.1 - Cross-Site Request Forgery 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H July 23, 2019
WPS Bidouille <= 1.12.2 - Multiple Cross-Site Request Forgery 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H July 23, 2019
Smash Balloon Social Photo Feed <= 1.11.3 - Cross-Site Request Forgery to Back-Up Deletion 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H March 5, 2019
WordPress Sentinel <= 1.0.0 - Cross-Site Request Forgery CVE-2011-5226 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H December 16, 2011
Register IPs <= 1.8.0 - Unauthenticated Stored Cross-Site Scripting 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L May 14, 2019
WP Hide & Security Enhancer <= 1.3.9.2 - Arbitrary File Download 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N July 21, 2017
iThemes Security <= 5.3.5 - Missing Capabilities Check 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L April 25, 2016
WPS Limit Login < 1.4.6.1 - Stored Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N July 23, 2019
Contextual Adminbar Color <= 0.2 - Stored Cross-Site Scripting 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N January 17, 2020
WPS Cleaner <= 1.4.4 - Missing Authorization Checks 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L July 23, 2019
Newspaper <= 10.3.3 - Reflected Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N June 3, 2020
WordPress Sentinel <= 1.0.0 - Cross-Site Scripting CVE-2011-5225 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N December 14, 2011
iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 - Hidden Login Bypass 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N April 22, 2021
WPS Cleaner <= 1.4.4 - Arbitrary Media File Disclosure 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N July 23, 2019

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation