Kacper Szurek

50
All Time Ranking
63
All Time Discoveries

Showing 21-40 of 63 Vulnerabilities

Title CVE ID CVSS Vector Date
Paid Memberships Pro < 1.7.15 - Directory Traversal CVE-2014-8801 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N November 14, 2014
DukaPress < 2.5.4 - Directory Traversal CVE-2014-8799 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N November 13, 2014
Backup and Restore WordPress – Backup Plugin <= 1.9 - Sensitive Information Disclosure CVE-2014-9012 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N July 16, 2014
Pie Register <= 2.0.13 - Missing Authorization CVE-2014-8802 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L January 17, 2015
Import any XML or CSV File to WordPress <= 3.2.4 - SQL Injection 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H February 19, 2020
Contact Form Email < 1.0.1 - Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N November 22, 2014
Watu Quiz <= 2.5.0.1 - Stored Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N November 16, 2014
Smart Forms – when you need more than just a contact form <= 2.1.0 - Missing Authorization CVE-2014-8803 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N November 6, 2014
Contact Bank – Contact Form Builder for WordPress <= 2.0.69 - Stored Cross-Site Scripting CVE-2014-8807 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N November 5, 2014
Favicon by RealFaviconGenerator <= 1.2.12 - Reflected Cross-Site Scripting CVE-2015-10116 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L April 1, 2015
WonderPlugin Audio Player < 2.1 - Multiple Cross-Site Scripting CVE-2015-2218 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L February 19, 2015
Nextend Social Login and Register <= 1.5.0 - Cross-Site Scripting CVE-2014-8800 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L February 12, 2014
Marketplace <= 2.4.0 - Path Traversal CVE-2014-9014 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N March 21, 2015
WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More <= 4.6.3 - Authorization Bypass 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L December 16, 2014
Backup and Restore WordPress – Backup Plugin <= 1.9 - Authorization Bypass 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N December 4, 2014
Livefyre Comments 3 <= 4.1.4 - Stored Cross-Site Scripting 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N August 2, 2015
Import any XML or CSV File to WordPress <= 3.2.4 - Missing Authorization and Cross-Site Request Forgery Checks 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L February 19, 2020
Lingotek Translation <= 1.1.8 - Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N June 20, 2016
Comments - wpDiscuz <= 3.1.4 - Reflected Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 30, 2016
Wordfence Security – Firewall & Malware Scan 6.1.1 - 6.1.6 - Reflected Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 10, 2016

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation