Krzysztof Zając

Vulnerabilities Discovered:

181
All Time Discoveries
0
Discoveries since Aug 24, 2023

Showing 1-20 of 181 vulnerabilities

Title CVE ID CVSS Vector Date
Qubely – Advanced Gutenberg Blocks <= 1.8.5 - Insufficient Authorization CVE-2021-24916 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N July 17, 2023
Stream <= 3.9.1 - Missing Authorization to Sensitive Information Disclosure CVE-2022-4384 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N January 16, 2023
Royal Elementor Addons <= 1.3.55 - Cross-Site Request Forgery CVE-2022-4102 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H December 15, 2022
Royal Elementor Addons <=1.3.55 - Missing Authorization to Subscriber+ Arbitrary Post Creation CVE-2022-4103 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N December 15, 2022
Royal Elementor Addons <=1.3.55 - Authenticated (Subscriber+) Arbitrary Post Deletion CVE-2022-4102 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H December 15, 2022
iubenda <= 3.3.2 - Authenticated (Subscriber+) Privilege Escalation CVE-2022-3911 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H December 12, 2022
Photo Gallery <= 1.8.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting CVE-2022-4058 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N November 28, 2022
Icegram Express <= 5.4.19 - Authenticated (Subscriber+) SQL Injection CVE-2022-3981 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H November 21, 2022
Five Star Restaurant Reservations <= 2.4.11 - Missing Authorization to Stored Cross-Site Scripting CVE-2022-0421 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N October 31, 2022
Easy Digital Downloads <= 2.11.7 - Cross-Site Request Forgery to Arbitrary Post Deletion CVE-2022-2387 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H October 17, 2022
WP Popup Builder <= 1.2.9 - Missing Authorization and Cross-Site Request Forgery CVE-2022-2405 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N September 5, 2022
WP Popup Builder <= 1.2.8 - Reflected Cross-Site Scripting CVE-2022-2404 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N September 5, 2022
Visual Portfolio, Photo Gallery & Post Grid <= 2.17.1 - Unauthenticated CSS Injection CVE-2022-2543 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N August 15, 2022
Visual Portfolio, Photo Gallery & Post Grid <= 2.18.0 - Contributor+ CSS Injection CVE-2022-2597 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N August 15, 2022
Directorist <= 7.3.0 - Sensitive Information Disclosure CVE-2022-2376 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N August 10, 2022
WP Hide & Security Enhancer <= 1.7.9.2 - Reflected Cross-Site Scripting CVE-2022-2538 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N August 8, 2022
WooCommerce PDF Invoices & Packing Slips 2.14.0 - 3.0.0 - Reflected Cross-Site Scripting CVE-2022-2537 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N August 3, 2022
WP Sticky Button <= 1.4 - Missing Authorization to Arbitrary Settings Update CVE-2022-2375 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L August 1, 2022
Product Slider for WooCommerce <= 2.5.6 - Missing Authorization CVE-2022-2382 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L July 26, 2022
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Subscriber+ Stored Cross-Site Scripting CVE-2022-2532 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N July 26, 2022

Share this researcher's vulnerability discoveries

All the threat data shared in this database is powered by Wordfence Intelligence Enterprise.
Interested in integrating this data into your platform or network?
Contact us now to discuss API access to our Wordfence Intelligence Enterprise Data Feeds.

Inquire Now

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation