minhtuanact

45
All Time Ranking
67
All Time Discoveries

Showing 41-60 of 67 Vulnerabilities

Title CVE ID CVSS Vector Date
Advanced Category Template <= 0.1 - Stored Cross-Site Scripting via Cross-Site Request Forgery in _form.php CVE-2023-31072 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 24, 2023
Email Subscription Popup <= 1.2.16 - Reflected Cross-Site Scripting CVE-2023-30489 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 7, 2023
Amelia <= 1.0.75 - Unauthenticated Reflected Cross-Site Scripting via 'code' CVE-2023-29427 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 6, 2023
Product Catalog Simple <= 1.6.17 - Reflected Cross-Site Scripting CVE-2023-29388 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 6, 2023
PropertyHive <= 1.5.46 - Reflected Cross-Site Scripting via 'merge_ids' CVE-2023-29172 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 3, 2023
WooCommerce JazzCash Gateway Plugin <= 2.0 - Unauthenticated Cross-Site Scripting CVE-2022-46822 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N March 22, 2023
Open Graphite <= 1.6.0 - Reflected Cross-Site Scripting via topic parameter CVE-2022-47439 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N March 21, 2023
Open RDW kenteken voertuiginformatie <= 2.0.14 - Reflected Cross-Site Scripting via open_data_rdw_kenteken CVE-2022-47431 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N March 17, 2023
WordPress Mortgage Calculator Estatik <= 2.0.7 - Reflected Cross-Site Scripting CVE-2023-28490 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N March 16, 2023
微信机器人高级版 <= 6.2.1 - Reflected Cross Site Scripting CVE-2022-45837 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N February 8, 2023
WPComplete <= 2.9.4 - Reflected Cross-Site Scripting CVE-2022-45825 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N January 27, 2023
Map Multi Marker <= 3.2.1 - Reflected Cross-Site Scripting CVE-2022-47591 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N January 13, 2023
Doofinder for WooCommerce <= 1.5.49 - Unauthenticated Open Redirect CVE-2023-40602 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N August 17, 2023
Dynamic Visibility for Elementor <= 5.0.5 - Missing Authorization to Authenticated(Subscriber+) Post Visibility Modification CVE-2023-35046 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L June 3, 2023
Order Your Posts Manually <= 2.2.5 - Reflected Cross-Site Scripting via 'cat_id' CVE-2023-32509 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N May 10, 2023
Joli Table of Contents <= 1.3.9 - Cross-Site Request Forgery CVE-2022-46820 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L January 3, 2023
Envira Gallery Lite <= 1.8.3.2 - Cross-Site Scripting CVE-2021-24126 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N December 19, 2020
Ultimate Addons for Contact Form 7 <= 3.2.10 - Missing Authorization CVE-2023-47693 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N November 9, 2023
Libsyn Publisher Hub <= 1.4.4 - Sensitive Information Exposure CVE-2023-45834 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N October 13, 2023
Woo Custom Emails <= 2.2 - Missing Authorization to Unauthenticated Settings Change CVE-2023-32507 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N May 10, 2023

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation