Morten Nortoft

82
All Time Ranking
26
All Time Discoveries

Showing 1-20 of 26 Vulnerabilities

Title CVE ID CVSS Vector Date
Ninja Forms Contact Form <= 2.9.21 - Reflected Cross-Site Scripting 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N August 4, 2015
Database Sync < 0.5 - Reflected Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N July 30, 2015
Admin Pack by SITE CASEIRO <= 1.1 - Authenticated (Admin+) Stored Cross-Site Scripting 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N July 30, 2015
Content Grabber <= 1.0 - Authenticated (Admin+) Cross-Site Scripting CVE-2015-9469 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N July 30, 2015
WP Accurate Form Data <= 1.2 - Cross-Site Request Forgery to Cross-Site Scripting CVE-2015-9443 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H June 21, 2015
Copy or Move Comments < 1.0.1 - Cross-Site Scripting and SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H June 16, 2015
Altos Connect <= 1.3.0 - Cross-Site Scripting CVE-2015-9444 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N June 15, 2015
Mobile Domain <= 1.5.2 - Cross-Site Request Forgery and Stored Cross-Site Scripting CVE-2015-1581 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N February 11, 2015
CrossSlide jQuery Plugin <= 2.0.5 - Multiple Cross-Site Request Forgery to Stored Cross-Site Scripting CVE-2015-2089 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H February 9, 2015
Redirection Page <= 1.2 - Cross-Site Request Forgery to Cross-Site Scripting CVE-2015-1580 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H February 9, 2015
WDSocialWidgets < 1.0.11 - Cross-Site Scripting CVE-2015-1582 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L January 26, 2015
Acobot Live Chat & Contact Form <= 2.0 - Cross-Site Request Forgery and Cross-Site Scripting CVE-2015-2039 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N January 26, 2015
Google Doc Embedder <= 2.5.18 - Cross-Site Scripting CVE-2015-1879 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N January 26, 2015
Cart66 Lite :: WordPress Ecommerce <= 1.5.4 - Reflected Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N January 26, 2015
WP Construction Mode <= 1.91 - Reflected Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N December 15, 2014
Sliding Social Icons <= 1.61 - Cross-Site Request Forgery and Stored Cross-Site Scripting CVE-2014-9437 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H December 15, 2014
WP-FB-AutoConnect <= 4.0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N December 14, 2014
WP Timed Popout <= 1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N December 14, 2014
Easy Social Like Box – Popup – Sidebar Widget < 2.8.3 - Cross-Site Scripting CVE-2014-9524 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L December 12, 2014
Our Team Showcase < 1.3 - Cross-Site Scripting CVE-2014-9523 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N December 12, 2014

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation