Paul Dannewitz

243
All Time Ranking
8
All Time Discoveries

8 Vulnerabilities

Title CVE ID CVSS Vector Date
Tidio Live Chat < 4.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H November 5, 2019
Visitor Traffic Real Time Statistics <= 1.12 - Cross-Site Request Forgery CVE-2019-15831 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H July 3, 2019
Visitor Traffic Real Time Statistics <= 1.13 - Cross-Site Request Forgery CVE-2019-15832 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H July 3, 2019
Widget Logic < 5.10.2 - Cross-Site Request Forgery CVE-2019-12826 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H July 1, 2019
Yet Another Stars Rating <= 1.8.6 - Unauthenticated PHP Object Injection 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H January 27, 2019
SQL Shortcode <= 1.1 - SQL Execution 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H September 2, 2017
Smoke Signal < 1.2.7 - Authenticated Stored Cross-Site Scripting 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L September 2, 2017
AddToAny Share Buttons <= 1.7.14 - HTTP Host Header Injection 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N August 16, 2017

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation