Pierre Rudloff

216
All Time Ranking
23
All Time Discoveries
0
90 Day Published Submissions
N/A
Last Published Submission

Showing 1-20 of 23 Vulnerabilities

Title CVE ID CVSS Vector Date
Meta Tag Manager <= 3.2 - Open Redirect CVE-2025-5983 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N October 1, 2025
PPWP – Password Protect Pages <= 1.9.10 - Authenticated (Subscriber+) Content Exposure via REST API CVE-2025-5998 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N August 25, 2025
jQuery Colorbox <= 4.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2025-3650 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N August 22, 2025
Sharable Password Protected Posts <= 1.1.0 - Unauthenticated Password protected Post Exposure CVE-2025-5920 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N June 13, 2025
WP Lightbox 2 <= 3.0.6.7 - Unauthenticated Stored Cross-Site Scripting CVE-2025-3745 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N June 9, 2025
Firelight Lightbox <= 2.3.15 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2025-5035 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N June 6, 2025
Responsive Lightbox & Gallery <= 2.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2025-5093 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N June 6, 2025
Custom Post Carousels with Owl <= 1.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2025-5125 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N May 30, 2025
tarteaucitron.io <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2025-4955 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N May 28, 2025
FancyBox for WordPress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting CVE-2025-3662 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N May 13, 2025
Simple Lightbox <= 2.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2025-3516 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N April 25, 2025
Responsive Lightbox & Gallery <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2025-3742 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N April 24, 2025
LightPress Lightbox <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2025-3649 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N April 21, 2025
Firelight Lightbox <= 2.3.14 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2025-3597 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N April 21, 2025
AAWEP Obfuscator <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting CVE-2025-3432 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N April 7, 2025
WP-Syntax <= 1.2 - Authenticated (Author+) Regex Denial of Service CVE-2024-13926 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L March 28, 2025
WP-GeSHi-Highlight <= 1.4.3 Authenticated (Author+) ReDoS CVE-2024-13896 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L March 20, 2025
WP SVG Upload <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG CVE-2024-11847 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N March 5, 2025
tarteaucitron.js for WordPress < 0.3.0 - Authenticated (Author+) Stored Cross-Site Scripting CVE-2024-11718 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N March 3, 2025
Minify HTML <= 2.1.10 - - Regular Expressions Denial of Service CVE-2024-12579 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N December 12, 2024

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation