Rio Darmawan

Organization: Zerobyte

13
All Time Ranking
190
All Time Discoveries

Showing 161-180 of 190 Vulnerabilities

Title CVE ID CVSS Vector Date
Newsletters <= 4.8.8 - Cross-Site Request Forgery CVE-2023-30478 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N April 13, 2023
Client Portal – Private user pages and login <= 1.1.8 - Cross-Site Request Forgery via cp_create_private_pages_for_all_users function CVE-2023-25968 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N February 22, 2023
Etsy Shop <= 3.0.3 - Cross-Site Request Forgery to Plugin Settings Update CVE-2023-25975 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L February 22, 2023
Feed Them Social <= 3.0.2 - Cross-Site Request Forgery CVE-2023-25056 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L February 21, 2023
Publish to Schedule <= 4.4.2 - Cross-Site Request Forgery leading to Plugin Option Changes CVE-2023-25994 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N February 20, 2023
Shoppable Images <= 1.2.3 - Cross Site Request Forgery CVE-2023-25698 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N February 13, 2023
WP Lightbox 2 <= 3.0.6.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings CVE-2023-45747 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N October 12, 2023
Simple Tweet <= 1.4.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings CVE-2023-45767 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N October 12, 2023
Fitness calculators plugin <= 2.0.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via admin settings CVE-2023-40552 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N August 16, 2023
Zeno Font Resizer <= 1.7.9 - Authenticated (Administrator+) Stored Cross-Site Scripting CVE-2023-25442 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N February 15, 2023
WP Prayer <= 1.9.6 - Authenticated(Admin+) Stored Cross-Site Scripting CVE-2023-25705 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N February 14, 2023
TinyMCE Custom Styles <= 1.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting CVE-2023-23995 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N January 27, 2023
ProfilePress <= 4.5.3 - Authenticated (Administrator+) Stored Cross-Site Scripting CVE-2023-23996 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N January 20, 2023
WPFrom Email <= 1.8.8 - Authenticated (Administrator+) Stored Cross-Site Scripting CVE-2023-23982 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N January 20, 2023
User Registration <= 2.3.0 - Authenticated (Administrator+) Stored Cross Site Scripting CVE-2023-23987 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N January 20, 2023
Conversational Forms for ChatBot <= 1.1.6 - Authenticated (Administrator+) Stored Cross-Site Scripting CVE-2023-23981 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N January 20, 2023
Responsive Vertical Icon Menu <= 1.5.8 - Authenticated (Administrator+) Stored Cross-Site Scripting CVE-2023-23870 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N January 20, 2023
OOPSpam Anti-Spam <= 1.1.35 - Authenticated (Admin+) Stored Cross-Site Scripting CVE-2023-22716 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N January 17, 2023
WP-CommentNavi <= 1.12.1 - Authenticated (Admin+) Stored Cross-Site Scripting CVE-2023-22715 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N January 17, 2023
Shoppable Images Lite <= 1.2.3 - Missing Authorization 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L February 13, 2023

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation