Vulnerabilities in smackcoders
23 resultsVexday analysis
SmackCoders registra 20 vulnerabilidades acumuladas na base com apenas 1 crítica (CVSS), sendo a fraqueza dominante a execução de código não restrita (CWE-94); nenhuma está sob exploração ativa conhecida, sugerindo risco moderado e controlável, embora a publicação recente de 1 falha nos últimos 90 dias indique atividade contínua que requer monitoramento.
CVE-2024-43965HIGHWordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerabilityEPSS 2.0%CVE-2023-4142HIGHWP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code ExecutionEPSS 1.6%CVE-2023-4141HIGHWP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code ExecutionEPSS 1.6%CVE-2025-2008HIGHImport Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 1.2%CVE-2025-2007HIGHImport Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 1.2%CVE-2026-13353HIGHWP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' ParameterEPSS 1.1%CVE-2023-4140MEDIUMWP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege EscalationEPSS 0.8%CVE-2025-2332CRITICALExport All Posts, Products, Orders, Refunds & Users <= 2.13 - Unauthenticated PHP Object InjectionEPSS 0.8%CVE-2025-10057HIGHWP Import – Ultimate CSV XML Importer for WordPress 7.20 - 7.28 - Authenticated (Subscriber+) Remote Code Execution via Code InjectionEPSS 0.7%CVE-2025-9990HIGHWordPress Helpdesk Integration <= 5.8.10 - Unauthenticated Local File InclusionEPSS 0.7%CVE-2023-4139HIGHWP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory ListingEPSS 0.7%CVE-2025-10058HIGHWP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.6%CVE-2023-45066MEDIUMWordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2025-13145HIGHWP Import – Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV ImportEPSS 0.5%CVE-2024-12315HIGHExport All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected DirectoryEPSS 0.5%CVE-2023-2487MEDIUMWordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2024-9364MEDIUMSendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log DeletionEPSS 0.4%CVE-2025-10040HIGHWP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Missing Authorization to Authenticated (Subscriber+) FTP/SFTP Credential ExposureEPSS 0.3%CVE-2025-14627MEDIUMWP Import – Ultimate CSV XML Importer for WordPress <= 7.35 - Authenticated (Contributor+) Server-Side Request Forgery via Bitly Shortlink BypassEPSS 0.3%CVE-2025-12732MEDIUMWP Import – Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticated (Author+) Sensitive Information ExposureEPSS 0.3%