Vulnerabilities in unknown
5,533 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2026-17533HIGHAll-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST ImportEPSS 0.5%CVE-2026-75796HIGHAI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP User ToolsEPSS 0.5%CVE-2024-0420MEDIUMMapPress Maps for WordPress < 2.88.15 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-74925HIGHMultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to AdministratorEPSS 0.5%CVE-2026-85569HIGHTutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request MisclassificationEPSS 0.5%CVE-2023-0233MEDIUMActiveCampaign < 8.1.12 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-16605HIGHMultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing AuthorizationEPSS 0.5%CVE-2024-4217MEDIUMShortcodes Ultimate Pro < 7.1.5 - Contributor+ Stored Cross-Site Scripting XSSEPSS 0.5%CVE-2023-1839MEDIUMProduct Addons & Fields for WooCommerce < 32.0.6 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2023-4757MEDIUMStaff / Employee Business Directory for Active Directory < 1.2.3 - Improper escaping of LDAP entriesEPSS 0.5%CVE-2024-13896MEDIUMWP-GeSHi-Highlight <= 1.4.3 - Author+ ReDoSEPSS 0.5%CVE-2026-11568HIGHProduct Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_dataEPSS 0.5%CVE-2023-7151MEDIUMProduct Enquiry for WooCommerce < 3.2 - Reflected XSSEPSS 0.5%CVE-2025-6174MEDIUMWordPress Qwizcards <= 3.9.4 - Reflected XSSEPSS 0.5%CVE-2023-4798—User Avatar - Reloaded < 1.2.2 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-19093MEDIUMTutor LMS < 4.0.6 - Instructor+ Arbitrary File Read via Video PathEPSS 0.5%CVE-2023-2568—Photo Gallery by Ays < 5.1.7 - Reflected XSSEPSS 0.5%CVE-2023-2324—Elementor Forms Google Sheet Connector < 1.0.7 - Reflected XSSEPSS 0.5%CVE-2023-2320—CF7 Google Sheets Connector < 5.0.2 - Reflected XSSEPSS 0.5%CVE-2021-24166—Ninja Forms < 3.4.34 - CSRF to OAuth Service DisconnectionEPSS 0.5%