Vulnerabilities in unknown
5,533 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2024-8700HIGHEvent Calendar <= 1.0.4 - Unauthenticated Arbitrary Calendar DeletionEPSS 0.5%CVE-2024-1564MEDIUMSchema Pro < 2.7.16 - Contributor+ Custom Field AccessEPSS 0.5%CVE-2024-0236MEDIUMEventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Virtual Event Password DisclosureEPSS 0.5%CVE-2026-82925HIGHSite Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form SignatureEPSS 0.5%CVE-2026-84099HIGHIDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.phpEPSS 0.5%CVE-2026-16267HIGHNewsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form FieldEPSS 0.5%CVE-2026-12987HIGHEvents Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking RegistrationEPSS 0.5%CVE-2024-1983HIGHSimple Ajax Chat < 20240223 - Unauthenticated Stored XSSEPSS 0.5%CVE-2023-5942MEDIUMMedialist < 1.4.1 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-76553MEDIUMWP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template Path TraversalEPSS 0.5%CVE-2026-77693HIGHOrder Tip for WooCommerce < 1.6.0 - Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajaxEPSS 0.5%CVE-2023-5757—WP Crowdfunding < 2.1.8 - Admin+ Stored XSSEPSS 0.5%CVE-2021-25108—IP2Location Country Blocker < 2.26.6 - Arbitrary Country Ban via CSRFEPSS 0.5%CVE-2023-5209—Bookly < 22.5 - Admin+ Stored XSSEPSS 0.5%CVE-2024-9021MEDIUMRelevanssi < 4.23.1 - Contributor+ Stored XSSEPSS 0.5%CVE-2023-5343MEDIUMPopup Box < 3.7.9 - Admin+ Stored XSSEPSS 0.5%CVE-2026-78361CRITICALzipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Option DeletionEPSS 0.5%CVE-2023-5119—Forminator and Forminator Pro < 1.27.0 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2023-6257MEDIUMInline Related Posts < 3.6.0 - Subscriber+ Password Protected Post ReadEPSS 0.5%CVE-2021-24668—MAZ Loader < 1.4.1 - Arbitrary Loader Deletion via CSRFEPSS 0.4%