Vulnerabilities in unknown
5,533 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2022-2350—Disable User Login <= 1.0.1 - Unauthenticated Settings UpdateEPSS 0.4%CVE-2023-3226—Popup Builder < 4.2.0 - Admin+ Stored Cross-Site ScriptingEPSS 0.4%CVE-2024-6021MEDIUMDonation Block for PayPal <= 2.1.0 - Unauthenticated Stored XSSEPSS 0.4%CVE-2024-4655MEDIUMUltimate Blocks < 3.1.9 - Contributor+ Stored XSSEPSS 0.4%CVE-2021-24853—QR Redirector < 1.6 - Subscriber+ Arbitrary QR Redirect Response Status UpdateEPSS 0.4%CVE-2025-13070MEDIUMCSV to SortTable <= 4.2 - Contributor+ LFIEPSS 0.4%CVE-2024-6487MEDIUMInline Related Posts < 3.8.0 - Admin+ Stored XSSEPSS 0.4%CVE-2023-4821MEDIUMDrag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.4%CVE-2022-2260—GiveWP < 2.21.3 - DoS via CSRFEPSS 0.4%CVE-2024-2369MEDIUMPage Builder Gutenberg Blocks < 3.1.7 - Contributor+ Stored XSSEPSS 0.4%CVE-2026-9067CRITICALSchema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media UploadEPSS 0.4%CVE-2026-78472HIGHNi WooCommerce Sales Report < 4.2.0 - Unauthenticated SQLi via 'sort' ParameterEPSS 0.4%CVE-2026-84068HIGHQuentn WP 1.2.13 - 1.2.14 - Unauthenticated SQLi via 'qntn_wp' ParameterEPSS 0.4%CVE-2026-88926HIGHVikRentItems Flexible Rental Management System < 1.2.4 - Unauthenticated SQLiEPSS 0.4%CVE-2026-16572HIGHLogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' CookieEPSS 0.4%CVE-2026-18474HIGHWP Directory Kit < 1.5.6 - Unauthenticated SQL Injection via search_location and search_categoryEPSS 0.4%CVE-2026-4935HIGHSureTriggers < 1.1.23 – Unauthenticated SQLiEPSS 0.4%CVE-2026-15205HIGHPaymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel LookupEPSS 0.4%CVE-2026-13395HIGHBookly < 27.8 - Unauthenticated SQL Injection via staff_idEPSS 0.4%CVE-2026-12983HIGHDinatur <= 1.18 - Unauthenticated SQL Injection via Column Name InjectionEPSS 0.4%