Vulnerabilities in unknown
5,492 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2022-4471MEDIUMYARPP - Yet Another Related Posts Plugin < 5.30.3 - Contributor+ Stored XSSEPSS 0.7%CVE-2022-4759MEDIUMGigPress < 2.3.28 - Contributor+ Stored XSS via ShortcodeEPSS 0.7%CVE-2022-4682MEDIUMLightbox Gallery < 0.9.5 - Contributor+ Stored XSS via ShortcodeEPSS 0.7%CVE-2022-4488MEDIUMWidgets on Pages < 1.8.0 - Contributor+ Stored XSSEPSS 0.7%CVE-2024-6517MEDIUMContact Form 7 Math Captcha <= 2.0.1 - Reflected XSSEPSS 0.7%CVE-2022-4109LOWWholesale Market for WooCommerce < 2.0.0 - Admin+ Arbitrary Log DownloadEPSS 0.7%CVE-2021-24813—Events Made Easy < 2.2.24 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2025-12841MEDIUMBookit < 2.5.1 – Unauthenticated Settings UpdateEPSS 0.7%CVE-2022-4303HIGHWP Limit Login Attempts <= 2.6.4 - IP SpoofingEPSS 0.7%CVE-2023-1405HIGHFormidable Forms < 6.2 - Unauthenticated PHP Object InjectionEPSS 0.7%CVE-2024-7354MEDIUMNinja Forms 3.8.6-3.8.10 - Reflected XSSEPSS 0.7%CVE-2023-3154HIGHNextGEN Gallery < 3.39 - Admin+ PHAR DeserializationEPSS 0.7%CVE-2021-24218—Facebook for WordPress 3.0.0-3.0.3 - CSRF to Stored XSS and Settings DeletionEPSS 0.7%CVE-2021-24888—ImageBoss < 3.0.6 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-3961MEDIUMDirectorist < 7.4.4 - Subscriber+ Sensitive Information DisclosureEPSS 0.7%CVE-2021-25026—Patreon WordPress < 1.8.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-0375MEDIUMEasy Affiliate Links < 3.7.1 - Contributor+ Stored XSSEPSS 0.7%CVE-2015-20106—ClickBank Affiliate Ads <= 1.20 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-24313—WP Prayer < 1.6.2 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.7%CVE-2023-4549—DoLogin Security < 3.7 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.7%