Vulnerabilities in unknown

5,492 results
Vexday analysis

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2023-7201MEDIUMEverest Backup < 2.2.5 - Admin+ Arbitrary File UploadEPSS 0.6%CVE-2022-4577MEDIUMEasy Testimonials < 3.9.3 - Contributor+ Stored XSSEPSS 0.6%CVE-2022-4717MEDIUMStrong Testimonials < 3.0.3 - Contributor+ Stored XSS via ShortcodeEPSS 0.6%CVE-2022-0426—Product Feed PRO for WooCommerce < 11.2.3 - Reflected Cross-Site ScriptingEPSS 0.6%CVE-2023-0174MEDIUMWP VR < 8.2.7 - Contributor+ Stored XSSEPSS 0.6%CVE-2022-4626MEDIUMPPWP – WordPress Password Protect Page < 1.8.6 - Contributor+ Stored XSS in ShortcodeEPSS 0.6%CVE-2022-4824MEDIUMWP Blog and Widget < 2.3.1 - Contributor+ Stored XSS via ShortcodeEPSS 0.6%CVE-2021-24920—StatCounter < 2.0.7 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-6383HIGHDebug Log Manager < 2.3.0 - Sensitive Logs ExposureEPSS 0.6%CVE-2022-0360—WP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-12378HIGHBookingPress <= 1.1.28 - Unauthenticated PHP Object InjectionEPSS 0.6%CVE-2025-15672HIGHChama < 1.0.13 - Unauthenticated PHP Object InjectionEPSS 0.6%CVE-2021-24500—Workreap theme < 2.2.2 - Multiple CSRF + IDOR VulnerabilitiesEPSS 0.6%CVE-2021-24982—Child Theme Generator <= 2.2.7 - Reflected Cross-Site ScriptingEPSS 0.6%CVE-2022-0914—Export All URLs < 4.3 - Private/Draft Post/Page Title Disclosure via CSRFEPSS 0.6%CVE-2022-0134—AnyComment < 0.2.18 - Arbitrary HyperComments Import/Revert via CSRFEPSS 0.6%CVE-2024-5807HIGHBusiness Card <= 1.0.0 - Admin+ File UploadEPSS 0.6%CVE-2022-1932—Rezgo Online Booking < 4.1.8 - Reflected Cross-Site-ScriptingEPSS 0.6%CVE-2022-1349—WPQA < 5.2 - Subscriber+ Arbitrary Profile Picture Deletion via IDOREPSS 0.6%CVE-2023-7204HIGHWP STAGING WordPress Backup Plugin < 3.2.0 - Unauthorized Sensitive Data ExposureEPSS 0.6%